Salted Hash — IT security news

About this Blog:

IT security news analysis, over easy!

Salted Hash — IT security news

Beware of Amex 'payment received' phishing attempts

I got an email this morning about how American Express received a payment from me. Had I clicked on the embedded links, I would have been in trouble.

to Social Engineering |

For a split second, I was excited as the email told me American Express had received a payment from me to the tune of $4,127.38. I have a balance to pay off on my corporate card, after all.

Then I remembered that my real balance is much lower than that. In fact, I don't think I've ever carried a balance that high.

I investigated with the folks in our finance department, who confirmed that this is indeed just another phishing attempt.

The obvious message, here: If you get an email from Amex about a payment, don't trust it. Don't click it.

Have a reasonably safe Monday.

More on phishing and social engineering:

CSO's Ultimate Guide to Social Engineering

Latest Citadel scam sophisticated -- except for grammar

5 scams on Tumblr, Pinterest

New Zeus malware scam promises rebates, security


WEBCAST
Transition Confidently to the Cloud

Vormetric Thanks to cloud computing, your business data is everywhere and being accessed by everyone. Making the wrong decision to protect your data can result in high costs, increased risk and executive exposure. View this live webinar on cloud security and the evolving data center, and learn why a data-centric approach to security is the best bet for today's virtual environment.

» Learn More

WHITE PAPER
Magic Quadrant for Enterprise Information Archiving

Symantec Gartner evaluates vendors offering products and services that provide archiving for email, files and other content types.

» Learn More

Browse CSO Blogs

See all CSO Blogs »

Recent Comments

RESOURCE CENTER