A new Zoom-themed phishing attack is circulating through email, text and social media messages, aiming to steal credentials for the
The Better Business Bureau (BBB) warned last week that the attack uses Zoom’s logo, and in a message tells recipients that their Zoom accounts were suspended and to click a link to reactivate; or that they missed a Zoom meeting, and to click a link to see the details
Another recent variant of the attack has been a message welcoming some recipients to the platform and requesting they click on a link to activate the account, said
In all cases, victims are taken to a phishing landing page, where they are asked to input their
“This phishing scam isn’t surprising, since attackers always update their phishing lures to take advantage of ongoing trends and events,” said
According to the BBB, scammers registered more than 2,449
“No matter what kind of phishing message you receive, scammers hope you will click on the link they’ve included in their email,” according to the BBB. “These links can download malware onto your computer or lead you to a page where you are prompted to enter your login information. Entering your username and password gives scammers access to your account and any other account that uses a similar login and
The phishing scam comes amidst the wave of remote workers driven home by the coronavirus pandemic, who have come to rely on online collaboration tools like Zoom and other platforms. BBB said, with Zoom’s usage exponentially growing in 2020, these credentials are invaluable for attackers. For instance, a database shared on an underground forum in April contained more than 2,300 compromised
“Naturally, this has attracted the attention of hackers and scammers,” said the BBB. “With a huge user base to target, con artists are using old tricks in new scams to try to steal
Compromised Zoom credentials could give cybercriminals access to web conference calls, where sensitive files, intellectual property data and financial information are shared. Cybercriminals can also use these credentials for
Attackers can also use these types of compromised credentials to launch
Potential victims can protect themselves from these types of scams by
“Phishing scams always involve getting an unsuspecting individual to click on a link or file sent in an email that will download dangerous malware onto their computer,” they said. “If you get an unsolicited email and you aren’t sure who it really came from, never click on any links, files, or images it