Yahoo! Mail accounts can be worth a lot for cybercriminals

Apr 17, 2012 07:02 GMT  ·  By

Yahoo! customers may receive an email that purports to come from the company, informing them that their account has exceeded its limit. In reality, it’s nothing more than a scam designed to steal login credentials from unsuspecting users.

The scam is not new, but according to Hoax Slayer, it’s hitting inboxes once again.

“Your E-mail account has exceeded its limit and needs to be verified, if not verified within 24 hours, we shall suspend your account. Click Here,” reads the message.

Internauts who fall for it and click the link are immediately taken to a site that replicates the legitimate Yahoo! Mail login page.

Once the user logs in, the username and the passwords are instantly stored in a database controlled by the cybercriminals.

Such compromised accounts can be worth a great deal for fraudsters because they can send shady emails to all the contacts in the victim’s address book.

While in most cases compromised email accounts are used to promote fake work from home jobs or shady pharmaceutical products, more recently, they have been successfully used to send out distress messages.

In these messages, the scammers invent a story about how the owner of the account was robbed while vacationing, usually in Barcelona. They ask the friend or contact to wire them money via Western Union or other transaction method that can’t be easily traced.

That is why Internet users should be highly cautious when clicking on links received via email or social media networks.

While email addresses can be easily spoofed, with website names it’s not so easy. The name of the website displayed in the browser’s address bar can always give away the true identity of a malicious scheme.

Also, if friends call you to say that you have been sending them distress emails, be sure to immediately change your password and notify all the potential victims of the scam attempt.

Note. My Twitter account has been erroneously suspended. While this is sorted out, you can contact me via my author profile or follow me at @EduardKovacs1