- Attack code released for new DNS attack
- Parts of SF network still locked out
- Basic to-do apps for iPhone, iPod touch
- Spam King pulls prison vanishing act
- SCO Group: Its future is all used up
News | Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
A new Web site spoofs the PayPal online payment site and attempts to trick PayPal customers into divulging sensitive account and billing information. The fake Web site is the latest example in what security experts say is a rising trend of "brand spoofing" scams.
PayPal customers are directed to the site, www.paypal-billingnetwork.net, by an e-mail message that appears to come from the Mountain View, Calif., company. The message claims that due to a "recent system flush," the customer's billing and personal information is "temporaly unavailable" (sic).
Customers need to verify their identity by visiting the site or risk having their account canceled, according to the message, which is signed by "Jhon Krepp" from the "PayPal Billing Department."
The actual site is almost identical to PayPal's real site, with the same graphics, layout and wording. In fact, many of the links on the site point back to the actual PayPal Web site. PayPal could not be reached for comment about the scam site.
Adding to the ruse, visitors to the paypal-billingnetwork.net site are greeted with an authentic-sounding pop-up message.
"We've worked hard to help make PayPal even better! However, we have to ask you to re-enter your Billing Information," the message reads, in part. Visitors are asked to have their last PayPal billing statement and credit cards handy before entering the site.
PayPal members who do not enter their billing information will have their PayPal accounts canceled, according to the message.
After acknowledging this message, users are presented with a form that asks for a wide range of personal and financial information including Social Security number, driver's license number, date of birth and credit card information.
Unlike much of the rest of the site, however, the form does not reside on PayPal's Web site, but on a server at a different IP address.
Paypal-billingnetwork.net is registered through Vancouver, Wash., Web hosting company Dotster. Dotster did not immediately respond to requests for comment.
On Tuesday, e-mail filtering company SurfControl PLC of Scotts Valley, California, issued a warning about brand spoofing, saying it has noticed a jump since March in unsolicited e-mail messages tied to fraudulent brand spoofing scams.
DLP solutions are the first-last opportunity to correct a policy problem...and do so at the last frontier...- Schratboy
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.
Download the white paper.
Unauthorized applications: Taking back control
Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?
Download the white paper.
Comment