‘This campaign works because it feels ordinary’: Experts reveal how hackers use fake DHL messages to lure in victims



  • A phishing campaign is spoofing DHL emails to steal login credentials
  • Victims are tricked with a fake waybill confirmation and staged validation steps
  • Captured data, including passwords and device details, is sent directly to attacker mailboxes

Forcepoint has published a report about an ongoing phishing campaign designed to steal people’s DHL login credentials.

It starts by sending an email to the victim, asking for confirmation of a waybill. While the email itself looks authentic, and is designed in the same fashion legitimate DHL emails are, this one is easy to spot as fake – the domain being used to send the message is cupelva[.]com – completely unrelated to DHL.

https://cdn.mos.cms.futurecdn.net/4HQfMQ7ScfTqv5RDukfnYA-2190-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img