Posts

Showing posts from December, 2022

Facebook Phishing Warning: Coke FANS

Image
  Let this serve as a warning. There is a Facebook post that claims that they will be "donating" refrigerators if users comment their preferred colors on the said post.  Once users comment on it, the page will reply encouraging users to "validate" their "registration" by visiting a website.   This is where things gets interesting.  If the users follow the page's instructions, the registration page will redirect users to a website that gathers user credentials which will later on can be used to steal the identity of those who commented.  A quick check on the site where users are redirected will yield this result:   Moral of the story: If it's too good to be true. It most probably is (scam).

Analyzing Another Banking Fiasco

The news about the "mysterious" loss of 1 million pesos from someone's bank account is making the rounds of social media right now (see video below).   https://fb.watch/hmCZUoZpiQ/?mibextid=v7YzmG Here are my thoughts on the incident: The victim should have been suspicious when a barrage of OTP notifications are received on her phone. She should have gone to her bank to check on her account Although not the culprit, the person who attended the call of the customer should have done a better job checking the system when the customer called. What probably happened: Based on what I saw in the video, this is probably a complex case of phishing and SIM Swapping.  According to the victim, she has not enrolled her account to the online facility meaning that the perpetrator/s was able to use the victim's cellphone number to enroll the account.  To enroll an account to such a facility, the perpetrator must know the victim's information as stored in the bank. The only way to

Sad Story of a Stolen iPhone (A Mastodon Epic)

Image
 While scrolling through my Mastodon timeline, I saw this rather interesting series of posts that could serve as both a cautionary tale and as a nudge to enable tracking on your cellphone.  The story was from user @em0@hachyderm.io  TL;DR: The author's iPhone was snatched at London.  The thieves attempted to phish his Apple ID credentials to unlock the stolen device.  Failing to get the owner's Apple ID, the phone ended up in Shenzen, China(!) Here is the series of Mastodon Toots in case you want to see the entire story .