Application security, Threat Management, Malware, Phishing, Vulnerability Management

Award for Best Phish goes to: iTunes movie scammers

Think naming the wrong movie as Best Picture at the Oscars is embarrassing? What about giving away your personally identifiable information (PII) in order to get a refund on movies you never actually paid for?

That's the basic plotline behind a phishing scam that impersonates iTunes and targets Canadian Apple users, according to Fortinet a blog post published late last week.

The Fortinet report cites a user who was sent a phishing email containing a fake receipt claiming the recipient spent nearly $100 on five movies. The spam email offered a link that users could click to request a full refund if the transaction was not authorized – implying possible fraudulent activity on the target's iTunes account. The link led to a phishing page asking for such PII as the user's name, address, birth date, phone number, payment card information, social insurance number, and mother's maiden name.

Clicking the cancel transaction button transmits the data to the scammers in plain text, at which point the user is redirected to the legitimate Apple website. According to Fortinet, the scam is reminiscent of 2015 iTunes phishing emails that targeted U.K. and Australian users with fake receipts for books and songs – except this iteration is even more convincing due to the scam's use of recent movie titles and its lack of overt mistakes.

Bradley Barth

As director of community content at CyberRisk Alliance, Bradley Barth develops content for SC Media online conferences and events, as well as video/multimedia projects. For nearly six years, he wrote and reported for SC Media as deputy editor and, before that, senior reporter. He was previously a program executive with the tech-focused PR firm Voxus. Past journalistic experience includes stints as business editor at Executive Technology, a staff writer at New York Sportscene and a freelance journalist covering travel and entertainment. In his spare time, Bradley also writes screenplays.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms and Conditions and Privacy Policy.