MX Lab security experts have come across a clever scheme

Apr 15, 2013 22:21 GMT  ·  By

An eBay phishing scheme targeting French users has been spotted by experts from MX Lab. 

The emails, entitled “Question sur l’ objet #2091501444 – Répondre maintenant” (Question on item #[number] – Answer now), are well designed so they might trick unsuspecting eBay customers into believing they’re legitimate, especially if the recipient has something for sale on the site.

In reality, the emails have nothing to do with eBay. Internauts who click on the links are taken to a webpage that replicates the eBay login webpage.

The only differences between the real page and the phony one are the disclaimer, which on the phony page is written in English and not French as it’s supposed to be; the lack of a link to the eBay app; and the fact that the Norton Secured logo is not valid on the site set up by the phishers.

To avoid raising suspicion, the page is designed so that victims are redirected to the legitimate eBay France login page after they hand over their usernames and passwords on the malicious website.

If you're a victim of this scam, be sure to change your eBay password immediately. If you utilize the same passphrase for multiple sites, change all of them.