Hackers target Three customers with "sophisticated" phishing scam

Cyber criminals use elements from Three’s style and links out to its website

Three UK

Cyber criminals are posing as UK mobile network operator Three as part of a sophisticated phishing campaign designed to extract the financial details of its customers.

Related Resource

Cyber security for accountants

3 ways to protect yourself and your clients online

Download now

The attack relies on a well-spoofed HTML document that entices Three customers to hand over everything from their password and personal details to credit card and payment information. 

Advertisement - Article continues below

The opportunistic phishing attack campaign, spotted by the Cofense Phishing Defence Centre, appears to be exploiting a sudden rise in demand for data services amid the global coronavirus pandemic. 

The volume of cyber crime exploiting the confusion and economic uncertainty around the crisis has generally increased, with attacks targeting businesses, hospitals and even the World Health Organisation (WHO).

Users are first informed of a bill payment that couldn’t be processed by their bank before they’re invited to download the HTML file ‘3GUK[.]html’ to edit billing information to avoid service disruption.

The attached file then requests login credentials, along with personal and payment information. Alarmingly, the file has cloned actual Three HTML code, and has pulled styling elements from the Three website to appear genuine.

The ‘smoking gun’, according to the researchers, lies in the action attribute of the HTML form element, confirming that any information provided is processed by the ‘processing.php’ script found at a compromised third-party web domain.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

The metadata examined by Cofense suggests the email address ‘online@three[.]co[.]uk’ is the apparent source, though on closer inspection it appears far from legitimate. 

“The SPF check shows this was the address provided in the SMTP MAIL FROM command,” the researchers said. “We also see a SoftFail result for the originating IP 86.47.56.231; this means the domain of three.co.uk discourages, but does not explicitly rule out, this IP address as a permitted sender.”

“In other words, the SPF records for the domain of three[.]co[.]uk contain the ~all mechanism, which flags but ultimately lets the email through. 

The phishing campaign is the latest in a string of opportunistic attacks that tend to exploit the zeitgeist. In this instance, Vodafone revealed last week that demand for its data services has surged by at least 50%, an increase likely also seen by its competitors. 

Featured Resources

Top 5 challenges of migrating applications to the cloud

Explore how VMware Cloud on AWS helps to address common cloud migration challenges

Download now

3 reasons why now is the time to rethink your network

Changing requirements call for new solutions

Download now

All-flash buyer’s guide

Tips for evaluating Solid-State Arrays

Download now

Enabling enterprise machine and deep learning with intelligent storage

The power of AI can only be realised through efficient and performant delivery of data

Download now
Advertisement

Most Popular

Visit/security/cyber-crime/355171/fbi-warns-of-zoom-bombing-hackers-amidst-coronavirus-usage-spike
cyber crime

FBI warns of ‘Zoom-bombing’ hackers amid coronavirus usage spike

31 Mar 2020
Visit/security/data-breaches/355173/marriott-hit-by-data-breach-exposing-personal-data-of-52-million
data breaches

Marriott data breach exposes personal data of 5.2 million guests

31 Mar 2020
Visit/development/application-programming-interface-api/355192/apple-buys-dark-sky-weather-app-and-leaves
application programming interface (API)

Apple buys Dark Sky weather app and leaves Android users in the cold

1 Apr 2020
Visit/data-insights/data-management/355170/oracle-cloud-courses-are-free-during-coronavirus-lockdown
data management

Oracle cloud courses are free during coronavirus lockdown

31 Mar 2020