Bitcoin Forum
May 02, 2024, 06:02:23 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: New phishing campaign uses Coinbase email  (Read 204 times)
cryptomaniac_xxx (OP)
Hero Member
*****
Offline Offline

Activity: 1484
Merit: 564



View Profile
October 20, 2020, 07:28:34 AM
Merited by Jating (2), Yaunfitda (2), btc_angela (2), DdmrDdmr (2), Daniel91 (1), Kemarit (1), dkbit98 (1)
 #1

A new report surfaces that cyber threat actors are using Coinbase as an email to install a Office 365 consent app that will give control and access to a victims emails.

(1) the phishing campaign starts when you received a email supposedly coming from Coinbase with there new terms of services. Who wouldn't? Coinbase has been in the limelight lately with their supposedly 'apolitical' stand.



(2) if you click on the link, 'Read and Accept Terms of Service FAQ" you will be redirected to a new site, a legit Microsoft asking you to login

(3) if you login to your Microsoft account you will be prompted to "allow an app from coinbaseterms.app to access their account."

then it will allow access to your,

  • Read your profile (User.read) - Allows users to sign-in to the app, and allows the app to read the profile of signed-in users. It also allows the app to read basic company information of signed-in users.
  • Read your mail (Mail.Read) - Allows the app to read email in user mailboxes.
  • Read and write access to your mail (Mail.ReadWrite) - Allows the app to create, read, update, and delete email in user mailboxes. Does not include permission to send mail.

The full and technical details is here: https://www.bleepingcomputer.com/news/microsoft/coinbase-phishing-hijacks-microsoft-365-accounts-via-oauth-app/

So this criminals are gong to exploit everything, this time a Coinbase email to get access to your own email, it will be damaging if you have some crypto related stuff in your inbox.

.
 airbet 
██
██
██
██
██
██
██
██
██
██
██
██
██
 .

▄████▄▄▄██████▄
███████████████
███████████████
███████▀▀▀▀████
██████████████
▀███▀███████▄██
██████████▄███
██████████████
███████████████
███████████████
██████████████
█████▐████████
██████▀███████▀
▄███████████████▄
████████████████
█░██████████████
████████████████
████████████████
█████████████████
█████████████████
███████░█░███████
████████████████
█████████████████
██████████████░█
████████████████
▀███████████████▀
.
.
.
.
██▄▄▄
████████▄▄
██████▀▀████▄
██████▄░░████▄
██████████████
████████░░▀███▌
░████████▄▄████
██████████████▌
███░░░█████████
█████████░░░██▀
░░░███████████▀
██████░░░██▀
░░▀▀███▀

   
|.
....
██
██
██
██
██
██
██
██
██
██
██
██
██
.
 PLAY NOW 
1714672943
Hero Member
*
Offline Offline

Posts: 1714672943

View Profile Personal Message (Offline)

Ignore
1714672943
Reply with quote  #2

1714672943
Report to moderator
"In a nutshell, the network works like a distributed timestamp server, stamping the first transaction to spend a coin. It takes advantage of the nature of information being easy to spread but hard to stifle." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714672943
Hero Member
*
Offline Offline

Posts: 1714672943

View Profile Personal Message (Offline)

Ignore
1714672943
Reply with quote  #2

1714672943
Report to moderator
Coyster
Legendary
*
Offline Offline

Activity: 2016
Merit: 1236


Cashback 15%


View Profile
October 20, 2020, 03:34:49 PM
 #2

So this criminals are gong to exploit everything, this time a Coinbase email to get access to your own email, it will be damaging if you have some crypto related stuff in your inbox.
Yeah, this phishing is pretty dangerous for users who keep information about their wallet stored in their mail box, or any of their private data/info, the scammers will use it to either compromise their wallets or to ask for a ransome if they get any useful personal data about the person, that's why as a rule of thumb, anything of your crypto stuff that can lead to your wallet imported elsewhere, should either be written down safely somewhere or if saved on a device, it should be offline.

