<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>iMore &#187; phishing</title>
	<atom:link href="http://www.imore.com/tag/phishing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.imore.com</link>
	<description>More of everything iPhone and iPad</description>
	<lastBuildDate>Sun, 27 May 2012 07:29:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>New phishing email scam asks you to update Apple ID billing information</title>
		<link>http://www.imore.com/2011/12/28/beware-phishing-email-scam-asks-update-apple-id-billing-information/</link>
		<comments>http://www.imore.com/2011/12/28/beware-phishing-email-scam-asks-update-apple-id-billing-information/#comments</comments>
		<pubDate>Wed, 28 Dec 2011 23:29:51 +0000</pubDate>
		<dc:creator>Andrew Wray</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[app store]]></category>
		<category><![CDATA[apple id]]></category>
		<category><![CDATA[christmas]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[ipad]]></category>
		<category><![CDATA[ipad 2]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[iphone 4]]></category>
		<category><![CDATA[iphone 4s]]></category>
		<category><![CDATA[iTunes]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[phishing attack]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://www.tipb.com/?p=88759</guid>
		<description><![CDATA[<em>The Mac Security Blog</em> points to a phishing email scam in circulation that asks for users to update their Apple ID billing information.]]></description>
			<content:encoded><![CDATA[<p><img src="http://cdn.imore.com/images/stories//2011/12/New-phishing-email-asks-you-to-update-your-Apple-ID-billing-information.jpg" alt="Beware: New phishing email asks you to update your Apple ID billing information" title="Beware: New phishing email asks you to update your Apple ID billing information" width="560" height="433" class="aligncenter size-full wp-image-88767" /></p>

<p><em>The Mac Security Blog</em> warns of a new phishing scam in circulation that tries to trick users into updating their Apple ID billing information, in hopes of stealing it for nefarious purposes.</p>

<blockquote>
  <p>A vast phishing attack has broken out, beginning on or around Christmas day, with e-mails being sent with the subject “Apple update your Billing Information.” These well-crafted e-mails could fool many new Apple users, especially those who may have found an iPhone, iPod or iMac under their Christmas tree, and set up accounts with the iTunes Store or the Mac App Store for the first time. The messages claim to come from “appleid@id.apple.com.” </p>
</blockquote>

<p>The email looks pretty legitimate, but upon hovering over the link you'll notice it points to an obviously fake Apple website asking you to enter your Apple ID credentials, and it's all downhill from there.</p>

<p>As always, never click on links in an email -- type them in yourself in a browser. When you get phishing emails, mark as spam and wash your hands of the worry.  Done and done.</p>

<p>Source: <a href="http://blog.intego.com/beware-of-apple-billing-information-phishing-e-mails/">The Mac Security Blog</a> via <a href="http://reviews.cnet.com/8301-13727_7-57348467-263/apple-billing-e-mail-scam-making-the-rounds/">CNET</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2011/12/28/beware-phishing-email-scam-asks-update-apple-id-billing-information/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>MobileMe to iCloud phishing scam hitting inboxes</title>
		<link>http://www.imore.com/2011/08/27/icloud-mobileme-email-phishing-scam-hitting-inboxes/</link>
		<comments>http://www.imore.com/2011/08/27/icloud-mobileme-email-phishing-scam-hitting-inboxes/#comments</comments>
		<pubDate>Sat, 27 Aug 2011 08:06:41 +0000</pubDate>
		<dc:creator>Chris Oldroyd</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[icloud]]></category>
		<category><![CDATA[ipad]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[ipod touch]]></category>
		<category><![CDATA[iTunes]]></category>
		<category><![CDATA[mobileme]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://www.tipb.com/?p=73467</guid>
		<description><![CDATA[<a href="http://cdn.imore.com/images/stories//2011/06/hero_mobileme_icloud.png"></a><a href="http://cdn.imore.com/images/stories//2011/08/iCloud-Thumb.png">
</a>

