Kaspersky Lab recently published a report that analysed increase in cyber criminal campaigns to steal users’ Apple IDs and account information by creating fraudulent phishing sites that imitate the official Apple site (www.apple.com).
Cyber criminals are using fake Apple sites to trick users into submitting their Apple ID credentials, which would enable them to access the user’s personal data and credit card numbers stored on their iCloud and iTunes accounts.
From January 2012 to May 2013, Kaspersky Lab’s cloud-based Kaspersky Security Network (KSN) detected an average of 200,000 attempts per day by users trying to access phishing sites. This showed a marked increase from the figure for 2011, which was an average of 1,000 detections per day.
Kaspersky Lab’s web antivirus module detected and prevented its users from accessing the sites; however, the increase in detections shows that such scams are becoming more common.
An official from Kaspersky Lab told Muscat Daily, “According to our research, there is an average of approximately 100-500 attempts targeting Apple IDs in Oman. While this is not an alarming figure, the number of attacks has increased in comparison from years prior.”
Kaspersky experts analysed cyber criminal behaviour on a daily and monthly basis and noticed that fluctuations and increases in phishing attempts often coincided with large events from Apple. For example, on December 6, 2012, following the opening of iTunes stores in India, Turkey, Russia, South Africa and other countries, Kaspersky Lab detected an all-time record of more than 900,000 phishing attempts directing to fake Apple sites in a single day.
“The main distribution method used to direct users to fraudulent Apple sites are predominantly phishing e-mails posing as Apple Support with fake alias names in the ‘sender’ field, such as services@apple.com,” he said, adding the messages would typically request users to verify their account by clicking on a link and entering their Apple ID information. The e-mails are designed to make them appear authentic, including the use of Apple’s logo and presenting the message with similar formatting, colouring and style that Apple uses.
He also said that another variation of these phishing e-mails are designed to steal Apple customers’ credit card information. This is done by sending users an e-mail requesting that they verify or update the credit card credentials attached to their Apple IDs, which can be done by clicking on a link in the message.
