Picture of a fishing hook

New phishing scam uncovered

Tricksters target PayPal users with email and phone ruse

Written by Lisa Kelly

A new phishing email is targeting PayPal users trying to trick them into calling a phone number and revealing their credit card information.

Security company Sophos says the email purports to come from PayPal and claims the recipient’s account has been the subject of fraudulent activity.

Unlike normal phishing scams, there is no internet link or response address, but instead a prompt to call a phone number and verify their details.

When dialled, users are greeted by an automated voice saying: ‘Welcome to account verification. Please type your 16 digits card number.’

If victims fall for the ruse, the scammer can steal the information and go on a spending spree. To appear legitimate, users are asked to re-enter their details if incorrect details are given.

Although the telephone number is American, Graham Cluley, senior technology consultant at Sophos says the fact that PayPal is global means people are more likely to be tricked.

‘This scam underlines a real problem for online companies in how they communicate with their customers. Many users are beginning to learn not to click on links in unsolicited emails, and only visit legitimate web sites, but how many would know whether a phone number for a web site is genuine or not,’ said Cluley.

He says it’s the first time a scam of this nature has targeted PayPal, but says it has been used to try and trick customers of some large American banks.

‘It it taking it to a new scale in the number of people it tries to trick because PayPal is global,’ he said.

He says this type of attack is likely to escalate with hackers ‘harvesting’ messages from corporate switchboard systems to sound even more like the legitimate company.

‘Phishers are changing their tactics. With voice over IP, they can set up a fake company switchboard on a computer,’ he warned.

‘The problem is that users know the url of their favourite websites, but they don’t easily know their telephone numbers,’ he said.

Cluley says online companies can improve the security of communication with their customers through increasing use of private messages.

‘If a customer is told via email that there is a message waiting for them and they have to log in to the site to get it, there is less scope for scams,’ he said.

What do you think? Email us at: feedback@computing.co.uk

Tags:

reader comments

related articles

 

Spammers warn of local nuclear meltdowns

New malware scam claims incidents in UK, Australia and Canada 12 Sep 2008

Fake anti-virus software on the rise

Security companies warn people to be vigilant 09 Apr 2009

Scammers dial up Western Union attack

New spam run uses fake money order to spread Trojan 27 May 2009

related whitepapers

today's top stories

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

Habitat gets a web site makeover

The furniture retailer is revamping its online presence to provide a fully transactional web site. CIO Jacques Dekock explains why 02 Jul 2009

Government aims to bolster UK's cyber defences

Is the UK’s first national cyber security strategy up to the task of co-ordinating the country’s response to digital threats? Computing investigates 02 Jul 2009

Focus resources on what really matters

IT has become too caught up in the drive for efficiency, at the expense of business success 02 Jul 2009

From tracks man to tax man

Phil Pavitt, outgoing chief information officer for Transport for London, talks to Rosalie Marshall about the lessons he will take to his new role at HMRC 02 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use social networking sites to look for a job?

Would you use social networking sites to look for a job?

Tell us what you think about job hunting through LinkedIn, Facebook, Twitter etc

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Phil PavittAnalysis

From tracks man to tax man

Phil Pavitt, outgoing chief information officer for Transport for London, talks to Rosalie Marshall about the lessons he will take to his new role at HMRC 02 Jul 2009

UPS worker making a deliveryAnalysis

Global standardisation delivers benefits at UPS

Delivery giant sees benefits of central IT solution 02 Jul 2009

Advertisement

Primary Navigation