0%

What you need to know about SMS phishing attacks

27 авг. 2021 г. 5 мин чтения
Изображение Баннера Новостной Статьи

If you believe you’ve received an SMS phishing attack, take these first three steps:

  1. Do not click the link!

  2. Copy the message and send it to 7726 (SPAM), a short-code service established by US-based cell phone carriers to help them detect and block malicious messages on their network

  3. Take a screenshot of the message and send it to [email protected]

What is SMS phishing?

Phishing is a type of online attack in which a cybercriminal impersonates a legitimate entity or authority and attempts to deceive their target into clicking on a malicious link or attachment. This can enable hackers to steal their victim’s sensitive information or infect their device with malicious software.

You may already privy to email-based phishing attacks, in which the attacker delivers a phishing message via email. However, in recent years, attackers have adopted a new type of delivery method — SMS, otherwise known as text messages.

SMS phishing, also known as “smishing”, is a type of phishing attack in which an attacker will spam malicious messages and links to hundreds or even thousands of cell phone numbers to deceive the recipients into taking some action that is against their best interest.

For crypto holders, the intent is to gain access to the recipient’s crypto wallet or account so that they can steal their funds. SMS phishing is largely problematic in crypto for two reasons:

  1. Cybercriminals have an ever-growing incentive to steal crypto assets due to their unprecedented growth in monetary value, and

  2. Crypto asset transactions are irreversible once the transaction has been confirmed and written onto the blockchain ledger.

If you’re invested in crypto, or even considering it, we strongly encourage you to take the time to understand how to identify this common threat and what to do if you receive one of these messages.

How to identify SMS phishing

Phishing messages can be easily detected 99.9% of the time by completing three simple checks. Let’s use the Coinbase SMS phishing message below as an example for this lesson:

  1. The Sending Number. One of the first things to check is the phone number from where the message was sent. By doing a quick Google search, you will find that this phone number is likely associated with a scam — your first red flag.

  2. The Message. Grammar mistakes are often a red flag indicating the message is likely a scam. If there are no grammar issues, check the intent of the message. Phishing messages will often attempt to tap into your emotions by either creating fear or excitement. If you receive a message that is emotionally triggering, either good or bad, it may be a phishing message and should be a red flag.

  3. The Link. Lastly, always be sure to examine the link. Plain and simple, if the link does not contain the domain Coinbase.com, it is phishing.

What to do if you receive an SMS phishing message

Now that you’ve got the tools to detect SMS phishing messages, the question remains — what should you do if you receive an SMS phishing message?

Luckily, the right response to protect yourself is easy: Do not click the link!

You can also copy the message and send it to 7726 (SPAM). 7726 is a short-code service established by US-based cell phone carriers like AT&T, Verizon, Sprint, or T-Mobile. By sending a copy of the SMS phish to 7726, you can help mobile carriers detect and block malicious messages on their network.

Lastly, take a screenshot of the message and send it to [email protected]. You’ll be enabling our Security team to investigate the phishing link and submit abuse reports to organizations that can help have the phishing site taken down.

As cryptocurrency grows in popularity, cybercriminals will continue to innovate and attempt to discover new ways to gain access to your investments. Coinbase Security continues to keep our customers abreast of new threats as they arise. However, it is also imperative that you take the security of your account into your own hands. If you’d like to learn more about account security best practices, review our guide on how to keep your crypto secure.

Additional examples of SMS phishing

  • The phone number is largely unknown according to Google

  • The message has a grammar issue and is trying to invoke a fear response of unauthorized account access

  • The link is not Coinbase.com. The domain in this link is what’s known as an Internationalized Domain Name (IDN). Take note of the special character accent on the “b”. Attackers will often use IDNs in phishing attacks since the letters can so closely resemble the word Coinbase.

  • The phone number is abnormally long and suspicious

  • The message has many grammar issues and is trying to invoke excitement by indicating receipt of 21 BTC

  • The link is not Coinbase.com

  • The phone number is largely unknown according to Google

  • The message is trying to invoke excitement by indicating receipt of 0.59 BTC

  • The link is not Coinbase.com (notice the link actually goes to the domain ssl-coinbase[.]com)

was originally published in The Coinbase Blog on Medium, where people are continuing the conversation by highlighting and responding to this story.

Автоматизируйте
свою
торговлю!

Автоматический бот мирового класса для торговли криптовалютами

Давайте начнём
Автоматизируйте свою торговлю

Популярные новости

How to Set Up and Use Trust Wallet for Binance Smart Chain
#Bitcoin#Bitcoins#Config+2 дополнительные теги

How to Set Up and Use Trust Wallet for Binance Smart Chain

Your Essential Guide To Binance Leveraged Tokens

Your Essential Guide To Binance Leveraged Tokens

How to Sell Your Bitcoin Into Cash on Binance (2021 Update)
#Subscriptions

How to Sell Your Bitcoin Into Cash on Binance (2021 Update)

What is Grid Trading? (A Crypto-Futures Guide)

What is Grid Trading? (A Crypto-Futures Guide)

Начните торговать с Cryptohopper бесплатно!

Бесплатное использование (кредитная карта не требуется)

Приступим
Cryptohopper appCryptohopper app

Отказ от ответственности: Cryptohopper не является регулируемой организацией. Торговля криптовалютами с помощью ботов связана с существенными рисками, и прошлая эффективность не являются признаком такой же эффективности их применения в будущем. Прибыль, показанная на скриншотах продукта, приведена для примера и может быть преувеличена. Занимайтесь торговлей с помощью ботов только в том случае, если обладаете достаточными знаниями, или обратитесь за советом к квалифицированному финансовому консультанту. Ни при каких обстоятельствах Cryptohopper не несет ответственности перед любым физическим или юридическим лицом за (а) любые убытки или ущерб, полностью или частично, вызванные, возникшие в результате или в связи с транзакциями с использованием нашего программного обеспечения, или (б) любые прямые, косвенные, особенные, последующие или случайные убытки. Пожалуйста, обратите внимание, что контент, доступный на социальной торговой платформе Cryptohopper, создаётся членами сообщества Cryptohopper и не является советом или рекомендацией Cryptohopper или от его имени. Прибыль, показанная в Маркетплейсе (Торговой площадке), не является индикатором будущих результатов. Используя услуги Cryptohopper, вы признаёте и принимаете риски, присущие торговле криптовалютой, и соглашаетесь оградить Cryptohopper от любых обязательств или понесенных убытков. Прежде чем использовать наше программное обеспечение или участвовать в любой торговой деятельности, необходимо ознакомиться и понять наши Условия предоставления услуг и Предупреждение о рисках. Пожалуйста, обратитесь к юридическим и финансовым специалистам для получения индивидуального совета, основанного на ваших конкретных обстоятельствах.

©2017 - 2024 Copyright by Cryptohopper™ - Все права защищены.