Showing posts with label Phishing Scams. Show all posts
Showing posts with label Phishing Scams. Show all posts

Monday, October 1, 2012

Reborn Hoax -- Reality of 'Visit the New Facebook/Timeline' Link

Beware! Its a Cyber World -- 'Visit the New Facebook' Link: Summary

A message is widely spreading on social network 'Facebook' claiming that if any Facebook user receives a message from someone, even from his/her friends' list, asking to click a link titled as 'Visit the New Facebook'; don't open the link as it may lead the user to a hacker's trap and may lose the access to his/her Facebook account.

The message looks like:

Reborn Hoax -- Reality of 'Visit the New Facebook/Timeline' Link
And reads as:

"W A R N I N G .. ! ! .....W A R N I N G .. ! !
If someone in your profile or a
friend sends you a LINK that says
'VISIT THE NEW FACEBOOK' do
... NOT open it. If you do, you're
... ... ... ... ... sure to say GOODBYE to your
Facebook account. This is actually
a trap by a HACKER who steals
your details and REMOVES you
permanently from your own
page. please COPY and paste it
on your wall and send it to your
groups too"
Beware! Its a Cyber World -- 'Visit the New Facebook' Link: Explanation
There are plenty of phishing scams and hacking attempts from internet fraudsters and cyber criminals trying to gain access to Facebook accounts; but in this specific case there's no reality and the warning is totally baseless. 
According to Facebook, "this re-worded hoax message is currently circulating. The original, whose warning was "Visit New Facebook", began circulating about a year ago. Now, with the recent introduction of the Timeline, someone has changed the message to say "Visit New Timeline", but the claims in the message are still untrue." 
According to Snopes; this warning is nothing more than a hoax spread by well-meaning but credulous Facebook users: there have been no recorded instances of "Visit the new Facebook" come-ons containing malicious links of any kind (only warnings about them) and none of the major computer security/anti-virus software companies has reported users' actually encountering Facebook info-stealing malware that reached them in such fashion. 
Therefore, the simple advice is not to pass on such sensational alerts without confirmation to your Facebook friends. Some hoaxes malign companies and individuals. You don’t want to be responsible for damaging the reputation of an innocent party just by automatically posting a story to your wall. It is great to spread useful information and legitimate warnings to your friends – just do a little fact finding before clicking “share.” 

Wednesday, February 29, 2012

Phishing Scam: Internal Revenue Service (IRS) Tax Refund Notification via Emails

Beware! Its a Cyber World -- Internal Revenue Service (IRS) Tax Refund Notification: Summary

A mail is circulating purportedly from Internal Revenue Service (IRS) United States Department of the Treasury enticing the recipients to use the attachment for applying to apply for tax refunds, calculated recently by the Department. 

The mail is a scam and has no grounds as identity theft tops the IRS's list of common scams that taxpayers can encounter at any point during the year.

See the contents of the mail below before heading towards further explanation:

=====================================================
From: Internal Revenue Service (message07621@34234.irs.gov)
To: (Omitted by Author of this article)
Sent: Wednesday, 29 February 2012 8:39 AM
Subject: Tax notification for
(Omitted by Author of this article)

Internal Revenue Service (IRS)
United States Department of the Treasury

After the last annual calculations of your fiscal activity we have
determined that you are eligible to receive your tax return.

Due to invalid account records we were unable to credit your account.
Please submit a verified tax return request as soon as possible.

Your tax return request form is attached to this email.

After you  submit the tax return request, please allow us
4 to 12 working days in order to process it.


Regards,
Internal Revenue Service

February 28th, 2012 (10:39:11 p.m.)
Document Reference: (1442361382).
====================================================
Beware! Its a Cyber World -- Internal Revenue Service (IRS) Tax Refund Notification: Explanation

The mail message asking recipients to use the attached form for submitting tax refund request actually leads to a look-alike IRS website showing the form to be filled up by the recipient to submit tax return. The form on the fake IRS website is shown below:

SCAM: Internal Revenue Service (IRS) Tax Refund Notification

 
If you're still waiting to file for your tax refund, you better act quick- or someone else could get it instead.

