12 Scams of Christmas, UPS ‘Shmishing’ Scam Alert, and More.

by | Dec 19, 2024 | Blog

This Week In Tech, we talk about the Better Business Bureau's 12 scams of Christmas, UPS smishing scam alert, and Windows malware attack targeting YouTube channels.

12 scams of Christmas.

During the holiday season, it’s important to watch out for scams targeting shoppers and donors. Here are key types to watch for:

  1. Misleading Social Media Ads: Research before buying, as many items advertised on social media are either fake or not as described.
  2. Social Media Gift Exchanges: These scams involve pyramid schemes where personal information is shared, and gifts or money are sent to strangers.
  3. Holiday Apps: Be cautious of free apps, as they may contain malware or excessive ads; review privacy policies and app reviews.
  4. Fake Toll Collection Texts: Scammers impersonate toll agencies, sending links to fake payment sites—verify through the legitimate service.
  5. Free Gift Cards: Avoid unsolicited emails offering free gift cards; these are usually phishing attempts to steal personal information.
  6. Temporary Holiday Jobs: Watch out for fake job listings aimed at stealing money or personal details.
  7. Impostor Scams: Be careful of fake websites or social media accounts impersonating businesses or customer support.
  8. Fake Charities: Verify charities before donating, especially during the busy holiday season.
  9. Fake Shipping Notifications: Scammers send phishing emails about deliveries, often with links that steal information or download malware.
  10. Advent Calendars: Research sellers of popular advent calendars to avoid unfulfilled orders or counterfeit products.
  11. Holiday Wishlist Items: Be wary of low-priced luxury goods or toys, as they may be knockoffs.
  12. Puppy Scams: Many online pet ads are fake—always meet pets in person before making a purchase.

Exercise caution and verify before making any purchases or donations to avoid falling victim to these scams.

Read More: BBB

UPS issues alert about ‘smishing’ scam Involving text messages.

UPS is warning customers about ‘smishing’ scams during the holiday season, where fraudulent text messages with fake package tracking information are sent to steal personal details. To avoid falling victim, recipients should be cautious of texts with unknown tracking info or clickable links. Real UPS tracking texts include a tracking number, package status, delivery date, time, location, and instructions to stop further messages. UPS texts never contain clickable links, and customers can request updates by texting their tracking number to 28777. For more information, keywords for specific tracking details are available on the UPS website.

Read More: USA Today

Windows malware phishing attacks target YouTube channels.

Cybersecurity firm CloudSek has reported that attackers are impersonating brands to target YouTube channel administrators, sales, and marketing staff with phishing emails. The attackers use automation to gather email addresses of YouTube channels and send bulk emails promising large compensation, up to $50,000 for channels with over 2 million subscribers. These emails contain OneDrive links to password-protected ZIP files, which include malware. The emails ask for financial data under the pretense of sending payment for a sponsored segment.

Once the ZIP file is opened, the malware, an info-stealer, steals browser credentials, cookies, and clipboard data. The file, disguised as “Contracts and Agreement Archive Collection.rar,” loads a process named “webcam.pif” to avoid detection. This malware has been flagged by 48 cybersecurity firms, and programs like Malwarebytes, Avast, or McAfee can detect it.

Read More: PC Mag

Here are some more blogs from this category.
Preventing Credential Stuffing Attacks: A Comprehensive Guide for Businesses

Credential stuffing is a type of cyberattack where threat actors use stolen usernames and passwords from one breach to gain unauthorized access to accounts.

Implementing Single Sign-On (SSO) in Your Business: A Complete Guide

SSO provides convenience and cybersecurity by reducing the number of passwords employees manage, mitigating credential theft, and centralizing access control.

Safe File Sharing Practices for Businesses

Safe file sharing is a critical part of cybersecurity, particularly as businesses rely on cloud storage, collaboration platforms, and remote work arrangements.

Comparing the Security of Google Workspace vs Microsoft 365: A Comprehensive Guide for Businesses

Microsoft 365 and Google Workspace are cloud productivity tools, both offering email, document management, storage, and collaboration tools. Which is better?

User Guide for Handling Email Compromises in Businesses

Learn what an email compromise is, common attack types, recent cybersecurity trends, and proven strategies to prevent and respond to threats.

How to Produce a Data Security Incident Report for Businesses: A Complete Guide

A data security incident report details an event in which sensitive data may have been exposed, modified, or destroyed. A critical component of cybersecurity.

How to Choose the Best Password Managers: A Complete Cybersecurity Guide for Businesses

Password managers are designed to securely store, generate, and manage credentials. They address a vulnerability in cybersecurity: weak and reused passwords.

Cybersecurity Training Checklist for Businesses: A Complete Guide to Building a Human-Centric Defense System

Cybersecurity training extends beyond awareness. Complete cybersecurity includes employees trained to recognize and respond to threats in real-world scenarios.

How to Protect Against Data Breaches: A Complete Cybersecurity Guide for Businesses

Protect your business from data breaches with insights on causes, trends, prevention strategies, tools, and cybersecurity solutions from AlphaKOR.

Best Data Backup Solutions: Complete Business Guide

A complete guide to protection, recovery, and cybersecurity resilience with data backup solutions for businesses. Everything you need to know.