Feeds

Fax-back phishing scam targets PayPal

Retro racket

Top 5 reasons to deploy VMware with Tegile

Phishers have gone retro with a scam that tries to dupe victims into faxing their banking details to fraudsters. Scam emails, (screengrab) which pose as messages from online payment outfit Paypal, urge users to fax back account information instead of the more usual tactic of handing over details to a bogus website.

Would-be victims are told the information is needed to investigate an alleged security breach involving an attempt to reset their password (have the lads from Lagos developed a sense of irony here?). The scam email points to a Microsoft Word document on a Polish website. Recipients are instructed to download and complete with their bank account details (including PIN information), credit card numbers and login details before faxing back to what ostensibly appears to be a freephone number in the US. Sophos has confirmed that the telephone number mentioned in the emails is hosting an active fax machine. It's unclear whether the phone is actually located in the States or is being redirected elsewhere.

Sophos has reported the scam emails to eBay and is awaiting a response. "The phishing gang may have made a huge blunder by including the fax number in their scam. PayPal and the authorities are sure to follow that lead when investigating this matter further," said Graham Cluley, senior technology consultant for Sophos. "In the last few days we have seen a number of attempts by phishers to use this technique, and it's possible that some people who know that they need to be careful about entering their confidential information on a bogus website may think that completing and faxing back such a form is somehow safer."

He added that the change in tactics by phishers was likely an experiment possibly prompted by the effect of greater public awareness on response rates to conventional phishing scams. ®

Internet Security Threat Report 2014

More from The Register

next story
'Kim Kardashian snaps naked selfies with a BLACKBERRY'. *Twitterati gasps*
More alleged private, nude celeb pics appear online
Home Depot ignored staff warnings of security fail laundry list
'Just use cash', former security staffer warns friends
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
UK.gov lobs another fistful of change at SME infosec nightmares
Senior Lib Dem in 'trying to be relevant' shocker. It's only taxpayers' money, after all
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Snowden, Dotcom, throw bombs into NZ election campaign
Claim of tapped undersea cable refuted by Kiwi PM as Kim claims extradition plot
Freenode IRC users told to change passwords after securo-breach
Miscreants probably got in, you guys know the drill by now
THREE QUARTERS of Android mobes open to web page spy bug
Metasploit module gobbles KitKat SOP slop
BitTorrent's peer-to-peer chat app Bleep goes live as public alpha
A good day for privacy as invisble.im also reveals its approach to untraceable chats
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.