QuickBooks clients have been warned by Intuit regarding ongoing phishing attacks using phony account suspension warnings as lures, according to BleepingComputer.
Attackers have been distributing phishing emails notifying users that their account has been temporarily put on hold after some account information was not verified. Included in the email is a "Complete Verification" button that has been suspected to redirect to a personal data-harvesting site. The email sender is not in any way affiliated with Intuit, stressed the company, which urged recipients of the phishing email to avoid clicking and opening included links and attachments. Intuit also called on clients to immediately delete the emails.
Meanwhile, those who had opened the links and attachments have been advised to promptly delete downloaded files, conduct anti-malware scanning of their systems, and replace their passwords. The advisory comes months after Intuit warned customers regarding a phishing campaign spoofing the firm in emails that threaten account deletion.
Sixty thousand emails from U.S. State Department accounts were noted by a staffer working for Sen. Eric Schmitt, R-Mo., to have been exfiltrated by Chinese threat actors during the widespread compromise of Microsoft email accounts that commenced in May, according to Reuters.
Threat actors have leveraged the ZeroFont phishing attack technique, which initially involved the insertion of hidden characters or words in emails to evade security detection systems, to modify message previews as shown on Microsoft Outlook and other email clients, BleepingComputer reports.
BleepingComputer reports that individuals who have filed claims against bankrupt cryptocurrency lender Celsius have been subjected to phishing attacks involving the impersonation of the lender's claims agent, Stretto.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news