LinkedIn is becoming a paradise for phishing attacks

 The so-called "Great Resignation" and LinkedIn’s frequent email notifications are creating the perfect environment for criminals looking to steal login information from unsuspecting victims, researchers have warned.  A report from cybersecurity experts Egress found cybercriminals have noticed the opportunity to steal identities with the help of Linkedin's email notifications, as the number of phishing emails impersonating the recruitment site has grown 232%In February 2022 alone.  The premise is simple: threat actors know that LinkedIn sends numerous email notifications almost every day: from “you’ve appeared in X searches this week,” to “your profile matches this job,” to anything else in between. 


Everyone's used to LinkedIn's emails:

They also know that with these emails being frequent, and with so many people in-between jobs (or searching for jobs), they might not be as careful with each and every message received.

To top it off, these phishing emails often mention high-profile companies, to further motivate (or distract) people into clicking the link in the message. 

http://www.cowboyfastdraw.com/telegraph/viewtopic.php?f=4&t=2784&p=14419#p14419
https://polymerfem.com/community/profile/erickwilson/
https://serviceprofessionalsnetwork.com/members/erickwilson/
https://stitchitintl.com/support-forum/profile/erickwilson37/
https://bradsprojects.com/toaster-the-dual-rail-step-up-breadboard-power-supply/#comments
https://nap-sack.com/events/topic/view/event_id/96/topic_id/398/post_id/5040
https://www.discuto.io/en/blog-entry/lessons-learnt-2013s-web-summit-dublin?page=1#comment-38207
https://forums.garmin.com/sports-fitness/cycling/f/varia-series/241840/rtl515-vs-rtl510/1379617#1379617
https://obsproject.com/forum/threads/settings-greyed-out.151406/
http://mcspartners.ning.com/forum/topics/loan-estimate
https://neuroptresidency.kaiserpermanente.org/congratulations-graduates-2019/#comment-20681
https://food52.com/blog/24633-how-to-make-mashed-potatoes
https://forum.justgetflux.com/topic/7816/possibiltiy-to-adjust-2-montors-seperately?loggedin=true
https://1source.basspro.com/news-tips/ice-fishing/11842/3-pros-pick-best-ice-fishing-line-you#comment-2893
https://redmine.thqnordic.com/issues/112962
https://support.google.com/googleplay/thread/151118574?hl=en&dark=1

 

The link, as you might imagine, will lead the victim to a website that looks identical to LinkedIn, but submitting the credentials there only means the details of their identities end up in the hands of the crooks.

"The attacks we have seen are bypassing traditional email security defenses to be delivered into people's inboxes. We advise organizations to examine their current anti-phishing securing stack to ensure they have intelligent controls deployed directly into people's mailboxes," Egress said.

"Individuals should take extreme caution when reading notification emails that request them to click on a hyperlink, particularly on mobile devices. We recommend hovering over links before clicking on them and going directly to LinkedIn to check for messages and updates."

LinkedIn, we would add, is not the only company being impersonated by cybercrooks in search of gullible users. Other major brands are being used for phishing as well, such as Amazon, DHL, Microsoft, and many, many others. Users should always pay attention to emails that carry links, or attachments, regardless of who the sender is.

 

Comments

Popular posts from this blog

The next iPad Pro needs to borrow this one iPad Air feature

Dying Light 2 devs launch update, backtrack three hours later

The iPhone 14 launch is likely to mean the end for the iPhone 11