12 Scams of Christmas, UPS ‘Shmishing’ Scam Alert, and More.

by | Dec 19, 2024 | Blog

This Week In Tech, we talk about the Better Business Bureau's 12 scams of Christmas, UPS smishing scam alert, and Windows malware attack targeting YouTube channels.

12 scams of Christmas.

During the holiday season, it’s important to watch out for scams targeting shoppers and donors. Here are key types to watch for:

  1. Misleading Social Media Ads: Research before buying, as many items advertised on social media are either fake or not as described.
  2. Social Media Gift Exchanges: These scams involve pyramid schemes where personal information is shared, and gifts or money are sent to strangers.
  3. Holiday Apps: Be cautious of free apps, as they may contain malware or excessive ads; review privacy policies and app reviews.
  4. Fake Toll Collection Texts: Scammers impersonate toll agencies, sending links to fake payment sites—verify through the legitimate service.
  5. Free Gift Cards: Avoid unsolicited emails offering free gift cards; these are usually phishing attempts to steal personal information.
  6. Temporary Holiday Jobs: Watch out for fake job listings aimed at stealing money or personal details.
  7. Impostor Scams: Be careful of fake websites or social media accounts impersonating businesses or customer support.
  8. Fake Charities: Verify charities before donating, especially during the busy holiday season.
  9. Fake Shipping Notifications: Scammers send phishing emails about deliveries, often with links that steal information or download malware.
  10. Advent Calendars: Research sellers of popular advent calendars to avoid unfulfilled orders or counterfeit products.
  11. Holiday Wishlist Items: Be wary of low-priced luxury goods or toys, as they may be knockoffs.
  12. Puppy Scams: Many online pet ads are fake—always meet pets in person before making a purchase.

Exercise caution and verify before making any purchases or donations to avoid falling victim to these scams.

Read More: BBB

UPS issues alert about ‘smishing’ scam Involving text messages.

UPS is warning customers about ‘smishing’ scams during the holiday season, where fraudulent text messages with fake package tracking information are sent to steal personal details. To avoid falling victim, recipients should be cautious of texts with unknown tracking info or clickable links. Real UPS tracking texts include a tracking number, package status, delivery date, time, location, and instructions to stop further messages. UPS texts never contain clickable links, and customers can request updates by texting their tracking number to 28777. For more information, keywords for specific tracking details are available on the UPS website.

Read More: USA Today

Windows malware phishing attacks target YouTube channels.

Cybersecurity firm CloudSek has reported that attackers are impersonating brands to target YouTube channel administrators, sales, and marketing staff with phishing emails. The attackers use automation to gather email addresses of YouTube channels and send bulk emails promising large compensation, up to $50,000 for channels with over 2 million subscribers. These emails contain OneDrive links to password-protected ZIP files, which include malware. The emails ask for financial data under the pretense of sending payment for a sponsored segment.

Once the ZIP file is opened, the malware, an info-stealer, steals browser credentials, cookies, and clipboard data. The file, disguised as “Contracts and Agreement Archive Collection.rar,” loads a process named “webcam.pif” to avoid detection. This malware has been flagged by 48 cybersecurity firms, and programs like Malwarebytes, Avast, or McAfee can detect it.

Read More: PC Mag

Here are some more blogs from this category.
Best Data Backup Solutions: Complete Business Guide

A complete guide to protection, recovery, and cybersecurity resilience with data backup solutions for businesses. Everything you need to know.

Business Guide to Securing Your Microsoft 365 Environment

Secure your business’ Microsoft 365 environment from cyber-threats. Learn about risks, common attacks, and best practices to secure your business, here.

Ransomware and Your Business: What You Need to Know

Explore the impact of ransomware on businesses, key trends, and effective strategies for prevention, and protection in today’s cybersecurity landscape.

Protecting Your Business from Phishing

Explore phishing risks, trends, and protection strategies to safeguard businesses from evolving cyber threats and financial loss.

Windsor Tech Companies: Building the Future of Business Today

Discover how Windsor tech companies are driving business growth and innovation, shaping a dynamic future for the region’s thriving business landscape.

How Top Tech Companies in London, ON Build Resilient IT Without Slowing Innovation

Understanding tech companies in London is essential for business leaders who want to remain competitive in today’s landscape…

Benefits of IT Outsourcing to Grow and Protect Your Business

You are likely aware that IT outsourcing is no longer a secondary consideration—it has become a primary lever for organizations intent on achieving re…

How Managed Services vs Professional Services Shape Your IT Success

Organizations are under increasing pressure to manage risk, control costs, and maintain agility, prompting careful consideration of how they source IT…

Navigating Change: How Windsor industries Thrive Amid Global Shifts

You understand that Windsor industries are at a pivotal crossroads—where local expertise meets global opportunity. For business leaders and decision-m…

Staff Augmentation vs Managed Services: Two Outsourcing Paths, One Strategic Decision

Choosing between staff augmentation and managed services is a decision that will ripple through every layer of your organization, impacting flexibilit…