Remove is-this-link-a-scam
article thumbnail

PayPal Phishing Scam Uses Invoices Sent Via PayPal

Krebs on Security

The missives — which come from Paypal.com and include a link at Paypal.com that displays an invoice for the supposed transaction — state that the user’s account is about to be charged hundreds of dollars. For starters, all of the links in the email lead to paypal.com. ” The message continues: “$600.00

Scams 320
article thumbnail

Calendar Meeting Links Used to Spread Mac Malware

Krebs on Security

Malicious hackers are targeting people in the cryptocurrency space in attacks that start with a link added to the target’s calendar at Calendly , a popular application for scheduling appointments and meetings. The profile also linked to Mr. Lee’s Twitter/X account , which features the same profile image.

Malware 275
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Teach a Man to Phish and He’s Set for Life

Krebs on Security

Like attaching a phishing email to a traditional, clean email message, or leveraging link redirects on LinkedIn , or abusing an encoding method that makes it easy to disguise booby-trapped Microsoft Windows files as relatively harmless documents. ’ One would think Microsoft would have had plenty of time by now to address this.”

Phishing 213
article thumbnail

Phishers Spoof USPS, 12 Other Natl’ Postal Services

Krebs on Security

Recent weeks have seen a sizable uptick in the number of phishing scams targeting U.S. Clicking the link in the text message brings one to the domain usps.informedtrck[.]com. The landing page generated by the phishing link includes the USPS logo, and says “Your package is on hold for an invalid recipient address.

Phishing 283
article thumbnail

‘Tis the Season for the Wayward Package Phish

Krebs on Security

Here’s a look at a fairly elaborate SMS-based phishing scam that spoofs FedEx in a bid to extract personal and financial information from unwary recipients. “A link was included, implying that the recipient could reschedule delivery.” ” Attempting to visit the domain in the phishing link — o001cfedeex[.]com

Phishing 312
article thumbnail

How Phishers Are Slinking Their Links Into LinkedIn

Krebs on Security

If you received a link to LinkedIn.com via email, SMS or instant message, would you click it? The LinkedIn redirect links allow customers to track the performance of ad campaigns, while promoting off-site resources. Here’s the very first Slink created: [link] which redirects to the homepage for LinkedIn Marketing Solutions.

Phishing 331
article thumbnail

Discord Admins Hacked by Malicious Bookmarks

Krebs on Security

Those who take the bait are sent a link to a Discord server that appears to be the official Discord of the crypto news site, where they are asked to complete a verification step to validate their identity. “I’ve seen all kinds of crypto scams, but I’ve never seen one like this.”

Hacking 292