The IRS is dealing with a surge of reports in identity tax fraud, and web based convenience isn't helping.

"Anytime something's very easy for you to do it's also easy for someone else to exploit," says David Powell of Teklinks.

He warns it's not hard for these web thieves to exploit their victims.

IRS's own website mentions it as:


Suspicious e-Mails and Identity Theft


The Internal Revenue Service has issued several recent consumer warnings on the fraudulent use of the IRS name or logo by scamsters trying to gain access to consumers’ financial information in order to steal their identity and assets. When identity theft takes place over the Internet, it is called phishing.

Suspicious e-Mail/Phishing

Phishing (as in “fishing for information” and “hooking” victims) is a scam where Internet fraudsters send e-mail messages to trick unsuspecting victims into revealing personal and financial information that can be used to steal the victims’ identity. Current scams include phony e-mails which claim to come from the IRS and which lure the victims into the scam by telling them that they are due a tax refund.

Phishing and Other Schemes Using the IRS Name

The IRS periodically alerts taxpayers to, and maintains a list of, phishing schemes using the IRS name, logo or Web site clone. If you've received an e-mail, phone call or fax claiming to come from the IRS that seemed a little suspicious, you just may find it on this list.

Tuesday, October 18, 2011

Latest Phishing Scam: Account Update Warning Notification From PayPal

Beware! Its a Cyber World -- Account Update Warning Notification From PayPal




Today I received the following warning notification, apparently from PayPal, asking to update the PayPal account information. It's a latest Phishing Scam and a 100% complete attempt to fool the recipients. 


It is not from PayPal. One way you can tell is that it does not contain your name, exactly as it was given in your PayPal account. PayPal always uses that information in all communication with you.

A link is provided in the mail to update Paypal account information which leads to a fake (look-alike) Paypal website. Screenshot is sown below:



Fake (Look-alike) PayPal Account Update Website Homepage
First go through the contents of the mail below, before jumping to the conclusion at the end:






==========================================================
From: PayPal (noreply@paypal.com)
To:
Sent: Tuesday, October 18, 2011 7:56 PM
Subject: Warning Notification








Warning Notification

Dear PayPal Customer,

It has come to our attention that your PayPal account information needs to be updated as part of
our continuing commitment to protect your account and to reduce the instance of fraud on our website.

If you could please take 5-10 minutes out of your online experience and update your personal records
you will not run into any future problems with the online service.

However, failure to update your records will result in account suspension. Please update your records
before October 20, 2011.

Once you have updated your account records, your PayPal account activity will not be interrupted and
will continue as normal.

Click here to update your PayPal account information (Link removed by author)

Sincerely,

PayPal


© 2011 PayPal Inc. All rights reserved. PayPal is located at 2211 N. First St., San Jose, CA 95131.
==========================================================
Account Update Warning Notification From PayPal -- Conclusion

When I opened the original Paypal website, I found quite different homepage shown below:



Original Paypal Website Homepage

You can see the difference in original and fake (look-alike) Paypal website.

Fortunately, I don't have PayPal account because this service is not available in my country of residence. Therefore, I'm one hundred percent sure that its a trap set by cyber scammers. 

Furthermore, I got enough evidence that it is a Phishing Scam  by going through following links:




http://www.virtu-software.com/anti-spam/scam_paypal.asp

http://www.newblood.com/developers/phishing-scam-alert-service.php

http://www.auditmypc.com/pay-pal.asp

Sunday, July 10, 2011

Phishing Scam - Yahoo Account Upgrade Notification

Beware! It's a Cyber World - - Yahoo Account Upgrade Notification




Received this mail early in this week asking for upgrade yahoo account with the help of an html file attached with the mail screen shot is .... 

