Have you received an email warning that your email or social media account password has “expired” and inviting you to follow a link to change it? If so, congratulations. You’re a target of the newest scam—and also one of the oldest in the book.
Yes, the “change password” scam has returned with a vengeance.
No one knows how common this particular form of online fraud is since it’s difficult to track. But phishing attacks, in general, are up from last year, according to a recent report from Wombat Security. Billions of email accounts are compromised every year.
“The attacker can acquire a million email addresses for a price of a latte,” says Igor Baikalov, chief scientist at Securonix, a computer security firm.
I’ve received the emails, many of my media colleagues have, and chances are, you have too. Fortunately, most of them go directly to your spam box. But not all of them.
“This scam works simply because a significant part of the population is just naïve to the most basic of scams,” says Robert Siciliano, a security analyst with Hotspot Shield.
“Change password” scams are making a comeback because people are confused. But the goal is the same: Criminals want to get into your social media account, where they’ll target your friends. Fortunately, you can protect yourself with a few easy steps.
Why the “change password” scam is back
Scammers are getting smarter about their phishing excursions, and their timing is perfect. Uncertainty about Europe’s strict new privacy law, the General Data Protection Regulation (GDPR), plus several recent data breaches that have prompted companies to send legitimate “change password” requests, is confusing to consumers. Given all that’s happened, there’s a presumption that the emails are legitimate, even though many are not.
“We’ve seen several phishing scams cite the newly enacted GDPR as a reason to request information from targets, taking advantage of the confusion around these new regulations and the deluge of related emails that internet users are already receiving,” says Harold Li, a vice president, at ExpressVPN, a provider of virtual private networks.
Don’t let this happen to you
Consider what happened to Stacy Caprio when she received a warning that her Facebook password needed to be updated. “I clicked the link to update it,” says Caprio, an internet marketer. “My account was hacked, and I had to go back in and change the password.”
Looking back, she says it was obviously a password heist. The scammers sent their illegitimate request to a newer email address that wasn’t even connected to her Facebook account.
Don’t blame Caprio. The “change password” scam is becoming so sophisticated that even professionals are having a hard time telling it apart from the real thing.
“The emails look real very real,” says Morey Haber, chief technology officer at cybersecurity company BeyondTrust. “Most of the basic content is well-formed, there are no spelling or grammatical errors, and the hyperlinks and email addresses are cleverly spoofed to resemble their legitimate counterparts.”
How to avoid a “change password” phishing attack
While the bad guys are constantly reinventing the “change password” scam, the steps to prevent it remain the same. They include:
- Use two-factor authentication on all your email and social media accounts. That way, even if criminals extract your password, they won’t get past the front door.
- Review any emails that appear to come from Gmail, Yahoo, Microsoft or any social network. “Check the contents of the email and verify carefully,” says Mike Bradshaw, a partner at ConnectMarketing, a business-to-business marketing agency. “Look for any misspellings, grammatical errors, incorrect links or email addresses.”
- Never click on any attachments that may come from a suspected spam threat, especially one requesting you to change passwords. “Question every email that is not a direct response from a request you’ve made,” says Leia Shilobod, CEO of InTech Solutions, an IT services company.
This is also a perfect time to check your antivirus software. A product like Norton can protect you from attachments that install malware on your computer. That, plus knowing how the “change password” scam works, why it’s back, and how to avoid it, will keep you out of trouble.
DISCLAIMER: This article expresses my own ideas and opinions. Any information I have shared are from sources that I believe to be reliable and accurate. I did not receive any financial compensation for writing this post, nor do I own any shares in any company I’ve mentioned. I encourage any reader to do their own diligent research first before making any investment decisions.
Mainz-based biotech company ActiTrexx receives €3.5 million in financing
The biotech company ActiTrexx has recently closed a Series A financing round, during which it raised $4.2 million (€3.5 million)....
Más Madrid proposes responsible cannabis legalization for adults
For Más Madrid, cannabis legalization, in addition to guaranteeing the freedoms of adult users and providing better tools to protect...
ESG investment: impact on the supply of financial products
The regulation promotes the incorporation of ESG criteria in its analysis and the redirection of its offer towards sustainable products...
Climate change: towards the adoption of a national MRV guide in Burkina
The opening ceremony of the workshop was chaired by Pamoussa Ouedraogo, the Director General of the Green Economy and Climate...
Chainlink (LINK) with big update and new possibilities
Chainlink has released the OCR (Off-Chain Reporting) update, which can open up new data sources and generally increases performance. It...
Business7 days ago
Virtual Reality (VR) mingles with team sports
Featured7 days ago
New capital injection for B2B fintech company Penta
Crowdfunding7 days ago
A crowdfunding campaign was launched by Biofarm, the first digital farm in Europe
Africa6 days ago
Burkina Faso validates a new project to increase access to energy in rural areas