Quantcast

Phishing Scam Takes Aim at MySpace.com

Social networking site is increasingly a target for identity thieves.

Jeremy Kirk, IDG News Service

  • 0 Yes
  • 0 No

A phishing site that harvested the login and credentials of MySpace.com users was removed as of Friday from a California server, a security vendor reported.

A phishing attack involves tricking users into visiting a look-a-like Web page that asks for personal information, which is then sent to a hacker.

The rich trove of personal information stored on MySpace user pages is making the social networking site an increasing attractive target for identity theft, said Ross Paul, a senior product manager at Websense, which makes security software.

Spreading Via IM

The attack would not have been noticed by most users, Paul said. The attack starts when a user is sent a link through an instant messaging program.

The link is from someone in their contact lists, asking them to click the link to MySpace to view photos, Paul said. The link leads to a fraudulent MySpace login page. Once the victim enters their information, they are then transparently logged into the real MySpace pages, Paul said.

But a hacker then has access to personal information stored by MySpace, such as someone's address and birthday, which could be used to open a bank account, Paul said.

A hacker can also tap other instant messaging contacts or e-mail addresses to send out the link to the phishing site, which often is done using automated programs.

"The rising popularity of this kind of meeting place is obviously increasing the potential for financial gain," Paul said. "The more information you give MySpace, the more at risk you would be if someone managed to get a hold of your login information."

MySpace, started in 2004 and bought by News Corp. last year, counts at least 73 million users and is growing. MySpace's "viral" networking model allows friends of friend to easily connect, but sexual predators have also used its features to meet underage victims.

As a result, MySpace appointed a chief security officer in April and implemented careful page monitoring.

  • Recommend this story?
  • 0 Yes
    0 No

"Phishing Scam Takes Aim at MySpace.com" Comments

With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.

Related Consumer Advice Articles

  • How to Stream Media around Your Home Here's the play-by-play on setting up a free media-streaming network with either Windows Media Player or Apple iTunes.
  • Use Gmail to Fight Spam Gmail already offers champion spam-filtering for Gmail accounts. Here's how to leverage it with non-Gmail accounts.
  • Overclock Your Body With Geek Cuisine Can caffeinated chips and drinks stuffed with more herbs than you'd find in an Asian pharmacy really make you more productive? We slurped and chewed our way through lots of so-called energy food to find out.
  • Give Web Users What They Really Want Most people go online with a goal in mind. Learn to capitalize on their habits.
  • LinkedIn: The Network Effect Revisited You've signed up for LinkedIn, because everyone says it's the primary business social network. But to whom should you connect? According to a few power users, there are a few common approaches, most of which are different than what you'd do on Facebook.
  • CDW Security Center Is your data protected? Visit the CDW Security Center Learn where you may be vulnerable and how to address those risks.
  • Asus Laptop Showcase Ultra-fashionable thin and light notebooks with SmartLogon Face Recognition. Find out more...
  • HP Ink Center Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)