Continue Reading on the link given below:




No Spam, Please

Sunday, July 3, 2011

Phishing Scam: Yahoo! Mail is Upgrading - - Asking for Account Revalidation Due to Exceeded Storage Limit

Beware! Its a Cyber World - - Yahoo! Mail is upgrading

A more sophisticated spam mail (Phishing Scam) to steal your personal log-in details is invading the inboxes of Yahoo mail users. In the past the cyber criminals have tried with a different way with the same intentions and I have shred these mails also on this forum to save my readers from any kind of cyber victimization.   

In last year's December  I received with 'Yahoo Alert' in subject line. The sender asking for personal log-in details. The in February, 2011 the cyber cowboys again came with new idea and mail received with subject line as 'AUTO CONFIRMATION(ACCOUNT)'. 

Today I received the following mail with the same intentions to steal the personal information to use it for their malpractices on the internet. Go through the mail below, then jump to my conclusion afterward:
 



=================================
From: Yahoo! Alert
Sent: Mon, July 4, 2011 7:36:06 AM
Subject: Yahoo! Mail is upgrading


*Your Mailbox Has Exceeded It Storage Limit As Set By Your Administrator,
And You Will Not Be Able To Receive New Mails Until You Re-Validate It. To
Re-Validate
  - Click Here (Link Disabled Intentionally)

Make sure you fill the correct data  to increase your mail size, We apologize for any inconvenience. Thank you for your anticipated  co-operation.
Note: Failure to comply may result lost of your account within 24 hours.
Thanks. System Administrator center.

====================================================

Beware! Its a Cyber World - - Conclusion 

When I clicked the link provided in the mail for account re-validation, the form opened show here below:

Yahoo! Mail is upgrading - Fake Account Re-validating Form (Screen Shot)
Just imagine the mail is sent to update the Yahoo Account and the form is powered by Google Docs; which tells the story that its just an effort to steal personal information of internet users which later can be used to harm them financially.

Please keep on sharing your comments and similar fraud mails and scams; so that our efforts can save the internet users from any kind of cyber victimization. 

Saturday, April 9, 2011

Online Banking Alert From ICICI Bank - - A New Phishing Scam for ICICI Customers to Steal Their Personal Information

Beware! Its a Cyber World - - Summary: Online Banking Alert From ICICI Bank

Email, purporting to be from India's ICICI Bank claims that the recipient's account is locked due to invalid attempts of logging-in supposedly done to secure the personal information of recipient. Further, it is instructed to update the information through the link given in the mail.

I received this mail today from ICICI Online Banking Service; but I have never been a client of ICICI bank. Even I never applied for any account in ICICI bank. 

No doubt its another phishing scam ..... the email is not from the ICICI Bank. Instead it is a phishing scam designed to trick bank customers into handing over their bank login details to Internet scammers.

Once anyone will click the link given in the mail it will lead to a look-a-like website of ICICI. The screen shot is given below:



 Following are the contents of mail from cyber criminals:


=====================================================

From: ICICI BANK (service@icici.com)
Sent: Sat, April 9, 2011 4:13:05 PM
Subject: Online Banking Alert



Dear Customer,


We've noticed that you experienced trouble logging into your ICICI Online Banking Account.

After three unsuccessful attempts to access your account, your ICICI Online Profile was locked. This has been done to secure your accounts and to protect your personal information from being compromised. ICICI Bank is committed to making sure that your online transactions are secure.

To unlock your account, and verify your identity please follow this link and sign in:
{link removed}
Sincerely,
ICICI Bank
Online Customer Service

=======================================================
Beware! Its a Cyber World - - Explanation: The message is not from the ICICI Bank and the claim that the recipient's bank account has been locked is a lie designed to trick him or her into the trap set by cyber criminals. Like other legitimate financial entities, the ICICI Bank does not send unsolicited emails asking its customers to provide bank account log-in details. In case of any mail coming from Bank or Financial Institution be careful about following points:
REMEMBER – Bank or Financial Institution will never contact you & ask for your logon details or password or any other personal information over email.

NEVER - follow a link within an email to use Internet Banking facilities - Bank or Financial Institution will never ask you to login from a link in email. - Never tell password(s) to any body.

