Update your password: email scam

A phishing campaign that is convincingly spoofing emails from the online payment company Stripe is in the wild and being replicated with other payment websites.

The email informs the recipient that an unknown device has logged into their account from an IP address in Tbilisi, Georgia, and it includes a link for the user to update their password. There are few visible signs that the email is fake as the phishing site looks slightly different from Stripe’s real login page, but most people wouldn’t notice the difference unless they looked at them side by side.

What is significant about this campaign is how quickly it was set up. Security experts received the email just 39 minutes after the phishing site’s domain was registered. The site’s SSL certificate had also been obtained the same day. This means the attacker set up the entire site and began churning out phishing emails in under 40 minutes.

This is one of the areas where security technology can’t stay ahead of the criminals. In recent years, security companies have substantially improved their ability to detect and flag malicious sites, and many phishing sites are taken down within twenty-four hours after they go live. As this case shows, however, criminals have adapted and are now incredibly fast at standing up new phishing sites.

Experts suggest users can avoid this form of attack by recommending users never click on login links in emails. You should instead navigate to the site with your browser or app and log in to your account. If there’s really an issue with your account, you’ll be able to take care of it from there.

Our experience in crisis management, disaster recovery and time critical project work has proven to be the major point of difference as has our open and transparent communication.

To discuss successful partnerships and how engaging Consulting IT to maintain your IT infrastructure will:

  • Reduce your Staff downtime/ Expenditure/ Stress/ Exposure and Risk
  • Increase your Awareness/ Business Continuity Plans/ Backup and Disaster Recovery Systems/ Auditing and Compliance

Simply contact Corey Hill (chill@consultingit.com.au), National Sales and Marketing Manager.

By | 2020-03-23T10:52:45+10:00 March 23rd, 2020|Latest Articles|