{"id":220372,"date":"2017-06-17T00:38:36","date_gmt":"2017-06-17T04:38:36","guid":{"rendered":"http:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/uncategorized\/whats-worse-than-getting-phished-getting-phished-and-sending-a-selfie-of-your-photo-id-and-credit-card-graham-cluley-security-news.php"},"modified":"2017-06-17T00:38:36","modified_gmt":"2017-06-17T04:38:36","slug":"whats-worse-than-getting-phished-getting-phished-and-sending-a-selfie-of-your-photo-id-and-credit-card-graham-cluley-security-news","status":"publish","type":"post","link":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/mind-uploading\/whats-worse-than-getting-phished-getting-phished-and-sending-a-selfie-of-your-photo-id-and-credit-card-graham-cluley-security-news.php","title":{"rendered":"What&#8217;s worse than getting phished? Getting phished *and* sending a selfie of your Photo ID and credit card &#8211; Graham Cluley Security News"},"content":{"rendered":"<p><p>Just the latest in a long line of  scams     <\/p>\n<\/p>\n<p>    Phishers are targeting PayPal users not only for their login    credentials but also for selfies of them holding their ID    cards.  <\/p>\n<p>    This scam campaign starts off like so many others. A user gets    an attack email falsely warning them that PayPal has suspended    their account \"for security precaution.\"  <\/p>\n<p>      \"Hi there,    <\/p>\n<p>      \"Our technical support and customer department has recently      suspected activities in your account.    <\/p>\n<p>      \"Therefore we have decided to temporarly suspend your account      until investigating your recent activiies. Such things can      happen if you clicked a suspecious link on social media or      gave your password to someone else    <\/p>\n<p>      \"We're always concerned about our customers security so      please help us recover your account by following the link      below.    <\/p>\n<p>    The phishing email gives itself away by its spelling errors and    strange grammatical usage. But it does get some things right.  <\/p>\n<p>    For instance, the scam does incorporate PayPal's logo and list    a valid (and publicly available, mind you) address for PayPal    at 353 Sacramento Street in San Francisco, California.  <\/p>\n<p>    Researchers at PhishMe report that the    attack campaign is currently hosted on a website    hellopc[dot]co[dot]nz, which an individual calling themselves    \"Mr.Dr3awe\" claims to have been hacked. The phishing kit used    in the campaign is buried in a subdirectory on the site. No    doubt Mr.Dr3awe hid the kit in this fashion in an attempt to    evade detection by anti-phishing vendors.  <\/p>\n<p>    Clicking on the phishing email's \"Let's Get Going\" link sends    the recipient to another website hosting a fake PayPal login    page. If they sign in, a subsequent page asks them for their    name, address, and credit card number.  <\/p>\n<\/p>\n<p>    For the purposes of gaining more control over the victim's    identity, the fraudsters then ask for something more. PhishMe's    Chase Sims explains:  <\/p>\n<p>      \"If the victim is willing to hand over their phone and credit      card numbers, could they possibly be willing to provide even      more personal information? How about a selfie? The next page      seeks to verify the identity with a photo of the victim      holding up a form of ID and credit card next to their face.\"    <\/p>\n<\/p>\n<p>    Uploading a valid image and hitting the \"Agree & Continue\"    button redirects the user to an official PayPal website.    Meanwhile, someone named \"najat zou\" in \"mansac, France\"    exfiltrates the data, at which point they can do whatever they    want with it.  <\/p>\n<p>    This     isn't the first    PayPal     phishing campaign, and it certainly won't be the last.  <\/p>\n<p>    With that said, users should avoid clicking on links in    suspicious emails, and they should never hand over their credit    card information to someone they don't know. They should also        protect their PayPal accounts with two-step verification    (2SV).  <\/p>\n<p>    Tags: data loss, phishing, Privacy, selfie, Spam  <\/p>\n<p>      Smashing Security audio podcast    <\/p>\n<p>      Follow @DMBisson    <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Read more: <\/p>\n<p><a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.grahamcluley.com\/paypal-phished-selfie\/\" title=\"What's worse than getting phished? Getting phished *and* sending a selfie of your Photo ID and credit card - Graham Cluley Security News\">What's worse than getting phished? Getting phished *and* sending a selfie of your Photo ID and credit card - Graham Cluley Security News<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Just the latest in a long line of scams Phishers are targeting PayPal users not only for their login credentials but also for selfies of them holding their ID cards. This scam campaign starts off like so many others. A user gets an attack email falsely warning them that PayPal has suspended their account \"for security precaution.\" \"Hi there, \"Our technical support and customer department has recently suspected activities in your account.  <a href=\"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/mind-uploading\/whats-worse-than-getting-phished-getting-phished-and-sending-a-selfie-of-your-photo-id-and-credit-card-graham-cluley-security-news.php\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"limit_modified_date":"","last_modified_date":"","_lmt_disableupdate":"","_lmt_disable":"","footnotes":""},"categories":[431593],"tags":[],"class_list":["post-220372","post","type-post","status-publish","format-standard","hentry","category-mind-uploading"],"modified_by":null,"_links":{"self":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts\/220372"}],"collection":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/comments?post=220372"}],"version-history":[{"count":0,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts\/220372\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/media?parent=220372"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/categories?post=220372"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/tags?post=220372"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}