BEWARE - of fraudulent websites looking similar to your Banking website. - of scam e-mails which may contain virus or be linked to a fraudulent website

Monday, February 21, 2011

Phishing Scam Alert - - "Billing update must be performed" Notice From AOL

Beware! It's a Cyber World - - Summary:

An Email pretending to be from AOL states that the recipient must follow a link to update account information or limitations will be placed on his or her AOL service.

In fact, the email is a phishing scam, as the message is not from AOL.  The scam is devised to trap recipients into providing personal and financial details to Internet criminals. The link in the email points to a bogus website that asks users to submit information via an online form.

Take a look below for the contents of the mail:
======================================================
Subject: Billing Update Must be Performed

Billing update must be performed


Dear AOL Member,

Our records indicate that your account hasn't been updated as a part of our regular account maintenance. Our new SSL servers check each account for activity and your information has been randomly chosen for verification. AOL Member Services strives to serve their customers with better and secure banking service.

Notification: Failure to update your account information may result in account limitation at shopping on our portal.

Update your information

To re-secure your account, just confirm your personal information.

Sincerely,
AOL Member Services

Please note that this email address cannot accept replies.
========================================================

Beware! Its a Cyber World - - Explanation:

This email, which claims to be from Internet service provider AOL, informs the recipient that he or she must update AOL account details or risk a subsequent limitation of services. The message claims that the account has been randomly chosen for verification by AOL's "new SSL servers". It warns that the account has not been updated as part of AOL's regular account maintenance procedure and urges the recipient to click the "update your information" link in order to "re-secure" the account.

However, the email is not from AOL. In fact, the message is a phishing scam designed to steal personal and financial information from AOL customers. Those who fall for the ruse and click the "Update" button will be taken to a fraudulent website designed to closely resemble a genuine AOL page. As shown in the screenshot below, the fake site asks users to provide a significant amount of private information, including credit card numbers and social security numbers:

All information on the bogus website will be sent to criminals who can subsequently use it to commit credit card fraud and identity theft. To further the illusion, secondary links on the fake site actually open genuine AOL web pages. Moreover, when a victim has finished filling in the information on the bogus form and clicked the "Submit" button, he or she will be automatically redirected to the genuine AOL website.

The phishing email itself is also designed to resemble a genuine AOL message.

AOL customers are regularly targeted by phishing scammers. AOL will not send out unsolicited emails warning customers that their account will be limited or suspended if they do not follow a link and provide personal information. In fact, any message that claims that you must update information for a bank, government department or online service by following a link or opening an attachment should be treated with suspicion.

Monday, February 14, 2011

Yahoo ID Verification Department - - Scam Mail From Pretending to be From Yahoo to Steal Recipient's Personal Information

Beware! It's a Cyber World: Yahoo ID Verification Department

Dear readers, beware of following mail from Yahoo ID Verification Department that can hit your inbox also or might be already there in your spam box. This is clearly an effort to steal your private information. Don't respond at all to the mail coming from inc@yahoo-inc.com.

We have already shared few of them under Phishing Scam.


============================================================
From: Yahoo ID Verification Department (inc@yahoo-inc.com)
Sent: Mon, February 14, 2011 3:57:51 AM
Subject: ****(AUTO CONFIRMATION(ACCOUNT)* Verification{KMM69467VL055834KM)!!!




Dear User,

We are sorry to inform you that we are currently working on securing our
server, during this process accounts which are not manually verified by us
will be deleted, Please confirm and submit your information for manual
verification.

Please provide these informations:
Email Name:.............
user account:.............
password:.............
date of birth:.............
occupation:.............
country:.............

Warning Account owner that refuses to update his/her account after two
weeks of receiving this warning will lose his or her account permanently.
Thanks Yaho0
=================================================================



Please keep on sharing your comments and similar fraud mails and scams; so that our efforts can save the internet users from any kind of cyber victimization.
 

