Categories: Phishing

Phishing Campaign Targeting Your Netflix Account ask for Login Details, Credit card and Photo ID

Phishing is one of the most common problems for Internet Users, hackers find a new innovative method to create believable URL’s to trick users. According to Google research, more than 15% accounts hijacked by using these social engineering methods. Crooks ran a Netflix phishing campaign to hijack user accounts.

Phishing campaigns run by crooks hijacking top brands and almost it is impossible to stop, With Recent Google research, they found 12.4 million potential victims of phishing kits; and 1.9 billion usernames and passwords exposed via data breaches and traded on black market forums.

Netflix Phishing Campaign

Netflix phishing campaign made a big news last week, it tricks the user to hand over login credentials, Credit card information and Photo ID.

Sophos team detailed on how this Phishing works, it starts with the Email coming from the reputed Netflix Email address with the warning that your account is “On hold”.

In the subject, attackers wrote Greek Letter Chi instead of “x”, the NETFLIX, word in the subject spelled with wired character.

The Email consist of “update now” button, on clicking it takes to a malicious site that posses like a legitimate site and asks victims to update their billing address, payment card details, Identity Info in successive steps.

Also Read Real-Time Intelligence Feed to Catch Malicious Phishing Domains SSL Certificate

To note the crooks made a convincing start that the Phishing website is HTTPS enabled with a green padlock, we should not trust HTTPS blindly and the TLS certificate is only to encrypt the connection between the browser and server.

Crooks tricked the victims with the faked Verified by VISA page to steal the payment card details, then attacks to upload your selfie to confirm your identity.

Once the crooks had all the details they redirect victims to the real Netflix login page. You can Copy the URL to analyzers that available over the Internet and ensure it’s Integrity. If it is a shortened URL you can unshorten it with the site and then analyze the actual URL.

To protect users IBM introduced a DNS security solution Quad9 that uses to protect users against most common cyber threats and their privacy.It keeps blocking you against known malicious domains and prevents your computer and IoT devices from connecting to malware or phishing sites.

Phishing and Keylogging are one of the most common problems for Internet Users, hackers keep on finding a new innovative method to create believable URL’s to trick users.

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

10 Best Penetration Testing Companies in 2025

Penetration testing companies play a vital role in strengthening the cybersecurity defenses of organizations by…

16 hours ago

Lumma Stealer Using Fake Google Meet & Windows Update Sites to Launch “Click Fix” Style Attack

Cybersecurity researchers continue to track sophisticated "Click Fix" style distribution campaigns that deliver the notorious…

20 hours ago

Fake BianLian Ransom Demands Sent via Physical Letters to U.S. Firms

In a novel and concerning development, multiple U.S. organizations have reported receiving suspicious physical letters…

1 day ago

Strela Stealer Malware Attack Microsoft Outlook Users for Credential Theft

The cybersecurity landscape has recently been impacted by the emergence of the Strela Stealer malware,…

1 day ago

New PyPI Malware Targets Developers to Steal Ethereum Wallets

A recent discovery by the Socket Research Team has unveiled a malicious PyPI package named…

1 day ago

Threat Actors Exploit PHP-CGI RCE Vulnerability to Attack Windows Machines

A recent cybersecurity threat has emerged where unknown attackers are exploiting a critical remote code…

1 day ago