ANNOUNCEMENT : ALL OF ROYAL MAIL'S EMPLOYMENT POLICIES (AGREEMENTS) AT A GLANCE (Updated 2021)... HERE

ANNOUNCEMENT : PLEASE BE AWARE WE ARE NOT ON FACEBOOK AT ALL!

Cybercriminals Use Password-Protected Forms to Phish Poste

Competitors and other mail organisations around the world news and discussion.This is an open forum.
TrueBlueTerrier
FORUM ADMINISTRATOR
Posts: 72497
Joined: 30 Dec 2006, 10:29
Gender: Male
Location: On my couch

Cybercriminals Use Password-Protected Forms to Phish Poste

Post by TrueBlueTerrier »

Cybercriminals Use Password-Protected Forms to Phish Poste Italiane Credentials

http://news.softpedia.com/news/Cybercri ... 2735.shtml" onclick="window.open(this.href);return false;

Image

Cybercriminals often launch campaigns designed to trick customers of Poste Italiane (the Italian Post Office) into handing over their personal information. However, experts from Sophos have come across one scam email that uses some old but interesting techniques.

The emails, written in Italian, are entitled something like “Useful information on the new security system,” and they urge recipients to download an attached form and complete it.

To make everything more legitimate-looking, the fake Poste Italiane notification informs recipients that they must use a password – one that’s included in the body of the email – in order to access the form.

According to experts, this tactic might make the attack less successful, since users who don’t read the entire email and rush to open the attachment are prevented from accessing the phishing page. On the other hand, the use of a password might add some credibility to the scam.

The use of a password could also prevent some security scanners from seeing that the HTML file that’s attached to the emails is a phishing page.

Additional technical details on this phishing attack are available on Sophos’ blog.
All post by me in Green are Admin Posts.
Any post in any other colour is my own responsibility.
If you like a news story I posted please click the link to show support Any news stories you can't post - PM me with a link
My sharing of news articles should not be interpreted as an endorsement or condemnation of any particular viewpoint or the issues presented. I share them solely for informational purposes.