Simple clear advice in plain English

Myspace users targeted in phishing scam

Scammers lure Myspace music fans to paying download sites and steal their personal details

MySpace logo
internet/myspace-usa

Myspace music lovers are being targeted by a mass phishing attack that directs them to a fake music download site.

According to IT security firm, Sophos, the emails try to lure the victim to the Myspace website to listen to a free music track sent by a Myspace user. However, rather than taking users to the Myspace website, it directs them to a site claiming to sell mp3 music.

Here the person is encouraged to pay to download music; this means the phishers can harvest personal information, credit card details and email addresses.

However, the site, which only had its domain name registered on 5 October and claims to be based in Lappeenranta in Finland, has no affiliation with the social networking website.

Sophos warned it is an aggressively distributed campaign and the phishing emails have been sent to hundreds of thousands of people around the world in the last week.

By pretending to be an email from a Myspace contact, the spammers heighten the chances of potential victims opening the email.

The company noted that to give the email additional authentication, the phishers have also included a faked Myspace boilerplate text in their message: "At Myspace we care about your privacy. We have sent you this notification to facilitate your use as a member of the Myspace service. If you don't want to receive emails like this to your external email account in the future, change your Account Settings to 'Do not send me notification emails'."

Graham Cluley, senior technology consultant at Sophos, said: "By making the headlines nearly every day, the Myspace brand has quickly become a household name, with 43 million users now signed up. As a result, it was only a matter of time before spammers jumped on its popularity for illegal purposes.

"This email has been so aggressively spammed out that many of its recipients are not even Myspace users, so common sense should tell them the email is unsolicited and is to be deleted.

"Anyone who follows the links expecting to get free music, however, is risking handing their email address, credit card numbers and other private information over to the spammers."

The subject headings of the phishing emails typically read: 'New message from on Myspace sent on

Article tags

Reader Comments

   

Add your comment

All fields must be completed. Your email address will not be displayed or used to send marketing messages.

All messages will be checked by moderators before appearing on the site.

See our Privacy Policy for more information.

Related articles

Wireless router settings

Is your PC security up to scratch?

Follow our 20 hints and tips to help you keep your valuable personal information safe

Results of searching online

What does the internet know about your friends and private life?

It's easy for other people to find out more about you than want them to know but we explain how you can lessen the chances of revealing too much online

Google Plus

Sophos warns spammers are sending out fake Google+ invites

First Google Plus-related scam identified by security company Sophos

Question & Answer

Q.Can I switch boot drives so that I can work on older...

> Read the answer

Q.Can I open my old genealogy files or have they gone...

> Read the answer

Q.Why are odd patterns appearing on my monitors shortly...

> Read the answer

Best deals on the web

img

Apple iMac 21.5" (MC309)

£927.29- Buy it now

img

Dell Inspiron 620 ST Intel Core i3-2100 3.10GHz / 3GB / 500GB / DVDRW / Win 7 Home Premium

£329.00- Buy it now

img

ZooStorm 7877-1023

£386.38- Buy it now

Latest issue & subscription deals

Poll

Are you concerned about viruses that target mobile phones?

Jargon Buster

Computing terms explained in plain English

Restore point

A Windows backup of system files and settings.

Great shopping deals from Computeractive