A new phishing email scam is arriving in email inboxes targeted at Apple MobileMe users. The email is supposed to be from Apple and is asking users to upgrade their]]></description>
			<content:encoded><![CDATA[<p><a href="http://cdn.imore.com/images/stories//2011/06/hero_mobileme_icloud.png"></a><a href="http://cdn.imore.com/images/stories//2011/08/iCloud-Thumb.png">
</a><img class="aligncenter size-full wp-image-67310" title="Apple posts MobileMe to iCloud transition guide" src="http://cdn.imore.com/images/stories//2011/06/hero_mobileme_icloud.png" alt="Apple posts MobileMe to iCloud transition guide" width="528" height="116" /></p>

<p>A new phishing email scam is arriving in email inboxes targeted at Apple MobileMe users. The email is supposed to be from Apple and is asking users to upgrade their MobileMe accounts to iCloud. The email has been based on an earlier email that Apple sent to MobileMe users after the WWDC iCloud introduction. <em>
</em>
<blockquote>Please sign up for iCloud and click the submit botton, you'll be able to keep your old
email address and move your mail, contacts, calendars, and bookmarks to the new service. Your subscription will be automatically extended through July 31, 2012, at no additional charge. After that date, MobileMe will no longer be available. Click here to update iCLOUD</blockquote>
When you click on the link, you are taken to a payment page which looks like an Apple update account billing information page. It then requests you to enter your credit card details and Apple Store account details. Obviously do not do this!</p>

<p>This phishing email is one of many currently doing the rounds, it is not that well done to be fair but it is worth mentioning as it appears to be a widespread problem. Stay well clear!</p>

<p>[<a href="http://www.macrumors.com/2011/08/26/new-phishing-email-targets-mobileme-icloud-transition/">MacRumors</a>]</p>

<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2011/08/27/icloud-mobileme-email-phishing-scam-hitting-inboxes/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>UPDATED: Apple comments on iTunes fraud - dev banned, change your password</title>
		<link>http://www.imore.com/2010/07/06/apple-comments-itunes-fraud-dev-banned-changed-password/</link>
		<comments>http://www.imore.com/2010/07/06/apple-comments-itunes-fraud-dev-banned-changed-password/#comments</comments>
		<pubDate>Tue, 06 Jul 2010 18:16:47 +0000</pubDate>
		<dc:creator>Rene Ritchie</dc:creator>
				<category><![CDATA[App Store Apps]]></category>
		<category><![CDATA[Development]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Fraud]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[ipad]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[ipod touch]]></category>
		<category><![CDATA[iTunes]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scams]]></category>

		<guid isPermaLink="false">http://www.tipb.com/?p=33735</guid>
		<description><![CDATA[<a href="http://cdn.imore.com/images/stories/2010/07/itunes-books-something-rotten-rm-eng-1278266811.jpg"></a>

Apple has responded to that <a href="http://www.imore.com/2010/07/04/itunes-accounts-hacked-cheat-app-store/">bizarre incident over the weekend</a> involving a glut of Vietnamese, copyright-infringing book apps rocking to best-seller status on the backs of hacked iTunes accounts.

<blockquote>
  The </blockquote>]]></description>
			<content:encoded><![CDATA[<p><a href="http://cdn.imore.com/images/stories/2010/07/itunes-books-something-rotten-rm-eng-1278266811.jpg"><img src="http://cdn.imore.com/images/stories/2010/07/itunes-books-something-rotten-rm-eng-1278266811-400x232.jpg" alt="iTunes account hacks Vietnamese book apps" title="iTunes account hacks Vietnamese book apps" width="400" height="232" class="aligncenter size-medium wp-image-33585" /></a></p>

<p>Apple has responded to that <a href="http://www.imore.com/2010/07/04/itunes-accounts-hacked-cheat-app-store/">bizarre incident over the weekend</a> involving a glut of Vietnamese, copyright-infringing book apps rocking to best-seller status on the backs of hacked iTunes accounts.</p>

