Jump to content

Microsoft Windows Update emails try to steal your Gmail, Yahoo, AOL passwords...


anuseems

Recommended Posts

Beware any emails which claim to come from [email protected] - it could be that you're being targeted in an attack designed to steal your AOL, Gmail, Yahoo or Windows Live password.

At first glance, if you don't look too carefully, the emails entitled "Microsoft Windows Update" may appear harmless enough. But the grammatical errors and occasional odd language should raise alarms bells that the emails may not really be from Microsoft.

Is this email really from Microsoft?

Dear Windows User,

It has come to our attention that your Microsoft windows Installation records are out of date. Every Windows installation has to be tied to an email account for daily update.

This requires you to verify the Email Account. Failure to verify your records will result in account suspension. Click on the Verify button below and enter your login information on the following page to confirm your records.

VERIFY

Thank you,

Microsoft Windows Team.

If you do make the mistake of clicking on the link you are taken to a third party website (not the real Microsoft.com), where you are warned that your computer is at high risk and told to choose between logging in via Gmail, Windows Live, Yahoo or AOL.

Phishing

For the benefit of this article, I chose to pretend that I wanted to log in via AOL. Surprise surprise, the web page asked me to enter my AOL username and password.

Phishing

Of course, whatever I enter at this point is going to be passed straight into the hands of a cybercriminal. Once your details are in their claws, they'll waste no time breaking into your online account, stealing information and potentially committing identity theft.

Oh, and I hope you don't use the same password on multiple websites. Things could definitely get very ugly..

Naturally, victims of the phishing attack are oblivious to what is going on - especially as the thoughtful scammers are caring enough to redirect your browser to a genuine Microsoft webpage related to updating your Windows security.

The attack concludes by taking the phishing victim to a genuine Microsoft webpage

Take care folks. Be suspicious of unsolicited emails, and always think carefully before entering your webmail passwords. If you are reckless you might be handing the keys to your online life over to a complete stranger.

@ http://nakedsecurity.sophos.com/2012/09/24/microsoft-windows-update-emails-try-to-steal-your-gmail-yahoo-aol-passwords/

Link to comment
Share on other sites


  • Replies 2
  • Views 1.4k
  • Created
  • Last Reply

Dumm dummmm darrrrrrrr - I was talking to a few people yesterday about a similar scam that's done over the phone - getting you to type in a web address and sign in with your e-mail XYZ.... I'm surprised people are still falling for this stuff....

Link to comment
Share on other sites


A new generation of the gullible has been let loose on the web so i'd expect this type of scam to become even more prevelant.

Link to comment
Share on other sites


Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...