realn2s, (edited ) to random German

Versuche gerade eine/die richtige Meldestelle für einen (leider erfolgreichen) Phishing Betrug zu finden.

Vom hörensagen soll das bei der Polizeiwache vor Ort eher unbefriedigend sein.
Hat jemand Tipps, Pointer oder Kontakte?
#Hessen #Cybersicherheit

Gerne RT

realn2s,

Zum Ablauf des Scams, um ihn vielleicht in Zukunft bei anderen zu verhindern:

Eine Webseiten hat den Computer "aus Sicherheitsgründen" gesperrt. Und man wird aufgefordert eine deutsche Microsoft Support Hotline anzurufen
(Ich vermute dass das "nur" eine Webseite in Vollbild Modus war)

Der Support schaltet sich dann remote auf den Gerät auf (weiß nicht was sie da benutzt haben) und "repariert" das Problem.
Zur Freischaltung muss man aber Geld per Xbox Gutscheinen übermitteln (hier 400€)

Diese Übermittlung gibt dann erst Mal "schief" und man sollte es mit neuen Gutscheinen noch Mal probieren. Das Geld von den ersten Gutscheinen könnte man dann zurückfordern.
(Tipps wie (ob) man Xbox Gutscheine sperren kann sind willkommen)

Hier wurde der Betrug erkannt und kein weiteres Geld übermittelt. Der PC wurde dann wieder "freigegeben".

Der Rechner ist von Netz getrennt und aus. Technische Details weiß ich erst in den nächsten Tagen, wenn ich mit den Rechner angeschaut habe. Durch den remote Zugang können natürlich Daten gestohlen oder Schadenssoftware installiert worden sein

#cybersicherheit #scam #SocialEngineering #Phishing

braveinnovators, to infosec Ukrainian

Тиждень тому українці почали отримувати СМС-повідомлення нібито від «Укрпошти» про те, що їх відправлення не доставлять, якщо вони не нададуть свої персональні дані (детальніше про це можна прочитати в матеріалі AIN.UA: https://ain.ua/2023/06/06/ukrposhta-poperedyla-pro-fishyng/).

#UAMaliciousURLBlocklist #phishing #scam #infosec #malware #cybersecurity #кібербезпека #Ukraine#Україна

braveinnovators,

Це рішення працює на всіх операційних системах (на скріншоті блокування однієї із адрес у браузері Brave для ОС Android). Єдине, що потрібно — додати фільтр Ukrainian Malicious URL Blocklist до свого веб-браузера: https://github.com/braveinnovators/url-blocklist

#UAMaliciousURLBlocklist #phishing #scam #infosec #malware #cybersecurity #кібербезпека #Ukraine#Україна

braveinnovators,

Саме тому ми створили універсальне правило для фільтра фішингових сайтів Ukrainian Malicious URL Blocklist завдяки якому всі веб-посилання у форматі ukrposhta.xxx.xxx будуть блокуватися автоматично і незалежно від того, які саме доменні імена будуть надалі використовуватися шахраями у цій фішинговій кампанії.

#UAMaliciousURLBlocklist #phishing #scam #infosec #malware #cybersecurity #кібербезпека #Ukraine#Україна

vlrny, to random
@vlrny@disabled.social avatar

Question:

Anybody else get this kind of creepy chat up out of the blue with no other interaction? Bot? Or just socially inappropriate?

Mostly just need to decide between ignore, block, or report.

vlrny,
@vlrny@disabled.social avatar

Pfft! I just remembered when I was on #wattpad I got these so often I engaged in full conversations out of curiosity and amusement.

Say hello to Jerry in Raptures, for example...

#spam #scam #phishing #mastodon

https://www.wattpad.com/1007782435-bot-or-human-with-weird-day-job-jerry-in-raptures

t3n, to ChatGPT German
@t3n@t3n.social avatar

Wie WormGPT Phishing-Angriffe automatisiert

In der Welt der Cyberkriminalität haben Hacker ein neues Werkzeug entdeckt, um ihre bösartigen Aktivitäten voranzutreiben.

Ein generatives KI-Tool namens WormGPT ermöglicht es Kriminellen, komplexe Phishing-Angriffe durchzuführen.
👉
https://t3n.de/news/wormgpt-kriminelle-ki-chatbot-1564733/?utm_source=mastodon&utm_medium=referral
#KI #ChatGPT #WormGPT #phishing

InfoSecSherpa, to random

Read InfoSecSherpa's #InformationSecurity and #DataPrivacy News Roundup for Saturday, June 17, 2023 🧑‍🏫🎣

Features The Washington Post article by Karina Elwood, "Teachers got an appreciation email from Fairfax Schools. It was a #phishing test.

https://infosecsherpa.medium.com/infosecsherpas-news-roundup-for-saturday-june-17-2023-5c6cb62394b

jasonnab, to random

A #phishing email targeting #netcup users is currently going around, be prudent and cautious of any urgent or suspicious emails received relating to your services there!

The spam email came from the domain campusfinances (dot) fr

which is hosted on Hetzner at IPv4 157 (dot) 90 (dot) 176 (dot) 97. The phishing link is hosted on another provider and IP.

