AfterDawn: Tech news

Twitter warns of phishing scam, two days late

Written by Andre Yoskowitz @ 27 Feb 2010 12:36 User comments (1)

Twitter warns of phishing scam, two days late

Two days ago we reported that there was a massive phishing attack being worked through Twitter, with people you are following sending personal messages asking you to click on a link that promptly took you to a new landing page where you are asked to sign in to Twitter.
By signing in, users were having their accounts stolen, and used to send more of the messages to other victims.

Today, Twitter finally released a warning about the attack:

Over the past few days, Twitter has been helping folks victimized by a phishing attack. Phishing is a deceitful process by which an attempt is made to acquire sensitive information such as Twitter usernames and passwords. The bad guys masquerade as someone you trust and may send you a Direct Message (DM) with a link. This DM may say something along the lines of, "LOL that you??" followed by a link to a fake Twitter login page. If you enter your credentials on that fraudulent page, the phishers can sign in as you and trick more people.



Anatomy of A Phishing Scam

Generally a phishing attack against Twitter users breaks down to a three-part process. First, accounts compromised in the manner described above send out messages to all accounts following them. Second, accounts that are newly compromised send out more messages. Third, the scammers behind the phishing attack make an attempt at monetization by sending out spam links instead of links to a fake login page. We fight phishing scams by detecting affected accounts and resetting passwords. However, it's better to stop them before they start.

Avoiding Phishing Scams

We designed the Direct Message system so that you could only get DMs from accounts that you choose to follow—this cuts way down on spam and attacks. Our Trust and Safety team identifies and deletes spam accounts every day. Still, we recommend against indiscriminately following hundreds or thousands of accounts without having a look first. To learn how you can avoid falling victim to a phishing scam or if you have other questions about keeping your Twitter account secure, please read Keeping Your Account Secure at our help site.


Thanks Twitter!

Previous Next  

1 user comment

127.2.2010 01:31

Not really twitters obligation to protect users from their own stupidity.

This message has been edited since its posting. Latest edit was made on 27 Feb 2010 @ 1:31

Comments have been disabled for this article.

Latest news

VLC hits milestone: over 5 billion downloads VLC hits milestone: over 5 billion downloads (16 Mar 2024 4:31)
VLC Media Player, the versatile video-software powerhouse, has achieved a remarkable feat: it has been downloaded over 5 billion times.
1 user comment
Sideloading apps to Android gets easier, as Google settles its lawsuit Sideloading apps to Android gets easier, as Google settles its lawsuit (19 Dec 2023 11:09)
Google settled its lawsuit in September 2023, and one of the settlement terms was that the way applications are installed on Android from outside the Google Play Store must become simpler. In the future, installing APK files will be easier.
8 user comments
Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets (06 Jun 2023 9:19)
Roomba Combo j7+ is the very first Roomba model to combine robot vacuum with mopping features. And Roomba Combo j7+ does all that with a very clever trick, which tackles the problem with mopping and carpets. But is it any good? We found out.
Neato, the robot vacuum company, ends its operations Neato, the robot vacuum company, ends its operations (02 May 2023 3:38)
Neato Robotics has ceased its operations. American robot vacuum pioneer founded in 2005 has finally called it quits and company will cease its operations and sales. Only a skeleton crew will remain who will keep the servers running until 2028.
5 user comments
How to Send Messages to Yourself on WhatsApp How to Send Messages to Yourself on WhatsApp (20 Mar 2023 1:25)
The world's most popular messaging platform, Meta-owned WhatsApp has enabled sending messages to yourself. While at first, this might seem like an odd feature, it can be very useful in a lot of situations. ....
18 user comments

News archive