Phishing warning: criminals abuse Black Friday hype
Phishers are jumping on the Black Friday bandwagon and luring victims with warnings about unauthorized Amazon access.
(Image: Bild erstellt mit KI in Bing Designer durch heise online / dmk)
The weeks of offers around "Black Friday" have begun. Online scammers use the opportunity to lure victims with fake warnings about unauthorized access, for example from the Netherlands.
(Image:Â Phishingradar / Verbraucherzentrale.de)
In the phishing radar, the consumer advice centers warn that fraudulent emails have been circulating since Friday stating that unknown access to the account would lead to the account being temporarily blocked. The subject line reads something like "Important warning: Unusual activity detected". The Amazon logo, which is probably the largest online retailer where a particularly large number of people order, is misused as a hook.
Download of alleged security software
The email is addressed personally with a real name. The reason also sounds plausible, explains the consumer advice center: "We have detected unusual activity in your account. On 21/11/2024, an attempt was made to access your account from an unknown IP address in the Netherlands," reads the text in the email. Access to the account has therefore been temporarily restricted. The victim should confirm the activity or take immediate action to protect the account.
Videos by heise
If the victim has carried out the access themselves, no further action is necessary. "If you do not recognize this activity, please change your password and check your account with our recommended security software," the fake email continues. The action button in the email is labeled "Download security software". The consumer advice center has not downloaded and checked the software, but it is almost certainly malware.
Further indications of phishing are the unprofessional presentation of the email with a simple logo and the sender's name "AMAZON", the sender's address is also dubious and the link within the email is incorrect. Phishingradar recommends that recipients should put such emails in the spam folder immediately. If necessary, you should check the official app or the website itself to see if a similar request can be found there.
(dmk)