• On The Insider: Britney's Bikini-Clad Top 10
May 21, 2008 11:27 AM PDT

Apple iTunes targeted by phishers

by Robert Vamosi

We've seen banks, even eBay and PayPal, all targeted by phishers. Now they've turned their attention to iTunes, creating a bogus site that reportedly looks like an iTunes billing page asking for current credit card information.

"We've never seen Apple as the target," Proofpoint's Andrew Lochart told Computerworld on Tuesday. "It's probably indicative that the bad guys see Apple's online presence as large enough to be a target."

In addition to asking for credit card information, the phony iTunes page also asks for one's social security number and mother's maiden name.

In general, if you receive an e-mail with a link to a site requesting personal financial information, be very cautious about proceeding. Bookmark or type in the URLs for sites containing financial information, such as your bank or e-commerce sites like iTunes. Never link directly from an unsolicited e-mail.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
advertisement
Click here!
Recent posts from Defense in Depth
Window Snyder to leave Mozilla
How to handle ID fraud's youngest victims
Is white listing going mainstream?
How Live OneCare changed the antivirus landscape
Express Scripts clients threatened with extortion
Study: DDoS attacks threaten ISP infrastructure
Security expert talks Russian gangs, botnets
Extortion used in Express Scripts database breach
Add a Comment (Log in or register) (5 Comments)
  • prev
  • 1
  • next
by dadsgravy May 21, 2008 12:51 PM PDT
With all the people switching from windows to mac, this might actually work!
Reply to this comment
by Thomas, David May 21, 2008 5:01 PM PDT
It is good practice to never use a link from an email for any critical information. I've been doing this for years now, and while I understand inexperienced users to fall for these social engineering traps, it should be explained over, and over again. This would literally dry up this type of phishing. Unfortunately, people still fall for it, but I still think it would be great if this was something always told to someone learning to user their email.
Reply to this comment
by Zero187 May 27, 2008 9:22 AM PDT
It really is just common sense, anyone that falls for a phishing scam really doesn't value their money that much if they are so willing to give away their info without looking into it. Darwinism for the net :)
Reply to this comment
by bernie.mcginn May 30, 2008 1:51 PM PDT
great article... thanks!
Reply to this comment
by karen-mobile August 27, 2009 3:03 PM PDT
Super insightful article, makes you think doesn't it.
<option value="http://www.mobilephones.name">karen</option>
Reply to this comment
(5 Comments)
  • prev
  • 1
  • next
advertisement

FAQ: Buying the right Windows 7 upgrade

Readers still have lots of questions on just which version of the software they need to buy in order to upgrade their PC. CNET News tries to offer some answers.

N.Y. lawsuit details Intel's 'largesse' toward Dell

Attorney General Andrew Cuomo's federal antitrust case filed Wednesday alleges a longstanding symbiotic relationship between Intel and Dell.

About Defense in Depth

Covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews of the top security researchers, as well as offering the hands-on, nontechnical advice you'll need to stay safe online.

Add this feed to your online news reader

Defense in Depth topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right