MacUpdate Weekend Sale :This weekend MacUpdate has slashed prices on Painter 12 and Painter Lite. Painter 12 retails for $429, but has been reduced by 54% to $199. Painter Lite has seen a 58% price cut from $69 to $29. Hurry, because these deals are only available until May 19th 2013.      
toggle

AAPL Stock: 433.26 ( -1.32 )

http://www.macnn.com/articles/09/02/27/new.mobileme.scam/

MobileMe users targeted in spreading phishing scam

updated 03:35 pm EST, Fri February 27, 2009

 

New MobileMe scam


MobileMe subscribers are again being targeted in an updated phishing scam, investigation reveals. Similarly to earlier attempts, the scam beings with an e-mail, prompting people to update their credit card information in advance of an upcoming renewal date. A link is provided to log into MobileMe, but in reality it guides users to a different domain -- "http.apple-billing.me.uk" -- which spoofs the design of the Apple online store, and tricks unwitting visitors into sharing credit card data.

Making the site a more serious threat is the fact that, due to not attempting an SSL connection, it is not automatically flagged by Extended Validation filters, used in modern browsers such as Safari 4. The scam message can be identified through unusually poor writing however, and real Apple notifications supply a person's username, as well as the last four digits of the on-file credit card.

Despite the use of a seemingly British domain, probing is said to show that the registration belongs to a Nike Jegart in Lamy, New Mexico. It is uncertain if the ownership listings are accurate or false, as a skilled hacker or criminal can create misleading attributions.




by MacNN Staff

Post tools:

TAGS :

 security, phishing, MobileMe
toggle

Comments

  1. afaby

    Fresh-Faced Recruit

    Joined: Jul 2005

    +4

    The domain...

    was most likely also purchased with a stolen credit card number, so I doubt that person is the real owner.

  1. byRyan

    Fresh-Faced Recruit

    Joined: Jun 2007

    +4

    nike?

    and is there even a real person named Nike? Who would do that to their kid?

  1. testudo

    Forum Regular

    Joined: Aug 2001

    -3

    ummm

    Making the site a more serious threat is the fact that, due to not attempting an SSL connection, it is not automatically flagged by Extended Validation filters

    Isn't this true of any site that isn't https? They don't make a secure connection, so the browser doesn't tell you it isn't secure.

    I would think it would be "more of a threat" if it DID make an SSL connection.

  1. Gazoobee

    Fresh-Faced Recruit

    Joined: Feb 2009

    +5

    one of these days ...

    ... there is going to be a hacker with the skill to do this kind of stuff who also knows how to read and write English.

    Then we are in trouble.

  1. ajhoughton

    Fresh-Faced Recruit

    Joined: Mar 2004

    -1

    skill? what skill?

    Skill? What skill? Any idiot can set something like this up; you don't have to know much about anything to do so. Especially in this case, since whoever did it didn't even bother with SSL (which complicates matters somewhat).

Login Here

Not a member of the MacNN forums? Register now for free.

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

MacNN Sponsor

Recent Reviews

Brother HL-3170CDW LED Printer

We've mentioned before that we are far from a paperless society. For now, at least, there are tasks that require a piece of paper for ...

HTC One

It is hard to overstate just how critically important the HTC One is to the Taiwanese company’s fortunes. Despite its alarming decline ...

Samsung Galaxy S 4

Samsung's new flagship Android smartphone, the Galaxy S 4, faces even stiffer competition than its popular predecessor. With a five-in ...

toggle

Most Commented