Sunday, January 23, 2011

Phishing Scam for Bigpond, Australian Internet Service Provider, Customers - - Required Log-in Details Due to Upgrading of Database Servers

Beware! Its a Cyber World - - Summary:

Email pretending to be from Australian Internet Service Provider Bigpond, claims that, due to an upgrade of database servers, the recipient must reply with his or her log-in email address and password to ensure continued service.

In fact, the message is not from Bigpond and the claim that users must provide their account details because of a server upgrade is untrue. The message is a phishing scam designed to steal account details from Bigpond customers. 

Let's have a look to the mail contents:

==========================================
Subject: FINAL WARNING

Attention: BIGPOND Email User

BIGPOND is upgrading database Servers from the old Servers (Nol06769) to the new Servers (No521766). You are to fill the details below to enable us upgrade and Verify from the old server.

FILL THE DETAILS BELOW OR ANYWHERE IN THE MAIL
Email Address:
Password:
Address:
City:

Attention: BIGPOND Account owners who do not update his or her account immediately you receive this Notification will have problems using our online facilities effectively. Notification Code:CZX1G13ABJ

The "BIGPOND "Upgrade Team Thanks for your co-operation.
=============================================

Beware! It's a Cyber World  - - Explanation:

According to this email, which purports to be from Australian Internet Service Provider Bigpond, the recipient is required to reply to the message with his or her account email address, and password. Supposedly, the information is required because Bigpond is upgrading its "database servers". The message warns that customers who do not provide the requested information will have problems using the service as a result. The email claims to be a "final warning" about the upgrade from the "Bigpond Upgrade Team".

However, the email is not from Bigpond and the claim that customers must provide account details because of a server upgrade is untrue. In fact, the message is a phishing scam designed to trick Bigpond customers into divulging private account details.

Those who fall for the ruse and reply with the requested details will in fact be handing over access to their accounts to Internet criminals. Once the scammers have this account information, they can then login to the customer's Bigpond account at will, steal or misuse any information stored there and use the customer's email account to send spam or other scam messages. The scammers are likely to change the customer's password so that he or she can no longer access email or Bigpond online services.

Bigpond - or any other legitimate service provider - will never ask customers to send passwords or other private information by replying to an unsecure email. Any message that asks you to reply with such information should be treated as highly suspicious. And, even if Bigpond was upgrading its servers it would not require customers to provide account details via an email. Bigpond, and its parent company Telstra, are regularly targeted by phishing scammers as are other telecommunications companies in Australia and elsewhere around the world.

Scammers often use similar ruses to trick recipients into handing over access to webmail accounts such as those provided by Hotmail and Gmail.

While the version discussed here asks recipients to directly reply to the email with their details, other phishing scams may ask recipients to follow a link that opens a bogus website where they are requested to provide details via an online form. Other variations of such scams may ask users to open and fill in a form attached to the email.

Users should be very cautious of any email purporting to be from their Internet Service Provider or webmail service that asks them to provide passwords and other account details either via email or via an online form.

Wednesday, January 5, 2011

$150 Survey From Coca Cola (Fake Website Survey Form): New Phishing Scam to Steal Personal Information and Credit Card Details

Beware! Its a Cyber World - - Summary:

An email pretending to be from Coca Cola claims that the recipient can receive $150 by following a link and filling out a short online survey.

The message is not from Coca Cola and the recipient will not receive money for participating. The email is a phishing scam designed to steal credit card and other personal information. Those who follow the link and fill in the "survey" will be asked to submit identity and credit card details, apparently so that the survey payment can be transferred to their account. However, all information submitted on the bogus website will be collected by scammers and used for credit card fraud and identity theft. 

Let's see the mail and it's contents
=====================================================
Subject: ***Cola Survey; Happy New Year***

You have been selected to participate in a public opinion poll conducted by Coca Cola, a non-partisan polling organization.

The poll is about current events at the national level and your views about them. It is short and should take you only 5-7 minutes to complete. All of your answers will be kept strictly confidential and will be used only for legitimate research purposes.

To take the poll, click on this link:
[Link to bogus website removed]

Each person taking the poll will win $150
Thank you for your participation!