<blockquote>
  <p>The developer Thuat Nguyen and his apps were removed from the App Store for violating the developer Program License Agreement, including fraudulent purchase patterns. </p>
  
  <p>Developers do not receive any iTunes confidential customer data when an app is downloaded. </p>
  
  <p>If your credit card or iTunes password is stolen and used on iTunes we recommend that you contact your financial institution and inquire about canceling the card and issuing a chargeback for any unauthorized transactions. We also recommend that you change your iTunes account password immediately. For more information on best practices for password security visit http://www.apple.com/support/itunes.</p>
</blockquote>

<p>Good advice for this incident, great advice in general. Also remember to never, not ever, click a link in an email and log into an account. That's how social engineering attacks like Phishing scams work. Use a strong password (long, with numbers and symbols), keep it unique, and change it once and a while. Treat it as securely as you treat your credit card and cash -- because that's what it is.</p>

<p>UPDATE: According to Clayton Morris who followed up with Apple, about 400 users were impacted. iTunes's servers were not hacked. In response Apple will be increasing the frequency they require you to enter your credit card verification number going forward.  </p>

<p>[<a href="http://www.engadget.com/2010/07/06/apple-responds-on-itunes-fraud-vaguely-confirms-said-fraud/">Engadget</a>, <a href="http://claytonmorris.squarespace.com/blog/2010/7/6/apple-says-only-a-small-percentage-of-itunes-accounts-were-c.html">Clayton Morris</a>]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2010/07/06/apple-comments-itunes-fraud-dev-banned-changed-password/feed/</wfw:commentRss>
		<slash:comments>19</slash:comments>
		</item>
		<item>
		<title>iPhone 3.0: Mobile Safari to get Anti-Phishing, Auto Fill</title>
		<link>http://www.imore.com/2009/03/18/iphone-30-mobile-safari-antiphishing-auto-fill/</link>
		<comments>http://www.imore.com/2009/03/18/iphone-30-mobile-safari-antiphishing-auto-fill/#comments</comments>
		<pubDate>Wed, 18 Mar 2009 13:52:25 +0000</pubDate>
		<dc:creator>Rene Ritchie</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[3.0]]></category>
		<category><![CDATA[auto fill]]></category>
		<category><![CDATA[iphone 3.0]]></category>
		<category><![CDATA[iphone OS 3.0]]></category>
		<category><![CDATA[mobile safari]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Safari]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=7594</guid>
		<description><![CDATA[Apple has gotten some much-deserved heat in the past for not adapting anti-phishing measures into their Safari browser. Phishing is when "bad guys" make look-alike websites and try to trick]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.imore.com/images/stories/2009/03/iphone_30_settings_safari_anti_phishing-266x400.png" alt="" title="iphone_30_settings_safari_anti_phishing" width="266" height="400" class="aligncenter size-medium wp-image-7595" /></p>

<p>Apple has gotten some much-deserved heat in the past for not adapting anti-phishing measures into their Safari browser. Phishing is when "bad guys" make look-alike websites and try to trick users into entering personal data like passwords or credit cards numbers, so they can be used to break into user accounts or make fraudulent purchases. We've had some warnings about <a href="http://www.imore.com/tag/phishing/">MobileMe phishing attacks</a> in the past for example.</p>

<p><a href="http://www.imore.com/2009/02/24/apple-releases-safari-4-beta-iphone-safari/">Safari 4 Beta</a> on the desktop finally took steps to address this, and it looks like Apple is rolling the anti-phishing alerts out to Mobile Safari as well! As more and more people start using mobile browsers for banking, email, and other security-sensitive tasks, Apple can't be too careful.</p>

