Over at Netcraft – the Internet services company which provides data mining, defence against fraud and phishing, and security testing – an employee spotted an interesting phishing scam against iTunes users, which is hosted on Honda’s website.
The employee in question, Nicholas Hatter, contacted me about his findings.
Appearing to affect the Brazilian arm of the automotive giant; a page was hosted with a SSL certificate which redirects to a page that replicates iTunes Connect (see below.)
Unsuspecting users enter their details which are then stolen and can be used to make purchases; email addresses could then potentially be sold on to mailing lists.
At this point it should be made clear Honda likely had no prior knowledge to this page being hosted, and its probable the car manufacturer was just a “front” to which victims were sent. What isn’t clear however, is exactly how many had fallen for the scam.
Since the findings by Netcraft; the page has been removed.
It’s certainly not the first time phishing scams have affected iTunes users; in fact, it’s so proliferate Apple host two separate support pages on the matter. One entitled “Identifying fraudulent ‘phishing’ email” and the other “Identifying legitimate emails from the iTunes Store”.
So many articles I’ve read essentially pitch these attacks as the customers own fault for falling victim, but the fact is, some are so simple anyone could be vulnerable.
One email scam sends the user an iTunes payment for a ridiculous amount of money – say, $692.99 for an album. The “customer” – now in a state of panic – opens a link to check their order which installs malware and/or Trojan horses that steal the user’s details.
Luis Corrons, Technical Director of PandaLabs, comments: “It never ceases to surprise us that the techniques used to trick victims continue to be so simple.”
Over at Mercury News, Valerie Gould tells her tale of being charged more than $650 in PayPal iTunes payments, and her warning for everyone to keep an eye on their statements.
Are Apple doing all they can against fraudulent transactions? Is it down to educating the consumer?
