NEW YAHOO SCAM: SPREAD IT AROUND

Submitted by Lynn on Tue, 03/07/2006 - 9:30am.

I've been on the Internet a long time. I almost never get fooled by login scams, aka phishing expeditions. The reason I now have to put "almost" in there is that this morning I got fooled for the first time.

I got a Yahoo Instant Message from my husband's little-used Yahoo account with an URL in it. The URL was:

http://www.geocities.com/look_at_me_now_2006/

(If you go there DO NOT LOG IN. IT IS NOT THE YAHOO PHOTOS SITE.)

screen shot of fake Yahoo Photos page

Now normally I'd look at a login page allegedly for something like eBay or a bank and if the URL wasn't an eBay or bank URL I'd know it for what it was--an attempt to hijack my account. This time was a little more complicated. I thought my husband had sent me the URL. Geocities is owned by Yahoo. It was possible that this was some kinda front end to Yahoo Photos I hadn't seen before. All of this went through my head in about a tenth of a second.

So I logged in. And got kicked to the sign-in screen for the REAL Yahoo Photos site. This is an instant clue that you've been had, and I had indeed been had. I immediately signed in to Yahoo and changed my password, so my account is safe. I hope.

Here's how I think the scam is working: These guys hijacked someone's Yahoo account and built the Geocities page to harvest more account IDs and passwords. They sent out the URL via the first hijacked account's buddy list. Thinking it was a trusted friend, the buddies clicked on the URL and tried to log in. Bingo, a bunch more accounts for the bad guys to hijack. They log in to those accounts, send out the URL again via those accounts' buddy lists, and off we go. Somewhere in there, my husband got had, and once that happened, I got had.

If you've gone to this URL and logged in, GO TO YAHOO AND CHANGE YOUR PASSWORD ASAP.

Technorati Tags:
( categories: )

Guest's picture

about 500$ of yahoo

Submitted by Guest (not verified) on Sat, 07/28/2007 - 9:50pm.

i want to ask you that many of us are getting mail
that you won 500$ by yahoo is it true..

reply to my email..

Lynn's picture

I don't have your email, I'm afraid

Submitted by Lynn on Sat, 07/28/2007 - 11:40pm.

So I hope you see this. No, Yahoo is NOT giving away money by email. If you get an email saying you've won money, 99.9999999% of the time it's going to be a fake.

Lynn Siprelle, Editor

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Lines and paragraphs break automatically.
  • You may quote other posts using [quote] tags.
  • Textual smileys will be replaced with graphical ones.
  • Web and e-mail addresses are automatically converted into links.
More information about formatting options