Saturday, February 8, 2025
HomePhishingPhishing Campaign Targeting Your Netflix Account ask for Login Details, Credit card...

Phishing Campaign Targeting Your Netflix Account ask for Login Details, Credit card and Photo ID

Published on

SIEM as a Service

Follow Us on Google News

Phishing is one of the most common problems for Internet Users, hackers find a new innovative method to create believable URL’s to trick users. According to Google research, more than 15% accounts hijacked by using these social engineering methods. Crooks ran a Netflix phishing campaign to hijack user accounts.

Phishing campaigns run by crooks hijacking top brands and almost it is impossible to stop, With Recent Google research, they found 12.4 million potential victims of phishing kits; and 1.9 billion usernames and passwords exposed via data breaches and traded on black market forums.

Netflix Phishing Campaign

Netflix phishing campaign made a big news last week, it tricks the user to hand over login credentials, Credit card information and Photo ID.

Netflix phishing

Sophos team detailed on how this Phishing works, it starts with the Email coming from the reputed Netflix Email address with the warning that your account is “On hold”.

In the subject, attackers wrote Greek Letter Chi instead of “x”, the NETFLIX, word in the subject spelled with wired character.

The Email consist of “update now” button, on clicking it takes to a malicious site that posses like a legitimate site and asks victims to update their billing address, payment card details, Identity Info in successive steps.

Also Read Real-Time Intelligence Feed to Catch Malicious Phishing Domains SSL Certificate

To note the crooks made a convincing start that the Phishing website is HTTPS enabled with a green padlock, we should not trust HTTPS blindly and the TLS certificate is only to encrypt the connection between the browser and server.

Crooks tricked the victims with the faked Verified by VISA page to steal the payment card details, then attacks to upload your selfie to confirm your identity.

Once the crooks had all the details they redirect victims to the real Netflix login page. You can Copy the URL to analyzers that available over the Internet and ensure it’s Integrity. If it is a shortened URL you can unshorten it with the site and then analyze the actual URL.

To protect users IBM introduced a DNS security solution Quad9 that uses to protect users against most common cyber threats and their privacy.It keeps blocking you against known malicious domains and prevents your computer and IoT devices from connecting to malware or phishing sites.

Phishing and Keylogging are one of the most common problems for Internet Users, hackers keep on finding a new innovative method to create believable URL’s to trick users.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Autonomous LLMs Reshaping Pen Testing: Real-World AD Breaches and the Future of Cybersecurity

Large Language Models (LLMs) are transforming penetration testing (pen testing), leveraging their advanced reasoning...

Securing GAI-Driven Semantic Communications: A Novel Defense Against Backdoor Attacks

Semantic communication systems, powered by Generative AI (GAI), are transforming the way information is...

Cybercriminals Target IIS Servers to Spread BadIIS Malware

A recent wave of cyberattacks has revealed the exploitation of Microsoft Internet Information Services...

Hackers Leveraging Image & Video Attachments to Deliver Malware

Cybercriminals are increasingly exploiting image and video files to deliver malware, leveraging advanced techniques...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Hackers Exploit ADFS to Bypass MFA and Access Critical Systems

Hackers are targeting organizations using Microsoft’s Active Directory Federation Services (ADFS) to bypass multi-factor...

Hackers Exploiting 7-Zip Zero-Day Vulnerability to Deploy SmokeLoader Malware

A newly identified zero-day vulnerability in the widely used 7-Zip archiving software, designated as...

New Phishing Attack Hijacks High-Profile X Accounts to Promote Scam Sites

A new wave of phishing attacks has been identified, targeting high-profile accounts on the...