PayChoice security breach leads to email scam
Friday, October 2, 2009
When users of payroll processor PayChoice received emails last week asking them to download a browser plug-in in order to continue accessing the site, many were lured into downloading malware that exploited security flaws in Internet Explorer and some Adobe software.
The attacks specifically targeted users that accessed PayChoice via the onlineemployer.com portal, and provided their username, log-on information and partial passwords to further the impression that the malicious email was legitimate. Security experts like Steve Friedl, writing at Unixwiz, speculate that the detailed information contained in the emails suggests some source of inside information.
PayChoice, which serves 125,000 clients from its New Jersey headquarters, released a statement saying that "[w]ithin hours of the attack, the company notified its clients, shut down the site www.onlineemployer.com and deployed further security measures to protect client information before restoring access to the system."
The attack's malware payload was a variant of the Bredolab Trojan, and experts say that the objective of the attack was to steal online banking information from employees with access to company funds.
Related News:
FBI: Law firms and PR agencies high on hacker target lists - 11.18.2009 Using complex email scams, cyber criminals are increasingly targeting sensitive information held by law firms and public relations companies, according to an FBI advisory released earlier this month.
Phishing email takes numerous forms - 11.17.2009 The practice of impersonating authoritative websites and sources in order to convince victims to divulge personal information - known as phishing - has come a long way from the Nigerian "419" scams that popularized the technique in the public mind. Modern phishing is becoming increasingly dangerous in part because attacks can come from a variety of sources.
Email filtering technology working overtime, but spam won't go quietly - 11.16.2009 While modern email filtering systems can block 95 to 99 percent of spam messages, according to Tech Target, mountains of unsolicited email are still delivered every day, accounting for the vast majority of all emails sent.
Phishing scam targets investors, spoofs finance agency - 10.9.2009 The Financial Industry Regulatory Agency (FINRA), an independent regulator of brokerages, is warning investors that they may be targeted by a phishing scam through emails claiming to come from the agency.
Phishing scammers leak Windows Live Hotmail passwords to web - 10.6.2009 Hackers posted thousands of passwords from Windows Live Hotmail email accounts to a website over the weekend, in what Microsoft said was the result of a phishing campaign targeting the free webmail service.
|