More in depth analysis later.

AAKL, to Cybersecurity

Akamai’s new study: Bots, #phishing and server attacks making commerce a #cybersecurity hotspot #infosec https://www.techrepublic.com/article/akamai-study-bot-attacks-commerce/

nrohluap, to Cybersecurity
@nrohluap@ioc.exchange avatar

Another fine phishing email in the inbox this morning:
“Survey or signature? YOU DECIDE!”
🤡
#CyberSecurity #phishing

realhackhistory, to ChatGPT
@realhackhistory@chaos.social avatar

You could just as easily find some elaborate method of persuading regular #ChatGPT to help write some convincing #phishing emails, hell just having mostly correct spelling and grammar would be a massive boost to believability and Microsoft Word could help with that as is.
https://thehackernews.com/2023/07/wormgpt-new-ai-tool-allows.html

AAKL, to random
5am, to random
@5am@fosstodon.org avatar

I made good progress on tonight. I'm hungry for more after getting three more badges, but my brain needs rest! 🐟🔍🛡️

5am, to random
@5am@fosstodon.org avatar

I'd be interested in knowing people's experience with 's Phish Insight. It seems like a really valuable free service to have at your disposal for gaining insights and helping improve your team's awareness. https://phishinsight.trendmicro.com/

Ciantic, to random
@Ciantic@twit.social avatar

Finnish market chain and bank S-Pankki is informing about #phishing attempts. The funny thing is that they are sending their email from: noreply.s-pankki@email.s-pankki.fi

What garbage is that? That is one confusing email address to use to inform about phishing attempts. Can't they come up simpler that is easier to verify by looking at?

chris_hayes, to random
@chris_hayes@fosstodon.org avatar

Credit to #hetzner for a quick response to a phishing report impacting one of my team's clients. The site was nuked within an hour of them receiving the report.

This is a good reminder that anyone can help defeat phishing sites by looking up their host and registrar. Those providers typically have phishing report forms.
#phishing

fifonetworks, to random

Cybersecurity professionals who promote fear are doing harm to overall cybersecurity awareness training efforts.

As an example, I received this inquiry from a person who was unnecessarily afraid to use a legitimate payment system. Read their question and my reply below:

"Hi Bob, I have a tech question for you. I just had my car serviced at the dealer. They offered a pickup and return service (of the car) which I used, so I did not physically have to go there. When they were done they texted me a copy of the bill and there was a link to make the payment. Since I wasn’t sure how safe that was I called and made the payment, but for future reference I thought I’d ask you if it is a safe/secure way to pay.
Thanks"

My reply:
"Yes! It's safe and secure to use a link in a text message, or QR code, given to you directly by a local business. That business is paying a transaction fee to use an online credit card payment services provider."

Instead of fostering fear, teach people how to distinguish between legitimate payment links and payment links from scammers.

Empower them.
Don't intimidate them.

#callmeifyouneedme #fifonetworks

#cybersecurity #fintech #scams #phishing #smishing #training

publicvoit, to security German
@publicvoit@graz.social avatar

Wieder mal ein gutes Argument, auf seinem Handy kein #Internbanking sondern maximal die Zweifaktorauthentifizierung zu machen und keine Apps abseits vom Play Store zu installieren: Eine sehr gut gemachte #Vishing Methode könnte bald in die EU schwappen: https://www.heise.de/news/Vishing-Betrueger-arbeiten-mit-raffinierter-Voice-Phishing-Masche-9212374.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag

#Voice #Phishing #Security #Sicherheit #Geld

itnewsbot, to random
heiseonline, to news German

Kurz informiert:Fake-Shops, Phishing-Kampagne, Vergeudete Arbeitszeit, Microsoft

Unser werktäglicher News-Überblick fasst die wichtigsten Nachrichten des Tages kurz und knapp zusammen.

https://www.heise.de/news/Kurz-informiert-Fake-Shops-Phishing-Kampagne-Vergeudete-Arbeitszeit-Microsoft-9192632.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#iCloud #Arbeitswelt #Digitalisierung #kurzinformiert #Phishing #news

fifonetworks, to email

Simplicity dot com's email server has been hacked. Yesterday I received an email through their domain that is obviously a phishing scam impersonating Harbor Freight.
#email #phishing

itnewsbot, to security

Torrent of image-based phishing emails are harder to detect and more convincing - Enlarge / Man hand holding a mobile phone with QR code. (credit: Getty ... - https://arstechnica.com/?p=1951208 #security #phishing #biz#qrcode #image

maxleibman, to infosec
@maxleibman@mastodon.social avatar

Them: It said, “Welcome to wetside, please leg in.” Why would you assume that was a legit log in screen?

Me [shrugging]: Autocorrect?

#infosec #phishing

AAKL, to random
AAKL, to Cybersecurity
AAKL, to Cybersecurity
  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • tester
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • tacticalgear
  • osvaldo12
  • normalnudes
  • cubers
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • modclub
  • lostlight
  • All magazines