.Mac users phished in MobileMe transition scam

Thu, 08/14/2008 - 01:28 — Jonny Evans
1115

 Apple's Mobile Me fracas caused "hundreds" of Mac users to fall prey to a phishing scam, tricked into handing over valuable personal information by spoof mail and a well-crafted site.

Data obtained by CardCops, a credit card protection service owned by the Affinion Group, shows several hundred .Mac member's data being traded in underground markets frequented by identity thieves. Details on sale are alleged to have included social security numbers, birth dates, mothers' maiden names, credit card numbers and more.

The information was obtained through a phishing scam, using emails that circulated when Apple began its disastrous transition from Mac.com to Me.com. The scams bore subjects such as "Billing problem", The Register explains.

In a classic move, clicking the link contained within that email took .Mac members to a (fairly) authentic page which claimed to belong to Apple and requested a host of details of a site visitor. With more than customary confusion among Mac users as Apple migrated its services to Mobile Me, it appears many who would otherwise have detected the problem fell for the scam.


( Filed Under: )

Comments

Well actually... Apple's

84

Well actually... Apple's fracas wasn't the cause. User mistakes where the cause. Phishing is solely the responsibility of the user.

Don't click links in emails.

I agree with Joe R

108

It is the responsibility of the user to verify the authenticity of their actions.

Links in emails

135

Whenever I get a link in an email for "updating" purposes, my first thought is a phishing scam. In fact, I have caught a few and reported them to eBay and PayPal. If a company I'm familiar with requests updating of information, I access the website in the usual way, by entering the URL into my browser manually. We who post here understand these things, but my guess is that the general public is ignorant of the dangers. Somehow, they need to be made aware. Of course, the unscrupulous thieves will then devise other means...