kolektiva.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Kolektiva is an anti-colonial anarchist collective that offers federated social media to anarchist collectives and individuals in the fediverse. For the social movements and liberation!

Administered by:

Server stats:

3.6K
active users

#Phishing

87 posts58 participants0 posts today

Also jetzt hab ich doch echt kurz überlegt, ob das wirklich sein kann, dass ich 1,95 Euro zahlen soll, damit mir weiterhin E-Mails zugestellt werden... und wollte mich schon aufregen, dass man als zahlender Kunde nun auch noch extra zahlen muss und so. 🤡

Aber gut gemacht ist diese Spam-Mail ja...


#Telekom, #Spam, #Mail, #Phishing

Dzwoni do Ciebie numer zza granicy? ,,Dodaj mnie na WhatsApp’’ – nowa kampania phishingowa

W ostatnich dniach obserwujemy nową kampanię cyber zbójów. Schemat, który zaraz Wam opiszemy nie odbiega za bardzo od innych tego typu, ale tym razem skala działania jest naprawdę imponująca i pojawia się kilka ciekawych elementów. Dużo osób (w tym ekipa sekurak.pl) dostaje połączenia z zagranicznych numerów (kierunkowe, np. +44, +36),...

#WBiegu #Awareness #Phishing #Scam #Telegram #Whatsapp

sekurak.pl/dzwoni-do-ciebie-nu

Sekurak · Dzwoni do Ciebie numer zza granicy? ,,Dodaj mnie na WhatsApp’’ - nowa kampania phishingowaW ostatnich dniach obserwujemy nową kampanię cyber zbójów. Schemat, który zaraz Wam opiszemy nie odbiega za bardzo od innych tego typu, ale tym razem skala działania jest naprawdę imponująca i pojawia się kilka ciekawych elementów. Dużo osób (w tym ekipa sekurak.pl) dostaje połączenia z zagranicznych numerów (kierunkowe, np. +44, +36),...

Attention #Phishing sur #Bruxelles !

Un appel téléphonique de quelqu'un se prétendant du SPF Finances - Pension qui appelle suite à un courrier jamais reçu (perdu par la Poste à cause des grèves) et dont le but final est de soutirer des infos personnelles (ou peut-être pire).

Ne donnez jamais aucune info par téléphone sans être sûrs de qui vous avez en ligne. Au pire, dites-leur d'envoyer un mail ou un courrier.

Restez vigilant-es !

Smishing Triad: Chinese eCrime Group Targets 121+ Countries, Introduces New Banking Phishing Kit

The Chinese eCrime group Smishing Triad has launched a global SMS phishing campaign targeting over 121 countries across various industries. Their infrastructure generates over one million page visits in 20 days, averaging 50,000 daily. The group has introduced a new 'Lighthouse' phishing kit focusing on banking and financial organizations, particularly in Australia and the Asia-Pacific region. Smishing Triad claims to have '300+ front desk staff worldwide' supporting their operations. They frequently rotate domains, with approximately 25,000 active during any 8-day period. The majority of phishing sites are hosted by Chinese companies Tencent and Alibaba. The campaign primarily targets postal, logistics, telecommunications, transportation, finance, retail, and public sectors.

Pulse ID: 67f80a4937d04f9036252cf7
Pulse Link: otx.alienvault.com/pulse/67f80
Pulse Author: AlienVault
Created: 2025-04-10 18:13:29

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.
#Asia#Australia#Bank
Replied in thread

@ra6bit : When we visit a shop or bank in the center of town, chances are extremely small that it's a fake. Not so on the internet (and in North Korea).

There is a fix, in short:

1) If people visit a website for the first time, their browser should (before fetching content) show them all known relevant info about the website (and warn for typical phishing domain names, such as "example.com-whatever[.]tld"). And if known, *usable* identifying info of the entity who is responsible for the website. I'm not against anonymous websites, but too often their owners are criminals, so such sites are unsuitable for risky transactions.

2) We need more human readable info in certificates. The CA/B forum must be replaced by a consumer (plus governments) controlled organization.

3) User education.

More details below "WHAT IS A DECENT WEBPKI" in infosec.exchange/@ErikvanStrat.

@lukyan