Sincerely,
Survey Manager
===========================================================
Beware! Its a Cyber World - - Explanation:

According to this email, the "lucky" recipient has been selected to participate in a public opinion poll conducted by Coca Cola. The message claims that each person who participates in the survey will receive $150 for his or her trouble. The recipient is urged to click a link in the message in order to take the poll.

However, the message is not from Coca Cola and the promise of $150 for poll participants is simply the bait used to entice recipients into following the link. In fact, the message is a phishing scam designed to steal credit card details and other personal information.

Those who fall for the ruse and follow the link will be taken to a crudely rendered website garishly decorated with Coca Cola graphics. Once there, they will be asked to fill in a very brief one-page survey pertaining to their consumption of Coca Cola products. After they click the "Submit" button on the bogus survey page, they will then be directed to a second page that asks them to provide sensitive personal information and credit card details. The page informs victims that the information is required to allow transfer of the poll participation payment. A screenshot of the bogus web form is displayed below:



All information submitted on the bogus form can be collected by Internet criminals and used to commit credit card fraud and identity theft.

As such scams go, this example is actually rather crude. Perhaps because the scammers responsible have used an earlier scam attempt as a template, the scam email rather bizarrely refers to Coca Cola as a "non-partisan polling organization". Moreover, the scam email claims that the poll questions will be about "current events at the national level" when the questions in the bogus poll are actually related solely to Coke products. And, while the email promises $150, the bogus website instead sets the payment at £150.

Scammers regular use fake surveys to steal personal and financial information from Internet users. In 2009, scammers claimed that Australian McDonald's customers could receive $50 just for filling out a short "Customer Satisfaction Survey". As in this example, the scammers used a bogus web form to steal credit card information from people who were tricked into participating. More generic versions that do not name a particular company have also been distributed over the last few years. These versions bill themselves as "quick and easy surveys" and again promise recipients quite sizable payments for participating. These generic versions are also designed to steal credit card details via a fake survey form.

Internet users should be very wary of any messages that promise a payment for filling out a short survey. Companies may certainly conduct customer surveys and may even reward participants by entering them into a prize draw or offering free or discounted products. In some cases, they may even pay customers who participate in in-depth surveys or organized focus groups. However, they are extremely unlikely to pay such a substantial fee for filling out a small and insignificant survey. Nor would any ethical company resort to sending out unsolicited bulk emails in order to entice consumers to participate.

If you receive one of these bogus survey messages, do not participate as instructed. Do not click on any links in the messages or open any attachments that they may contain.

Monday, January 3, 2011

eBay 'Respond Now' Phishing Scam - - Reality of the Mail Pretending to Be From eBay on Behalf of Likely Buyer

Beware! It's a Cyber World - - Summary:

A rapidly circulating email pretending to be a question sent via eBay from a likely buyer, instructs the recipient to answer by clicking the "Respond Now" button.

In fact, clicking the "Respond Now" button opens a bogus login webpage as the email is not from eBay. The email is a phishing scam designed to steal eBay login details from recipients. 
===========================================================


Subject: Question about Item #492297780326 - Respond Now

Question about Item #492297780326 - Respond Now


eBay sent this message on behalf of an eBay member through My Messages. Click the "Respond Now" button to answer the question.

Item: 492297780326

This message was sent while the listing was active.
********* is a potential buyer.

Hello, Shipping to Washington, DC please?
Thank you,
Betsy Respond to this question



Responses in My Messages will not include your email address.

Thank you,
eBay

=========================================================
Beware! It's a Cyber World - - Explanation:

Online auction website eBay is almost constantly targeted by scammers intent on stealing login and other personal information from eBay members. Such scam messages take many forms, including supposed complaints from other members, bogus "eBay administration" messages that claim that members must upgrade account details, and, as in the version discussed here, fake queries from potential buyers about item listings.

