Information theft through email

✨ READ THIS ARTICLE NOW IF YOU DON’T WANT YOUR INFORMATION HACKED THROUGH EMAIL ✨

Phishing attacks using spoofed email are a well-known form of information theft, but many people still fall for them, causing serious harm, and the risk of stolen information is high if you interact with these scam emails.

❗ HOW HACKERS RUN EMAIL SCAMS ❗

– First, you receive an email saying you need to verify your email account because it is about to be locked, deleted or is out of storage.
– You click the link in the email and are taken to a fake login page that looks very much like the email login page you use.
– Your email username is pre-filled to build trust; you’re only asked to enter your password.
– When you enter your password and log in, the site redirects you straight to your real home page.

👉 Once a hacker has your email password, they have many ways to exploit the compromised account. Here are some common cases:

Spoofing email as a reply, with a data-encryption virus attached:
– This spoofing attack is the most common one customers face. After taking over your account, the hacker signs in and copies all your personal email data.
– The hacker then replies to emails with content you have received or sent, and the display name is a 100% match for the people you have corresponded with.
– They attach .doc files containing dangerous macros; when opened on the user’s computer, these automatically download malware. The aim is to encrypt the data on the personal computer or take it over.
– Viruses commonly embedded in Word or Excel files with macros:
+ Ransom:MSIL/Swappa
+ Ransom:Win32/Teerac
+ TrojanDownloader:Win32/Chanitor
+ TrojanSpy:Win32/Ursnif
+ Win32/Fynloski
+ Worm:Win32/Gamarue

Email accounts not involved in money transactions:
– The hacker uses these accounts to send email in bulk. These emails are spam, bulk mail or even spread viruses.
– Successfully sent, these emails get the customer’s domain blacklisted by international anti-spam organisations. They also directly affect the IP and IP range of the service provider.

Email accounts that regularly handle money transactions:
– The hacker doesn’t use this account to spam, but adds an auto-forward configuration to Gmail, Yahoo, Hotmail, etc. to monitor transactions.
– Once they have information on a money transaction by email, the hacker spoofs the transaction email between the two parties and requests a transfer.
– The hacker may use a look-alike domain, wrong by just one character, to send a transfer request, or use email with a display name that is a 100% match for the regular correspondent.
– The hacker also creates email rules to delete emails from partners, so no confirmation email is sent, and the hacker sends their own confirmation to the partner instead.

🔥 RECOMMENDATIONS 🔥

To avoid unnecessary risk and improve your personal information security, GPIT would like to share some measures:
– Do not click unfamiliar links attached in email.
– Carefully check whether the website URL is trustworthy when signing in to your email account.
– You only need to sign in to your admin email account or user email account for the purpose of using email. You do not need to sign in anywhere else to verify, increase storage, avoid being locked, and so on.

Contact Me on Zalo
0945886818