<p>Also of note in the screen shot above is auto-fill. We're guessing this works like the desktop, automatically entering common data in text fields like name, email address, etc. (Of course, the convenience comes at the expense of the very security mentioned above -- balance your usage accordingly!)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2009/03/18/iphone-30-mobile-safari-antiphishing-auto-fill/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Yet Another MobileMe Phishing Scam</title>
		<link>http://www.imore.com/2009/02/26/mobileme-phishing-scam/</link>
		<comments>http://www.imore.com/2009/02/26/mobileme-phishing-scam/#comments</comments>
		<pubDate>Thu, 26 Feb 2009 14:27:56 +0000</pubDate>
		<dc:creator>Rene Ritchie</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[mobileme]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=7284</guid>
		<description><![CDATA[<a href='http://www.imore.com/images/stories/2009/02/mobileme-00225-3.png'></a>

Stealing credit card information is big business so perhaps it should come as no surprise that we're seeing so many phishing attacks targeted at even niche services like MobileMe. We've]]></description>
			<content:encoded><![CDATA[<p><a href='http://www.imore.com/images/stories/2009/02/mobileme-00225-3.png'><img src="http://www.imore.com/images/stories/2009/02/mobileme-00225-3-400x341.png" alt="" title="mobileme-00225-3" width="400" height="341" class="aligncenter size-medium wp-image-7285" /></a></p>

<p>Stealing credit card information is big business so perhaps it should come as no surprise that we're seeing so many phishing attacks targeted at even niche services like MobileMe. We've <a href="http://www.imore.com/tag/phishing">reported on a bunch of them</a> already, and this latest one is just more of the same.</p>

<p>If you get an email warning you about the status of your account, asking you to verify billing info, or basically asking you anything at all, NEVER click on the link. Always launch your web browser and type in the main URL by hand (i.e. don't click on the email's "Login" button, go to Firefox or Safari and type in "http://www.me.com/"). (And yes, DNS can be cache poisoned and localhosts can be over-written, but depending how valuable a target you are and how much time you want to invest in proofing yourself, manually entering URLs is a good compromise between convenience and security.</p>

<p><a href="http://www.appleinsider.com/articles/09/02/26/new_phishing_scam_targets_mobileme_users.html">Apple Insider</a> has all the details for those who want them. Surf safe!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2009/02/26/mobileme-phishing-scam/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>MobileMe Phishing Scam Round 3</title>
		<link>http://www.imore.com/2008/09/23/mobileme-phishing-scam-round-3/</link>
		<comments>http://www.imore.com/2008/09/23/mobileme-phishing-scam-round-3/#comments</comments>
		<pubDate>Wed, 24 Sep 2008 02:11:16 +0000</pubDate>
		<dc:creator>Jeremy Sikora</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[mobileme]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Phishing Scam]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=4568</guid>
		<description><![CDATA[<a href='http://www.imore.com/images/stories/2008/09/apple_phishing_t.jpg'></a>

Well it seems like these scam artists will just not go away! Here at TiPb we like to keep you, our loyal readers, safe by alerting you of every scam]]></description>
			<content:encoded><![CDATA[<p><a href='http://www.imore.com/images/stories/2008/09/apple_phishing_t.jpg'><img src="http://www.imore.com/images/stories/2008/09/apple_phishing_t.jpg" alt="" title="apple_phishing_t" width="400" height="291" class="aligncenter size-medium wp-image-4570" /></a></p>

<p>Well it seems like these scam artists will just not go away! Here at TiPb we like to keep you, our loyal readers, safe by alerting you of every scam out there.  A while back we reported <a href="http://www.imore.com/2008/08/15/mobileme-phishing-attack-nets-hundreds-of-victims/">two</a> <a href="http://www.imore.com/2008/09/08/mobileme-phishing-scam-round-2/">other</a> phishing scams aimed at MobileMe customers, and told you Apple was even <a href="http://www.imore.com/2008/08/29/apples-mobileme-blog-addresses-phishing-scams/">posting warnings</a> about them.</p>

<p>Just like those phishing scams, these latest scammers are looking to obtain your credit card information.  According to <a href="http://www.ugnn.com/2008/09/apple_phishing_alert.html">UGN Infomanager</a>:</p>

