September 23, 2009 12:13 PM PDT

Twitter phishing scam spreads via direct messages

by Elinor Mills
  • Font size
  • Print
  • 6 comments

A new phishing scam is spreading through Twitter via direct messages, according to several reports.

Itamar Kestenbaum writes on his JewNews.net blog that he received a direct message on his Twitter account from someone he didn't know that said "rofl this you on here?" followed by a link to what appeared to be a video-related Twitter page.

The page looks like a legitimate Twitter log-in page but nabs your credentials if you type in your password, he warns.

Meanwhile, a posting on the Mashable blog said the site had received multiple reports of the new phishing scam and that someone there had even received one of the phishing-related direct messages themselves.

No word on this yet on Twitter's official blog or from a Twitter spokesperson. We'll keep you posted as we hear more.

In the meantime, if you clicked on the phishing link and typed in your credentials, you should change your password immediately.

Update at 5:30 p.m. PDT: Twitter acknowledged the phishing scam in a tweet on Wednesday that said "A bit o'phishing going on--if you get a weird direct message, don't click on it and certainly don't give your login creds!"

JewNews.net captured this screenshot of the phishing-related direct message Twitter users are receiving and the fake log in page the link directs to.

(Credit: JewNews.net)

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
Recent posts from InSecurity Complex
Web-based Lookout protects mobile devices, data
Using Facebook and Twitter safely
Firefox, Adobe top buggiest-software list
Adobe to patch zero-day Reader, Acrobat hole
Keeping Uncle Sam from spying on citizens
Facebook sues men for allegedly phishing, spamming
Scammers exploit Google Doodle to spread malware
Symantec confirms zero-day Acrobat, Reader attack
Add a Comment (Log in or register) (6 Comments)
  • prev
  • 1
  • next
by n3td3v September 23, 2009 12:52 PM PDT
Thankfully I don't use direct messages I tell people to email me stuff instead.
Reply to this comment
by mikeburek September 25, 2009 12:55 AM PDT
Right.... Because phishing scams can't happen over email....
by snafu_08 September 24, 2009 7:57 AM PDT
Ditto ...
Reply to this comment
by setjeff15081947 September 24, 2009 5:05 PM PDT
Twitter? Bah! Humbug, I say ? Humbug!
Tweet ?Tweet!
Reply to this comment
by Harrison912 September 28, 2009 1:50 PM PDT
I typically use Twitter to market my safety and security web site so I'm always interested in anything going on like this there. Thanks, Elinor.
Reply to this comment
by Zakynthos September 28, 2009 6:41 PM PDT
Very interesting. As Twitter becomes more popular over time, these sorts of security breaches will occur more often.
Reply to this comment
(6 Comments)
  • prev
  • 1
  • next
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About InSecurity Complex

Elinor Mills became fascinated with hacker culture when she was sent to Las Vegas to cover DefCon in 1995. Since then, script kiddies have given way to cyber criminals targeting bank passwords, and privacy risks are everywhere, from Google to Facebook and the iPhone. InSecurity Complex keeps tabs on the flaws, the foibles, and the fixes.

Add this feed to your online news reader

InSecurity Complex topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right