Surety IT Security Alert – March 2019

Surety IT provides a monthly alert of the scams impacting Australian businesses including phishing scams, malware attacks and security
breaches/bugs.

You need to be particularly aware of –

1. ANZ

  • Using legitimate-looking fake ANZ landing pages, this latest phishing scam uses a display name of ‘Support’ is actually sent using Amazon
    web services and the domain ‘@anzsupport.cf’
  • The email explains the banks use of challenge questions to secure accounts and recipients are requested to confirm their challenge
    questions and answers.

 

  • Recipients who click on the link are led to an ANZ branded site to login using their Customer Registration Number and Password

 

  • Should recipients log in, they are directed to a second page requesting 3 challenge questions and answers are set.  Once this is
    completed they are redirected to the actual ANZ website.

 

  • The purpose of this scam is to harvest the login details of ANZ customers so cyber criminals can break into bank accounts.

2. Apple ID

  • In an attempt to steal Apple login credentials and are personal information, 2 new variations of emails scams are being sent using a
    display name of ‘Apple’.
  • A link is provided that requests recipients verify their Apple ID details, including billing information.

 

 

  • Those who click on the link are led to a 404 page which is believed to have been an Apple phishing page.
  • Red flags on this email include grammatical errors and the fact that recipients are not addressed by name.

3. Multiple Email Providers Brand-jacked

  • In a new phishing scam, multiple popular and well-established companies such as Office 365 and Yahoo have been brandjacked
  • The email is sent from a compromised mailbox with the ‘From’ field containing the email address of the actual sender and the ‘To’ field
    has been replaced with a generic display name of ‘Recipients’

 

 

  • Those who click on the ‘Download Attachments’ link are directed to a Onedrive branded phishing sites with additional links to select the
    email provider.

 

 

  • Should one of the email provider links be clicked, recipients are redirected to a fake login page. For example the Office 365 login page is
    below:

 

 

  • All links in this phishing scam are designed to harvest users’ confidential login details.

4. Xero

  • In this latest scam, cyber criminals have brand-jacked Xero and are sending hoax invoice notifications.
  • Using the display name ‘Xero Subscription Notifications’, the body of the email advises recipients that their invoice is ready and that
    the amount in the invoice will be debited from their credit card.
  • Including several links leading to legitimate Xero help pages, a link to the bill is also provided.

 

 

  • Those who click on the link containing the invoice number initiate a download of a malicious payload designed to infect systems.
  • The red flag in this email is that the real Xero commonly uses a PDF attachment rather than a link to an external website.

5. Egnyte & WeTransfer

  • Appearing to be generated by Egnyte and sent via the software company’s domain, this latest phishing scam is being sent using a display
    name of a compromised user.
  • Advising recipients that the sender has shared a file with them, a link is provided to view a PDF file.

 

 

  • Should the link be clicked, recipients are redirected to an authentic looking WeTransfer email for sharing a file.

 

 

  • The ‘View Folder’ link leads to an Office 365 phishing page.

 

  • Well executed, cyber criminals have utilised high quality graphical elements whilst spoofing all 3 brands – Egnyte, WeTransfer and Office
    365.

If you’d like any further information, assistance with your cyber security or you don’t know where to start please call us on  1300
478 738

or email us at  info@suretyit.com.au.

Contact Us

Name(Required)
This field is for validation purposes and should be left unchanged.

Find out how we can help with your IT challenges.

About the author:

Picture of Ash Klemm

Ash Klemm

Ash has over 20 years of experience in sales and marketing. His journey from a casual salesperson at Chandlers to State Manager at a national IT distribution company, while battling health issues, including a double lung transplant in 2015, gave him the experience, know-how, tenacity, and marketing insight, to find solutions and help businesses grow. After spending several years in the ivory tower of state management, Ash missed the genuine connection of face to face meetings and helping make a difference to businesses in need. His authentic, conversational, and easy-going nature helps our customers feel at ease and shows them we are a brand to trust. Ash spends his days advocating for our customers to ensure they receive the best possible service in a timely fashion. Ash is also the in house chair builder. His curiosity and natural problem-solving ability make him the perfect first call for all our new customers to help determine what is wrong, how Surety IT can help and what the best solutions are moving forward.
Scroll to Top