Phishing Scam Alert: New Breed of Phishing Scam Targets eBay, PayPal and Other Top Banking Sites

A powerful new phishing technique has been discovered that is able to spoof eBay, PayPal and other top web destinations without triggering anti-phishing filters in Internet Explorer 7. This phishing tactic is not initiated by clicking on a link in an email or instant message, but by actually typing in the address to these sites manually.

What to do:

Phishing scams are a serious threat:

Watch for bad grammar and poorly written statements when using online bank accounts.
Make sure your INVISUS Security software is updating automatically.
Make sure your computer is scanned regularly (as scheduled or done manually) with the INVISUS security suite.
If possible, download and use Firefox as your primary Internet browser, instead of Internet Explorer, until these issues have been resolved by Microsoft.
Make sure your Automatic Updates for Windows is turned on so you will receive any new patches for IE7 as soon as they are available.

More information:

After attempting to log in to PayPal and other online accounts, the user is prompted for his/her date of birth, social security number, mother's maiden name, credit card details and other sensitive information. Be aware that these online businesses will not ask for such detailed information in this way, and always look out for poor grammar. Badly written websites, emails and instant messages are a sure sign of a phishing scam. The PayPal phishing site reads:

"We have noticed an increasing fraudulent activity recently. In order to provide your security and protect you from fraudsters we have introduced a new system of identification that will help us to avoid any kind of fraud or unauthorised access. Please enter as more information as possible to provide your complete identification and to activate all the features of the new system."

Online websites that are known to have been hit are PayPal, HSBC Bank, eBay and Barclays Bank. More websites may be discovered soon. The phishing website for HSBC reads:

"Sorry, we unable to recognize digits from your security number. Please enter full security number below."

Those experiencing this attack have inadvertently installed an html injector. That means the victims' browsers are, in fact, visiting the PayPal website or other intended online account, but a file has attached itself to Internet Explorer and is managing to read and modify the web pages that are visited. After entering the information asked for, the html injector sends the user to the real website, but forwards all the sensitive information to the hacker. These phishing websites have bypassed Norton 360 and other major security phishing filters.

(Alert Release Date: 5/25/07)


Created by INVISUS®

www.myinvisusdirect.com/JSasser

Related Articles

New Ebay, Paypal Phishing Scam, Please Read

Phishing Scam Alert: New Breed of Phishing Scam Targets eBay, PayPal and Other Top Banking Sites A powerful new phishing technique has been discovered that is able to spoof eBay, PayPal and other top web destinations without triggering anti-phishing filters in Internet Explorer 7. This phishing tac...

May 25, 2007 Alert: New Phishing Scam

Phishing Scam Alert: New Breed of Phishing Scam Targets eBay, PayPal and Other Top Banking Sites A powerful new phishing technique has been discovered that is able to spoof eBay, PayPal and other top web destinations without triggering anti-phishing filters in Internet Explorer 7. This phishing ...

Paypal Mobile Payments

By Stu Woo   PayPal says it will process $3 billion in mobile-device payments this year, up from the company’s previous projection of $2 billion. The online payments service, which is owned by eBay, had projected last fall that it would process $1.5 billion in 2011. It raised that projecti...

How To Tell If A Site Is A Scam

You know I have been working online long enough to see so many sites out there that are scam site and other sites that are not a scam but when you Google them it looks like they are. Well there are some key ingredients that can jump out at you to tell you a site is a scam - the main one is t...

Selling Secrets of E Bay Revealed How to Auction Like an EBAY Pro.

E bay can be tricky you may think it is great to chase all the hot items and resell them as thisis what many eBay sellers try to do though usually this is a saturated strategy where eBay sellerslow-ball each other scrapping out lower profits. Th...

Top phishing sites

by Elizabeth Rogers, Don't take the bait. Find out where and how scammers trick victims into giving out their information.Your account has been blocked because of multiple log-in attempts. Your credit card is about to expire or has expired. We need your help to clear up fraudulent activity on your ...