<blockquote>Yesterday, and over night a wave of phishing attacks hit the servers targeting Apple Mobile Me users, and others who might not know the specifics of the phish. There were several, all from different "senders" but leading to the same address. READ THIS ALERT.<br /><br />

<strong>DO NOT CLICK ON ANY LINK IN THIS PHISHING ATTEMPT</strong>. 
Not only could it extract information from your computer, the site, or clickthrough pages could contain malware or spyware intended specifically for Mac users. If you can avoid opening it, you will avoid pinging the botnet of a live address.</blockquote>

<p>In addition to all of that, <a href="http://www.macnn.com/articles/08/09/23/mobileme.phishing.scam/">MacNN</a> is reporting that "the originating server DNS addresses have been masked by Joker.com, a site suspected of sympathizing with online criminals".  Really nice isn't it?  Be careful out there people!</p>

<p>(<em>Via <a href="http://www.macnn.com/articles/08/09/23/mobileme.phishing.scam/">MacNN</a></em>)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2008/09/23/mobileme-phishing-scam-round-3/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>MobileMe Phishing Scam Round 2</title>
		<link>http://www.imore.com/2008/09/08/mobileme-phishing-scam-round-2/</link>
		<comments>http://www.imore.com/2008/09/08/mobileme-phishing-scam-round-2/#comments</comments>
		<pubDate>Mon, 08 Sep 2008 22:55:26 +0000</pubDate>
		<dc:creator>Jeremy Sikora</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[mobileme]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=4159</guid>
		<description><![CDATA[<a href='http://www.imore.com/images/stories/2008/09/mobileme_scam.jpg'></a>

Not long ago we brought to your attention a <a href="http://www.imore.com/2008/08/15/mobileme-phishing-attack-nets-hundreds-of-victims/">phishing scam</a> that was going around to some MobileMe customers, we then reported that <a href="http://www.imore.com/2008/08/29/apples-mobileme-blog-addresses-phishing-scams/">Apple addressed the scam in their MobileMe </a>]]></description>
			<content:encoded><![CDATA[<p><a href='http://www.imore.com/images/stories/2008/09/mobileme_scam.jpg'><img src="http://www.imore.com/images/stories/2008/09/mobileme_scam.jpg" alt="" title="mobileme_scam" width="366" height="301" class="aligncenter size-medium wp-image-4162" /></a></p>

<p>Not long ago we brought to your attention a <a href="http://www.imore.com/2008/08/15/mobileme-phishing-attack-nets-hundreds-of-victims/">phishing scam</a> that was going around to some MobileMe customers, we then reported that <a href="http://www.imore.com/2008/08/29/apples-mobileme-blog-addresses-phishing-scams/">Apple addressed the scam in their MobileMe blog</a>.   Well Apple Insider is now reporting that round 2 is just begining.</p>

<p>In this latest scam, an email is going around that says there are some issues with the users subscription renewal information.  It then goes on to direct them to a link to update their credit card information.  You can see the exact email that MobileMe customers are receiving below.  Notice there is not a single MobileMe logo?</p>

<p><a href='http://www.imore.com/images/stories/2008/09/mmfraud-1.png'><img src="http://www.imore.com/images/stories/2008/09/mmfraud-1.png" alt="" title="mmfraud-1" width="164" height="200" class="aligncenter size-thumbnail wp-image-4161" /></a></p>

<p>Here are some great tips from Rene:
<blockquote>REMEMBER: Don’t EVER believe email requests for secure data. Go to the site yourself (not through their link — type it in) and log in and see if there really is a problem. Check domain names carefully. App1e.com isn’t the same as Apple.com, they’re just hoping you don’t notice. Worried about the recent DNS poisoning attacks? Use HTTPS/SSL or use a direct IP address. If in any doubt, pick up a phone and call Apple (or your credit card company) directly.</blockquote></p>

