Posts

Showing posts with the label phishing

Wow! I Got Mail!

Image
  It looks like a not-so-anonymous donor is willing to donate money for use in my non-existent "charity work in my area". 🤣 BUT SERIOUSLY... this is yet another example of threat actors that simply want to (a) verify my email address so they can continue sending me scam messages. (b) lure me in and scam me if I am greedy enough to "bite" into their lure.  Should anyone else receive a similar message, the best way to handle it is to simply ignore it and tag it as "junk email".  Oh, and if similar messages from unknown sources come your way... well you know what to do.

Oh no! My TikTok is Being Hacked!

Image
  . ..and then I realized that I don't have a TikTok account. I’ve also received similar messages claiming that new log-ins have been detected on my non-existent X (aka Twitter) and my MFA-protected Facebook account. This is a relatively new tactic that will trick unsuspecting recipients into clicking on a fake log-in screen for TikTok, X, or Facebook, hoping to steal their login credentials. So, stay alert and don’t fall for it! Have you received messages similar to this?

I'm Rich! Rich I Tells Ya!

Image
  ...and all I need to do is send personal information to the International Monetary Fund Director of ATM Department, Mr. Arjun Rajesh (who inexplicably uses arjunrajesh@ gmail.com)  and I will have ₱1,634,980,891.97 in my bank account! But seriously , I can't believe how there are still people that gets scammed by emails like this. If you (and of my three blog readers) reads this, please do your share and inform everyone you know of this scam.

Beware of Fake Docusign Emails

Image
  Let this serve as a friendly reminder to refrain from digitally signing documents that you may unexpectedly receive. Such actions may inadvertently provide your digital signature to threat actors (hackers), which could subsequently be exploited for unauthorized financial transactions in your name. According to Bleeping Computer : Threat actors are abusing DocuSign's Envelopes API to create and mass-distribute fake invoices that appear genuine, impersonating well-known brands like Norton and PayPal.   Using a legitimate service, the attackers bypass email security protections as they come from an actual DocuSign domain, docusign.net. The goal is to have their targets e-sign the documents, which they can then use to authorize payments independently from the company's billing departments. The best way to avoid this is to double-check that the digital documents you received in your inbox are real and you expect it. If the message simply appears on your inbox unexpectedly, do not...

WARNING: GCash Phishing Leveraging the SIM Registration Act

Image
A lot has happened since the Philippine SIM Registration Act has been implemented.  There are people who are for and against its implementation.  That is an issue that can only be resolved in time.  However there is a bigger issue has stemmed from it.  The law is now being leveraged by threat actors that seeks to gather personal information from their potential victims. While reviewing my SPAM folder for legitimate messages that have slipped into the cracks, I noticed this interesting sender. A casual look makes it appear as if it came from GCash, a service I use for my digital wallet needs.  Although the display name says "admin@gcashmobile.com", it was sent "via sendgrid".  Just to let you know, legitimate emails from GCash comes from the "@gcash.com" email domain so this is already a big red flag.   Here is the body of the message: Looks convincing, right?  However, one thing that everyone should be aware of is this: Companies will always refer...