Join our iPhone, iPod touch, iPad and Apple TV community today! Register Here | Login

MobileMe Phishing Attack Nets Hundreds Of Victims

By , Friday, Aug 15, 2008 at 4:35 pm
0

Remember that warning we posted on Tuesday about a MobileMe phishing attack in the wild? Turns out it's been terrifyingly effective so far. Ars Technica quotes CardCops president Dan Celements:

"We found 20 different files parked on the server, each file with two or three or four, up to 20, profiles. Cumulatively, there were about 300 profiles collected in that one day. And 100 to 200 were mac.com addresses."

NOT GOOD. Ars goes on to rightly point out that Apple customers are typically higher-income, and thus more desirable targets. We'd also add that Apple users are not as accustomed to malware and phishing as our Windows-using friends, but as email and web browsing doesn't care about platform, we REALLY need to be. Just like you wouldn't open a package left at your door that smelled like gasoline and was ticking, even if it came in a Tiffany's box, don't open links or give out credit card information just because it fakes coming from Apple.

REMEMBER: Don’t EVER believe email requests for secure data. Go to the site yourself (not through their link — type it in) and log in and see if there really is a problem. Check domain names carefully. App1e.com isn’t the same as Apple.com, they’re just hoping you don’t notice. Worried about the recent DNS poisoning attacks? Use HTTPS/SSL or use a direct IP address. If in any doubt, pick up a phone and call Apple (or your credit card company) directly.

Rene Ritchie

Editor-in-Chief of iMore, Executive Producer at Mobile Nations, co-host of Iterate and ZEN and TECH, cook, grappler, photon wrangler.

More Posts - Website

 TwitterFacebookGoogle Plus

← Previously

Shiny Apple Logo Mod + Is the iPhone a Blade Runner Replicant?!

Next up →

Colbert Threatdown: iPhone Kills! + Zune... Does Nothing

Leave a Reply

Note: Comments must be civil, respectful, and on-topic. If a comment does not add to the conversation, if it contains spam advertising, or inappropriate language or content, it will be removed. Insulting the topic, author, staff, site, network, or other commenters will result in the comment being marked as spam and potential prevent future comments from appearing on the site. Do not post as a business or your comment will likely be confused with spam. Comments containing links may be held for moderation. Relax, enjoy, and share in the discussion.