<p>Head on over to <a href="http://www.appleinsider.com/articles/08/09/07/mobileme_users_hit_by_phishing_scam.html">Apple Insider</a> for the full story with detailed pictures.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2008/09/08/mobileme-phishing-scam-round-2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Apple&#039;s MobileMe Blog Addresses Phishing Scams</title>
		<link>http://www.imore.com/2008/08/29/apples-mobileme-blog-addresses-phishing-scams/</link>
		<comments>http://www.imore.com/2008/08/29/apples-mobileme-blog-addresses-phishing-scams/#comments</comments>
		<pubDate>Sat, 30 Aug 2008 02:29:27 +0000</pubDate>
		<dc:creator>Rene Ritchie</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[mobileme]]></category>
		<category><![CDATA[mobileme update blog]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=4052</guid>
		<description><![CDATA[Remember that <a href="http://www.imore.com/2008/08/15/mobileme-phishing-attack-nets-hundreds-of-victims/">phishing scam</a> that targeted MobileMe users a while back? The one that may have nabbed hundreds of account holders' information? Well Apple must, because the latest in their]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.imore.com/images/stories/2008/08/mobileme_phishing.jpg" alt="" title="mobileme_phishing" width="366" height="400" class="aligncenter size-medium wp-image-3823" /></p>

<p>Remember that <a href="http://www.imore.com/2008/08/15/mobileme-phishing-attack-nets-hundreds-of-victims/">phishing scam</a> that targeted MobileMe users a while back? The one that may have nabbed hundreds of account holders' information? Well Apple must, because the latest in their series of MobileMe Updates <a href="http://www.apple.com/mobileme/news/2008/08/being-phishing-aware.html">addresses the issue</a> head on:</p>

<blockquote>You will never receive a message from MobileMe asking you to send personal information over email. If we are ever unable to charge your credit card, for instance, we will send you a reminder email, but will not directly link to any web pages. The safest way to respond and update any necessary information is to type www.me.com into your browser and log in to your account directly. That way you can be confident you are at me.com and your personal information is secure.</blockquote>

<p>Apple further <a href="http://support.apple.com/kb/HT2080">provides a support document</a> on how to better determine the actual destination hidden behind a link, and an email address -- <a href="mailto:reportphishing@apple.com">reportphishing@apple.com</a> -- where users can forward any questionable content for investigation by Apple legal and law enforcement.</p>

<p>Together, MobileMe users can help take a byte out of Apple-targeted crime!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2008/08/29/apples-mobileme-blog-addresses-phishing-scams/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>MobileMe Phishing Attack Nets Hundreds Of Victims</title>
		<link>http://www.imore.com/2008/08/15/mobileme-phishing-attack-nets-hundreds-of-victims/</link>
		<comments>http://www.imore.com/2008/08/15/mobileme-phishing-attack-nets-hundreds-of-victims/#comments</comments>
		<pubDate>Fri, 15 Aug 2008 20:35:35 +0000</pubDate>
		<dc:creator>Rene Ritchie</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[mobileme]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=3822</guid>
		<description><![CDATA[<a href='http://www.imore.com/images/stories/2008/08/mobileme_phishing.jpg'></a>

Remember that warning we posted on Tuesday about a <a href="http://www.imore.com/tag/mobileme/">MobileMe phishing attack in the wild</a>? Turns out it's been terrifyingly effective so far. <a href="http://arstechnica.com/journals/apple.ars/2008/08/15/hundreds-of-mobileme-customers-caught-in-phishing-net">Ars Technica</a> quotes CardCops president Dan]]></description>
			<content:encoded><![CDATA[<p><a href='http://www.imore.com/images/stories/2008/08/mobileme_phishing.jpg'><img src="http://www.imore.com/images/stories/2008/08/mobileme_phishing.jpg" alt="" title="mobileme_phishing" width="366" height="400" class="aligncenter size-medium wp-image-3823" /></a></p>

