article thumbnail

Fla. Man Charged in SIM-Swapping Spree is Key Suspect in Hacker Groups Oktapus, Scattered Spider

Krebs on Security

The missives asked users to click a link and log in at a phishing page that mimicked their employer’s Okta authentication page. Those who submitted credentials were then prompted to provide the one-time password needed for multi-factor authentication. A booking photo of Noah Michael Urban released by the Volusia County Sheriff.

article thumbnail

‘Land Lordz’ Service Powers Airbnb Scams

Krebs on Security

site that helps him manage more than 500 scam properties and interactions with up to 100 (soon-to-be-scammed) “guests” looking to book the fake listings. Airbnb could help by adding some type of robust multi-factor authentication, such as Security Keys — which would defeat these Airbnb phishing pages.

Scams 250
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Bomb Threat, Sextortion Spammers Abused Weakness at GoDaddy.com

Krebs on Security

Grasping the true breadth of Bryant’s prescient discovery requires a brief and simplified primer on how Web sites work. Contacted by KrebsOnSecurity, GoDaddy acknowledged the authentication weakness documented by Guilmette. “We’ve identified a fix and are taking corrective action immediately,” the statement continued.

DNS 242
article thumbnail

LastPass: ‘Horse Gone Barn Bolted’ is Strong Password

Krebs on Security

To automatically populate the appropriate credentials at any website going forward, you simply authenticate to LastPass using your master password. “LastPass in my book is one step above snake-oil. “And if they haven’t followed the guidelines we recommended that they change their downstream passwords.” ”

Passwords 271
article thumbnail

It’s Way Too Easy to Get a.gov Domain Name

Krebs on Security

John Levine , a domain name expert, consultant and author of the book The Internet for Dummies , said the.gov domain space wasn’t always so open as it is today. Such a hoax could well decide the fate of a close national election. “Back in the day, everyone not in the federal government was supposed to register in the.us