Twitter user Fry apparently falls foul of latest social networking attack

Sophos warns of Twitter attacks

Stolen personal details could leave Twitter users vulnerable to further cyber attacks

Written by Dinah Greek, Computeractive

Twitter users have been warned of an evolving attack that tries to fool them into giving away personal information and opens them up to online fraud.

Security company Sophos said it had received reports that people were getting direct messages that purported to be from friends, with links saying they can view pictures or blogs about themselves and even win an iPod.

However, the messages are spoofed and the links go to a page that looks like the regular Twitter login page, but which is actually a phishing website.

Advertisement

This allows the criminals to steal the unwary user’s Twitter log-in details. These are then used to continue the scam and pass on the messages to more Twitter users. However, Sophos said that the information about a person gained thought the Twitter attacks could be used for more frauds.

Graham Cluley, Sophos’ senior technology consultant, said: "It would be bad enough to hand your Twitter username and password over to a criminal, as they could pose as you online and spread malware and spam to your friends and followers.

“However, as an alarming 41 per cent of internet users foolishly use the same username and password for every website they access, the potential for abuse is even greater.

"Compromised social networking accounts are valuable for hackers as they can use them as a springboard for spam campaigns, identity theft attacks and other online crime.”

According to Sophos, thousands of Twitter users have reported getting these messages with writer, TV star and Twitter celebrity Stephen Fry among those who unwittingly clicked on the link. The original messages over the weekend pretended to point to funny pictures or blog articles about the recipients:

"Hey, I found a website with your pic on it... LOL check it out here."
"Hey! Check out this funny blog about you."

However, clicking on the links would take users to a bogus Twitter page that would steal users' login names and passwords. Other messages are claiming that recipients could win an Apple iPhone if they visit a web link:

"Hey. I won an iPhone! Come see how here."
"Wanna win the new iPhone? It's so easy and cool, I love this thing!"

Twitter users who may have lost control of their accounts need to change their passwords as a matter of priority before more harm is done, warned Sophos.

Tags:

Reader comments

More from Computeractive

News

The latest home computing news

Downloads

The best PC tools, applications and more

Reviews

Independent opinions on new hardware and software

Step-by-step guides

Easy-to-follow projects with pictures

PC Help

Solve PC problems with our Q&A

Videos

PC projects demonstrated and product reviews

Articles

An in-depth look at how to get the best from your PC

Magazine

What's coming up in Computeractive

Forums

Get help with your PC problems from our readers

Competitions

Your chance to win computing prizes

Shopping

Great deals on products, services and more

NEW! Computeractive CD Rom 11
All 26 issues of Computeractive from 2008 on one CD-Rom.

Ultimate Guide to Disc Burning
Everything you need to know about creating your own discs.

Create your own calendars softwareCreate your own Calendars
The fun and easy way to create your own calendars!

Computeractive - Issue 280Computeractive Back Issues
Missed an issue? Click here to find a back issue

Blogs

Windows Watch

Windows Watch

Keeping an eye on the latest XP and Vista news

An example of good hardware design

A friend has had to send his XBox 360 back to Microsoft for repairs, and the instructions for doing so recommended removing...

Download Junkie

Download Junkie

Your daily dose of download discussion

Buy Acronis True Image 2009 for only $35.99, 25% off the RRP!

Many of us are downloading our media files from the Internet, then storing them on our hard drive....

Advertisement

Free email newsletters

Techno babble demystified...

[Display all definitions]

Or type in any computer-related word and click "Go"

Advertisement

Computeractive is not reponsible for content of Google adverts

Primary Navigation

© Incisive Media Ltd. 2009. Incisive Media Limited, Haymarket House, 28-29 Haymarket, London SW1Y 4RX, is a company registered in England and Wales with company registration number 04038503

Search computeractive.co.uk