Feeds

Phishers target Yahoo! Photos

Picture teaser tempts unwary

Boost IT visibility and business value

Updated Internet crooks looking to capture login details of Yahoo! accounts are changing tactics. Phishing attacks that attempt to capture a user's Yahoo! ID and password by tricking the gullible into handing over their credentials to fake sign-in pages have been around for months if not years. Recently, though, these phishing sites have begun using alternative Yahoo! Sign In pages, such as Yahoo! Photos, net security firm Websense reports.

Users typically receive an email or instant message that claims to be from a friend wanting to show off photos of a recent event, such as a vacation or a birthday party. The message contains a link to a phishing site, which records the user's Yahoo! ID and password, and then forwards the Yahoo! ID and password on to the real Yahoo! Photos site. What started off at a crude attack has evolved with the introduction of a more subtle form of social engineering attack.

Websense reports that the majority of these sites are hosted in the US on free web space provided by the Yahoo! Geocities service. A phishing screen shot example can be found here.

Yahoo! Photos users are advised to go the Yahoo! site itself rather than following links in suspicious-looking emails.

In a statement, Yahoo! said that phishing is an industry-wide issue which it treats very seriously. "When we learn about phishing sites, we remove them as quickly as possible. Yahoo! treats users' security as a top priority and continues to take a hard look at how to effectively combat phishing," it said. Users can report phishing issues at Yahoo! abuse here. The firm's security advice to consumers can be found here. ®

Gartner critical capabilities for enterprise endpoint backup

More from The Register

next story
Microsoft: We plan to CLEAN UP this here Windows Store town
Paid-for apps that provide free downloads? Really
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Hear ye, young cyber warriors of the realm: GCHQ wants you
Get involved, get a job and then never discuss work ever again
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
BYOD's dark side: Data protection
An endpoint data protection solution that adds value to the user and the organization so it can protect itself from data loss as well as leverage corporate data.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?