itmanagerdaily.com » Warn users about Twitter hijacking

Warn users about Twitter hijacking

March 9, 2010 by Sam Narisi
Posted in: In this week's e-newsletter, Latest News & Views, Security, User support

Your users who are harnessing the power that is Twitter need a heads up: Cyberthieves are targeting the popular social network big time.

Here’s a brief rundown on how these scams work:

The scams are similar to an instant message or in an e-mail spoof. A message arrives from a friend saying: “haha. This you????” or “Lol. this you??” followed by a Web link.

The link takes the targeted user to a Web site that looks like a Twitter sign-in page. It’s not. Check the URL and you’ll see that it’s hosted elsewhere. If a user enters credentials, they’re stolen.

Twitter is prone to this kind of attack due to the popularity of URL-shortening services – scammers can use those to disguise links.

One scam in particular has gotten a lot of press lately. Its victims so far include HSBC Bank, a British cabinet minister and members of the British press.

Warn users, especially marketing folks who use the site for company business, not to assume that messages from contacts are legitimate.

If they’re sent to what looks like Twitter’s login page, they should check the URL to make sure they aren’t giving info away.

What should users do if they fall victim to the scam?

Tell them to:

  1. Change their password immediately
  2. Change the password on any service where they use the same password
  3. Change the password on any service that uses Twitter, such as Twitterfeed, and
  4. Notify contacts about what happened and apologize.

ITManagerDaily delivers the latest IT news once a week to the inboxes of over 175,000 IT professionals.

Click here to sign up and start your FREE subscription to ITManagerDaily!

Tags: ,

One Response to “Warn users about Twitter hijacking”

  1. Twitter warning Says:

    [...] I’ve never used Twitter.  I don’t know how to “tweet” (say something in 140 characters or less).  But a scam warning has been issued that I feel compelled to pass along.  It is currently posted at this site: http://itmanagerdaily.com/warn-users-about-twitter-hijacking/. [...]

Leave a Reply


advertisement

Whitepapers


    Quick Vote

    • Will your company add IT employees this year?

      • No, our staffing levels will stay the same (55%, 11 Votes)
      • Yes (25%, 5 Votes)
      • No, we'll be eliminating positions (20%, 4 Votes)

      Total Voters: 20

      Loading ... Loading ...

  • advertisement

    See what readers are saying...

    • Brad L: I would add: Do not use REPLY ALL unless you really want everyone to get your response. Use REPLY as a rule....
    • sophie: Here's two more ideas I use: 1. when writing an email, I don't put the recipient's name into the TO box until it is co...
    • Ray DaSilva: Really ? iPhone 4 Antenna Problem = Windows Vista Operational System. The OS that MS charged $ 300 and then charge an...
    • Dave K: Scammers are getting clever. I received a call from 800-955-6600 saying "This is Capital One. Please enter your 16-digi...
    • BJ: My identity was stolen earlier this year when I allowed my driver's license to be copied in order to test drive a new ca...
    • Rasheen: The common problem I face when advising corporations of security risk is the false perception that the companies informa...







    a