<p>Remember that warning we posted on Tuesday about a <a href="http://www.imore.com/tag/mobileme/">MobileMe phishing attack in the wild</a>? Turns out it's been terrifyingly effective so far. <a href="http://arstechnica.com/journals/apple.ars/2008/08/15/hundreds-of-mobileme-customers-caught-in-phishing-net">Ars Technica</a> quotes CardCops president Dan Celements:</p>

<blockquote>"We found 20 different files parked on the server, each file with two or three or four, up to 20, profiles. Cumulatively, there were about 300 profiles collected in that one day. And 100 to 200 were mac.com addresses."</blockquote>

<p>NOT GOOD. Ars goes on to rightly point out that Apple customers are typically higher-income, and thus more desirable targets. We'd also add that Apple users are not as accustomed to malware and phishing as our Windows-using friends, but as email and web browsing doesn't care about platform, we REALLY need to be. Just like you wouldn't open a package left at your door that smelled like gasoline and was ticking, even if it came in a Tiffany's box, don't open links or give out credit card information just because it fakes coming from Apple.</p>

<p>REMEMBER: Don’t EVER believe email requests for secure data. Go to the site yourself (not through their link — type it in) and log in and see if there really is a problem. Check domain names carefully. App1e.com isn’t the same as Apple.com, they’re just hoping you don’t notice. Worried about the recent DNS poisoning attacks? Use HTTPS/SSL or use a direct IP address. If in any doubt, pick up a phone and call Apple (or your credit card company) directly.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2008/08/15/mobileme-phishing-attack-nets-hundreds-of-victims/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WARNING: MobileMe Phishing Scam in the Wild</title>
		<link>http://www.imore.com/2008/08/12/warning-mobileme-phishing-scam-in-the-wild/</link>
		<comments>http://www.imore.com/2008/08/12/warning-mobileme-phishing-scam-in-the-wild/#comments</comments>
		<pubDate>Tue, 12 Aug 2008 15:00:46 +0000</pubDate>
		<dc:creator>Rene Ritchie</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[mobileme]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=3770</guid>
		<description><![CDATA[Phishing attacks, where a bad guy tries to fool you into giving them personal information such as financial account logins, are nothing new on the 'net. Fake emails leading you]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.imore.com/images/stories/2008/06/iphone_pirate_2.jpg" alt="iPhone 2.0 Jailbreak and Unlock" title="iPhone 2.0 Jailbreak and Unlock" width="273" height="336" class="aligncenter size-full wp-image-2601" /></p>

<p>Phishing attacks, where a bad guy tries to fool you into giving them personal information such as financial account logins, are nothing new on the 'net. Fake emails leading you to a fake bank site to enter your information so that they (increasingly organized crime, often in Russia or China) can log into your real site and transfer out all your money, then steal your identity and sell it off to second and third tier hackers for other nefarious uses. </p>

<p>This specific attack pretends to come from Apple regarding a MobileMe billing problem, and asks the user to click a link to update their credit card information (which will be promptly stolen). What makes this recent attack particularly dangerous is that <a href="http://www.imore.com/2008/07/19/rocky-launch-botched-authorization-4-month-of-mobileme-free/">MobileMe HAS had billing problems</a> in the recent past, and what with all the other problems associated with the launch, users may be unfortunately prone to believe the phishing attack.</p>

<p>REMEMBER: Don't EVER believe email requests for secure data. Go to the site yourself (not through their link -- type it in) and log in and see if there really is a problem. Check domain names carefully. App1e.com isn't the same as Apple.com, they're just hoping you don't notice. Worried about the recent DNS poisoning attacks? Use HTTPS/SSL or use a direct IP address. If in any doubt, pick up a phone and call Apple (or your credit card company) directly.</p>

<p>Yes, the bad guys are bombing the internet back to the stone age. It's not a safe browsing world. Be careful and protect your data with the same care you protect real-world valuables.</p>

<p>(via <a href="http://arstechnica.com/journals/apple.ars/2008/08/12/phishing-e-mail-appears-in-mobileme-disguise">Ars Technica</a>)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2008/08/12/warning-mobileme-phishing-scam-in-the-wild/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

