Latest Warnings

August 13, 2016

Visa Alert and Update on the Oracle Breach

This post was originally published on this siteCredit card industry giant Visa on Friday issued a security alert warning companies using point-of-sale devices made by Oracle‘s MICROS retail unit to double-check the machines for malicious software or unusual network activity, and to change passwords on the devices. Visa also published a list of Internet addresses that may have been involved in the Oracle breach and are thought to be closely tied to an Eastern European organized cybercrime gang. The Visa alert is the first substantive document that tries to help explain what malware and which malefactors might have hit Oracle — and […]
December 7, 2017

Phishers Are Upping Their Game. So Should You.

This post was originally published on this siteNot long ago, phishing attacks were fairly easy for the average Internet user to spot: Full of grammatical and spelling errors, and linking to phony bank or email logins at unencrypted (http:// vs. https://) Web pages. Increasingly, however, phishers are upping their game, polishing their copy and hosting scam pages over https:// connections — complete with the green lock icon in the browser address bar to make the fake sites appear more legitimate. A brand new (and live) PayPal phishing page that uses SSL (https://) to appear more legitimate. According to stats released […]
December 19, 2017

Buyers Beware of Tampered Gift Cards

This post was originally published on this sitePrepaid gift cards make popular presents and no-brainer stocking stuffers, but before you purchase one be on the lookout for signs that someone may have tampered with it. A perennial scam that picks up around the holidays involves thieves who pull back and then replace the decals that obscure the card’s redemption code, allowing them to redeem or transfer the card’s balance online after the card is purchased by an unwitting customer. Last week KrebsOnSecurity heard from Colorado reader Flint Gatrell, who reached out after finding that a bunch of Sam’s Club gift […]
January 11, 2018

Bitcoin Blackmail by Snail Mail Preys on Those with Guilty Conscience

This post was originally published on this siteKrebsOnSecurity heard from a reader whose friend recently received a remarkably customized extortion letter via snail mail that threatened to tell the recipient’s wife about his supposed extramarital affairs unless he paid $3,600 in bitcoin. The friend said he had nothing to hide and suspects this is part of a random but well-crafted campaign to prey on men who may have a guilty conscience. The letter addressed the recipient by his first name and hometown throughout, and claimed to have evidence of the supposed dalliances. “You don’t know me personally and nobody hired […]