Netflix bills itself as the “world’s leading Internet television network.”
The video subscription service boasts more than 44 million members in more than 40 countries —
and, together, those members stream (and presumably watch) more than 1 billion hours of TV shows
and movies each month.
Such statistics have made Netflix an investor favorite. Although Netflix and other technology
stocks have struggled in the past few weeks, shares of the company are up nearly 90 percent since
April 2013 — and up a jaw-dropping
3,800 percent since the company’s initial public offering
12 years ago.
It was inevitable, perhaps, that the company’s rapid growth would catch the attention of
scammers, too.
The Better Business Bureau warns of a new scheme that seeks to capitalize on Netflix’s
popularity. Like most “phishing” schemes, it’s designed to steal financial data and other
confidential information that can be used to make unrelated, but equally fraudulent,
transactions.
“Netflix has a good reputation, and scammers are taking full advantage of that,” said BBB
spokeswoman Paula Fleming. “Anyone using their video-streaming service could fall for this
scam.”
Armed with a computer stripped of all personal information, Jerome Segura, senior security
researcher for Malwarebytes, a California-based maker of anti-virus software, demonstrated how the
scam works.
A Netflix member — in this case, Segura — gets an official-looking email or a pop-up notice
indicating that the company has detected “unusual activity” on his or her account.
“To protect your account from unauthorized use, we have temporarily suspended this username,”
the notice says.
The Netflix user is encouraged to contact “Member Services” to regain access to streaming
content. A toll-free number is provided.
The person who answers the phone identifies himself as a “Netflix support staffer.” He explains
that the account in question has been compromised by a hacker.
The supposed support staffer then connects the would-be victim to a “Microsoft-certified
technician” — ostensibly to fix the security breach.
That person says he can resolve the problem in short order. He just needs remote access to the “
infected” computer.
As part of the demonstration, chronicled in its entirety on video, Segura gave the con artist
the requested access. Within seconds, files were being downloaded from the computer.
“I had set up fake banking sheets on the desktop, and they were taken as we were speaking,” he
said.
Netflix said it was aware of the scam, which the BBB first flagged last month, and had taken
steps to stop it. The company didn’t say how many people might have been affected.
Even if the Netflix scam outlined above is rendered harmless, similar phishing schemes
undoubtedly will continue to plague unwitting computer users, Segura said.
Unfortunately, there’s little to prevent crooks, especially those who operate offshore, from
hijacking — or at least attempting to hijack — trusted, high-profile brands.
The best deterrents: up-to-date anti-malware software and, perhaps more important, consumer
vigilance.
To that end, the BBB offers these tips:
• Never let someone log into your computer remotely. A user with remote access can peruse — and
copy — anything on your computer, including the most-sensitive personal information.
• Don’t click on links in emails. Instead, if you want to visit a site, type the address
manually in the search bar.
• If a URL doesn’t look right, don’t continue to the site. Scammers often employ URLs that
mirror those of respected entities, except for a few jumbled letters or numbers.
• Always verify an organization’s phone number on its official website. That way, you can be
sure you’re calling a legitimate number.
kurt.ludlow@10tv.com