In this particular phishing campaign, the scammers have sent out bogus messages that supposedly contain a question about shipping costs from a potential buyer. The email, which at first glance appears to have been sent via the eBay website, requests recipients to click the "Respond Now" button included in the message, ostensibly in order to answer the "buyer's" query. However, the email was not sent via eBay and does not contain a genuine question from an eBay user. In fact, the email is an attempt by Internet criminals to steal confidential eBay login details from unsuspecting users.

In order to further the illusion of legitimacy, the bogus emails are designed to closely resemble genuine eBay messages. They include eBay logos, colour schemes and formatting. Those who fall for the ruse and click the "Respond Now" button will be taken to a fraudulent website that mimics a genuine eBay page. Once on the fake site, the victim will be urged to "login" with his or her eBay username and password supposedly so that a response to the "question" can be provided. However, the login details entered on the fake site will be sent directly to the scammers who can then use them to access the victim's real eBay account. Once they have managed to hijack the victim's account in this way, the scammers can use it to commit fraud using the victim's identity. In some versions of the scam, the victim may also be asked to provide credit card and other personal information via secondary forms displayed on the bogus website.

Given the prevalence of phishing scam attempts that target eBay, users should be very cautious of any emails that ask them to click a link and provide login details or other personal information. Rather than follow a link in an email, a safer method is to go directly to the eBay website via a new browser window and login. Genuine eBay messages will appear in the "Messages" section of your eBay account. eBay has published several basic tips on protecting yourself from scammers on its website along with more comprehensive information about phishing scams.

Many other high profile online entities and financial institutions are regularly targeted by phishing scammers. Phishing remains one of the most common types of Internet fraud and many people all around the world fall victim to such scams every day. 

Tuesday, December 21, 2010

Another Scam for Facebook Users - - 'Facebook Account Update' Phishing Scam

Beware! Its a Cyber World - - Summary:

An recently spreading email, purporting to be from Facebook, claims that Facebook is implementing a new log-in system and that the user must therefore follow a link in the message to update his or her account.

In fact, this a clear cut phishing scam by cybercriminals just to steal the recipients' log-in details and information to use the use for their malicious puposes in the future. 

Let's have a look to mail contents below here:
=========================================================
Subject: Facebook Account Update

Dear Facebook user,

In an effort to make your online experience safer and more enjoyable, Facebook will be implementing a new login system that will affect all Facebook users. These changes will offer new features and increased account security.

Before you are able to use the new login system, you will be required to update your account.
Click here to update your account online now.

If you have any questions, reference our New User Guide.
Thanks,
The Facebook Team

========================================================
Beware! Its a Cyber World - - Explanation:

This email, which purports to be from social networking website, Facebook, claims that Facebook is about to implement a new login system. The message claims that Facebook users must follow a link in the message to update their details before they will be able to use the new system.

However, the email is not from Facebook and the claim that Facebook users are required to update their account details is untrue. In fact, the email is a phishing scam designed to steal Facebook login details from unsuspecting users. To further the illusion of legitimacy, the email is designed and formatted to resemble a genuine Facebook message. Those who fall for the ruse and follow the link in the bogus email will be taken to the following fake Facebook login page:


The fake login page has been created so that it looks like a genuine Facebook login.

If a victim enters his or her username and password on the bogus page and clicks the "Login" button, the following pop-up notice will be displayed:


The notice claims that the account confirmation has been completed. Clicking the "OK" button takes the user to the genuine Facebook website.

Users who submit their login details on the fake page will actually be sending their username and password directly to the criminals running the phishing scam. Because the scam notice redirects to the genuine Facebook website, the victim may not realize that his or her account has been compromised until it is too late.

Once they have stolen this information, the scammers can then login to their victim's real Facebook account and pose as the genuine user. They can also change account details thereby effectively locking the genuine user out of his or her Facebook account. Having successfully hijacked the user's account, the scammers can then use it to post spam and scam messages in the victim's name and steal any personal information stored in the account.

Phishing scammers regularly target Facebook users. Users should be very cautious of any email that claims to be from Facebook and asks them to click a link and provide login or other personal information.
Related Posts Plugin for WordPress, Blogger...