Another round of phishing hits Twitter

Share this article:

After last week's phishing attacks on social networking sites, yet another round has struck Twitter.

The latest scam involved messages coming from a site called “TwitterCut,” which were posted to users' Twitter streams and purported to guarantee an increase in the number of their followers. But once the link was clicked, the victims were directed to a site that requested them to login with their Twitter credentials. If they did, the site siphoned their list of existing followers and sent similar messages to all of them, along with links to a paid dating service.

Twitter, in acknowledging the problem, posted a note on its status page Tuesday night that said: “We are currently pushing a password reset on accounts we believe may have been caught in a phishing scam.”

On the TwitterCut website, the site operators denied that they had engaged in any phishing, and announced that they were shutting the site down.

“According to several social network blog sites, TwitterCut has been the bud of several rumors,” a message on the site said. “Our website and its programmers can assure you that these rumors are not true and that TwitterCut is simply a Twitter train that was a work in progress!”

The meta content of the site, however, still contains a claim that says: "Need more followers on Twitter? We can promise you thousands or more followers. Come visit us now!"

US-CERT lists a number of ways to avoid being trapped in phishing scams, including not sending information over the internet before checking a website's security and paying attention to the URL of a website (malicious websites may look identical to legitimate sites, but with a variant URL). Another tip is to install and maintain anti-virus software, firewalls and email filters to reduce phishing traffic.

Last week's round of social networking scams involved FackBook messages to users that appeared to come from their friends, but linked to bogus websites, and scammers who created a fake Twitter login page to harvest user credentials.

Share this article:

Next Article in News

Sign up to our newsletters

More in News

Five schools earn NSA's excellence in cyber ops distinction

The schools earned NSA's Centers for Academic Excellence designation for their cyber offerings.

With RATs at their disposal, 419 scammers target businesses

With RATs at their disposal, 419 scammers target ...

A new report reveals how Nigeria's 419 scammers are spreading malware to pocket business funds.

InfoSec pros worried BYOD ushers in security exploits, survey says

InfoSec pros worried BYOD ushers in security exploits, ...

A study by the Information Security Community on LinkedIn found most organizations don't have proper polices and support for BYOD.