Powered by Movable Type 3.121
Home The Book Training Events Tools Stats
Web log archive.
Dispatches Archive

« February 2017 | Main | August 2017 »

July 13, 2017

Phony Netflix Payment Scam Permalink

Don't fall for this one:

Fake Netflix payment notice

Everybody's gotta have their Netflix so they can properly chill, and you don't want a failed payment to prevent you from getting your downloaded goodness. This email notification, titled "We were unable to collect your last payment", is truly fake news. In the image, I show the actual URL of the link, which isn't anything related to Netflix.

For the quick-to-click crowd, however, they won't notice this fact, nor that the link redirects to a Chinese site with an incredibly believable Netflix sign-in page:

Fake Netflix Sign In Page

This is how lots of folks give up a valuable pair of login credentials (email and password), which they wrongly use for many sites, including some corporate networks that don't implement more stringent password rules. Even in just the consumer space, if you reuse your Netflix credentials for Amazon or your AppleID, giving them up to crooks can cause you all kinds of headaches.

As always, if you receive an email like the one above, do not ever follow the link in the email. Instead, log onto the site through a previously saved bookmark. If there are genuine problems with your payment method, you'll be advised on the site.

Posted on July 13, 2017 at 12:11 PM

July 05, 2017

Sloppy Scammer Permalink

The Subject: line promises that there's a $90K/year job opening at Apple. The body, however, has different messages about a job. First, I'm being presented with an offer "to work with us" — whoever "us" is. Three positions are apparently available at Google and Facebook. What happened to Apple? Dunno.

Phone job offer spam

Then comes a "Position Summary", which indicates just one available position that pays $75/hour. That's about $150K/year, not $90K. So what's the deal?

There is no deal.

The URLs behind all clickable links go to a domain that was registered way back earlier today. Although the name/address of the registrant is all-American, I don't buy it for an instant. The contact mail address (conceivably of the actual registrant) is a mail.ru address — our old friends of the Russian Federation.

The URLs are coded in such a way that my email address could be determined from any click I make. I'd rather not do it with this harvested address, so I can only guess at the possible outcomes:

  • Malware loading
  • Request for deep personal information that a legitimate employer might ask for
  • Recruitment as a money laundering mule

None of these leads to anything good. Unfortunately, the hot brand names will trick plenty of job hunters/hoppers into at least clicking a link. Woe unto them.

Posted on July 05, 2017 at 12:41 PM