article thumbnail

How Coinbase Phishers Steal One-Time Passwords

Krebs on Security

A recent phishing campaign targeting Coinbase users shows thieves are getting cleverer about phishing one-time passwords (OTPs) needed to complete the login process. In each case, the phishers manually would push a button that caused the phishing site to ask visitors for more information, such as the one-time password from their mobile app.

Passwords 348
article thumbnail

Why You Should Opt Out of Sharing Data With Your Mobile Provider

Krebs on Security

A new breach involving data from nine million AT&T customers is a fresh reminder that your mobile provider likely collects and shares a great deal of information about where you go and what you do with your mobile device — unless and until you affirmatively opt out of this data collection.

Mobile 288
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Massive utility scam campaign spreads via online ads

Malwarebytes

Enter the utility scam , where crooks pretend to be your utility company so they can threaten and extort as much money from you as they can. This scam has been going on for years and usually starts with an unexpected phone call and, in some cases, a visit to your door. Report the scam to the proper authorities, which may be the FTC.

Scams 139
article thumbnail

WhatsApp cryptocurrency scam goes for the cash prize

Malwarebytes

Password [ **] USDT Balance 1,660,086.50 But since it was a rainy day and I’d never seen this type of WhatApp scam before, I decided to investigate. Knowing that in this type of scam the victim always has to invest a—relatively–small amount to get the bait, I knew what to expect. Account Csy926. USDT or $602,494.07.

article thumbnail

Steer clear of cryptocurrency recovery phrase scams

Malwarebytes

As an example of this, a simple search for “metamask download” reveals sites claiming to offer MetaMask extensions for various browsers and mobile devices. The site claims: MetaMask cannot recover your password. The MetaMask site is a secret recovery phrase phish. Thanks to Jerome for finding this.

article thumbnail

50 Ways to Avoid Getting Scammed on Black Friday

Adam Levin

Here are 50 ways to avoid getting scammed on Black Friday — and beyond. Make sure your smartphone, tablet and laptop are password-protected, particularly if you’re in the habit of carrying them around wherever you go. Popular browsers, like Safari or Firefox, frequently issue updates to protect against scams. Lock your devices.

Scams 243
article thumbnail

Two Charged in SIM Swapping, Vishing Scams

Krebs on Security

Bryan hijacked social media and bitcoin accounts using a mix of voice phishing or “ vishing ” attacks and “ SIM swapping ,” a form of fraud that involves bribing or tricking employees at mobile phone companies. Interestingly, the conspiracy appears to have unraveled over a business dispute between the two men.

Scams 310