Pages: [1]   Go Down
  Print  
Author Topic: New Apple ID Phishing Effort Compromises Over 100 Sites  (Read 367 times)
HCK
Global Moderator
Hero Member
*****
Posts: 79425



« on: May 04, 2013, 07:00:41 am »

New Apple ID Phishing Effort Compromises Over 100 Sites

As highlighted by The Next Web, security firm Trend Micro yesterday outlined a new phishing scam that has seen the perpetrators compromise over 100 sites in their attempts to gain access to users' Apple ID accounts. While Apple IDs are relatively popular targets for phishing scams, Trend Micro's analysis offers some interesting detail on the approaches used by the criminals.We’ve identified a total of 110 compromised sites, all of hosted at the IP address 70.86.13.17, which is registered to an ISP in the Houston area. Almost all of these sites have not been cleaned. [...]   We’ve seen attacks targeting not only American users, but also British and French users. Some versions of this attack ask not only for the user’s Apple ID login credentials, but also their billing address and other personal and credit card information. It will eventually result in a page that states that access has been restored, but of course the information has been stolen.Trend Micro's sample of a spam message designed to trick recipients into sharing their account information at the compromised sites shows a very poor attempt at copying Apple's email style, but inexperienced Internet users are undoubtedly still falling for the scheme.     Trend Micro offers a number of suggestions to help users protect themselves from phishing scams, including checking for consistent domains throughout email addresses and links included in an email and checking for indicators that the user is at a secure site associated with the correct company.   While phishing scams rely on the gullibility of users to direct them to fake account management sites, Apple has sought to increase account security on its own site with its recent introduction of two-step verification to help minimize the possibility of an unauthorized party gaining access to a user's account. That feature is, however, only available in a handful of countries for the time being.   Recent Mac and iOS Blog Stories • Leap Wireless Reports Improved iPhone Sales Amid Customer Losses  • Apple Seeds Build 12E40 of OS X Beta 10.8.4 Developers • AT&T Announces Upgrade to In-Store Smartphone Trade-In Program • Russian Billionaire Buys $100 Million in Apple Stock • Jawbone Releases API for Developers, Buys BodyMedia • Vine Adds Support for Mentions and Front-Facing Camera • Belkin Officially Begins Shipping Thunderbolt Express Dock • Apple Tops Consumer Reports' Tech Support Ratings, Bests Its Own Score    
 


http://www.macrumors.com/2013/05/01/new-apple-id-phishing-effort-compromises-over-100-sites/
Logged
Pages: [1]   Go Up
  Print  
 
Jump to: