Phishers have switched tactics in their ongoing attempt to lift usernames and passwords from unsuspecting Yahoo users, a security company says.
Phishers have switched tactics in their ongoing attempt to lift usernames and passwords from unsuspecting Yahoo users, a security company said, by turning to secondary sign-on pages, such as that for the Yahoo Photos image sharing service.
San Diego-based Websense said that crooks are sending out spam that claims to contains photos from a friend wanting to show off some recent pics, such as ones from a wedding or birthday. The messages include a link to a phony site, which captures the user's Yahoo ID and password, then passes the data to the real Yahoo Photos site.
Websense also reported that the majority of the spoofed sites using this trick are hosted by Yahoo's own GeoCities service, which offers 15MB of data storage and 3GB of data transfer per month at no charge.
Phishing criminals are always searching for sneakier ways to deceive Internet users. Last week, for instance, security vendor SurfControl noted that some phishers were using phony digital certificates to calm users' worries about suspicious sites.
We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
2017 State of IT ReportIn today's technology-driven world, "innovation" has become a basic expectation. IT leaders are tasked with making technical magic, improving customer experience, and boosting the bottom line -- yet often without any increase to the IT budget. How are organizations striking the balance between new initiatives and cost control? Download our report to learn about the biggest challenges and how savvy IT executives are overcoming them.
Infographic: The State of DevOps in 2017Is DevOps helping organizations reduce costs and time-to-market for software releases? What's getting in the way of DevOps adoption? Find out in this InformationWeek and Interop ITX infographic on the state of DevOps in 2017.