It can't be repeated enough that users should not click on random links, and should always verify from the official website whenever they get a mail that requires then to click on a link attached to it to be sure it's a legitimate update or whatever. Clearing your mail box is also another good practice imo

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Yaunfitda
Hero Member
*****
Offline Offline

Activity: 2842
Merit: 575



View Profile
October 20, 2020, 10:08:43 PM
 #3

^^, Yes and probably more than that,  there could also be some personal stuff hiding somewhere in our email,  Smiley. And you really have to commend it to this criminals, they know that Coinbase as of late has been in the crypto media because Brian Armstrong is very vocal of his company Sixty Coinbase employees take buyout offer after no politics at work rule.

███████████████████████████████
███████████████████████████████
███▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀███████████
█████████████▀▀        ▀▀██████
██████▀▀▀▀▀▀              ▀████
██████████▀     ▄▄██▄▄     ▀███
██████████      ██████      ███
██████████▄     ▀▀██▀▀     ▄███
██████▄▄▄▄▄▄              ▄████
█████████████▄▄        ▄▄██████
███▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████████
███████████████████████████████
███████████████████████████████
.
|
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
SSC NAPOLI
OFFICIAL EUROPEAN
BETTING PARTNER
|.ROLLBOTS.|
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄██▀▀▀▀▀▀▀▀▀▀▀▀▀▀█████▄
▄█████████▀████████▀████▄
██████▄▄▄█████▄▄█████████
█████████████████████████
██████▀▀▀█████▀▀█████████
▀█████████▄████████▄████▀
▀██▄▄▄▄▄▄▄▄▄▄▄▄▄▄█████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
ROLLBIT COIN
TRADE RLB NOW!
|...PLAY NOW...
jossiel
Hero Member
*****
Offline Offline

Activity: 2982
Merit: 632


View Profile
October 20, 2020, 10:39:42 PM
 #4

By checking the email domain of the sender, they are not from Coinbase. I wouldn't click any link that it attaches. A very concise explanation from OP why no one should click links attached from suspicious emails.

Or if somebody accidentally clicks a link, if it's asking for permission or any login, no need to waste your time just close it immediately.

Signature for rent
libert19
Hero Member
*****
Offline Offline

Activity: 2492
Merit: 942



View Profile WWW
October 21, 2020, 04:25:06 AM
 #5

You can just look at the senders email, it looks far from legit.

Edit: ss shows you responded, I'm curious to know what did you respond.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
erep
Hero Member
*****
Offline Offline

Activity: 2282
Merit: 589



View Profile
October 21, 2020, 04:03:36 PM
 #6

One thing is certain that the number of victims of phishing scams is increasing due to inaccuracy in checking the sender address, the keyword "sender address" is to describe the sender's identity so that it can distinguish between official, and scammer e-mail addresses, ignore any incoming messages other than not the official sender address.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
▄▄█▄▄░░▄▄█▄▄░░▄▄█▄▄
███░░░░███░░░░███
░░░░░░░░░░░░░
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░░░░███▄█░░░
░░██▌░░███░▀░░██▌
█░██░░███░░░██
█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀
.
REGIONAL
SPONSOR
███▀██▀███▀█▀▀▀▀██▀▀▀██
██░▀░██░█░███░▀██░███▄█
█▄███▄██▄████▄████▄▄▄██
██▀ ▀███▀▀░▀██▀▀▀██████
███▄███░▄▀██████▀█▀█▀▀█
████▀▀██▄▀█████▄█▀███▄█
███▄▄▄████████▄█▄▀█████
███▀▀▀████████████▄▀███
███▄░▄█▀▀▀██████▀▀▀▄███
███████▄██▄▌████▀▀█████
▀██▄█████▄█▄▄▄██▄████▀
▀▀██████████▄▄███▀▀
▀▀▀▀█▀▀▀▀
.
EUROPEAN
BETTING
PARTNER
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
October 21, 2020, 04:38:02 PM
 #7

A new report surfaces that cyber threat actors are using Coinbase as an email [...]

No, they aren't.

Just look at your own screenshot. The email address is
Code:
contact@shocktech.co.jp

They aren't even trying spoof a coinbase mail address.

This is one of the easy-to-spot phishing mails.

Simakura
Jr. Member
*
Offline Offline

Activity: 56
Merit: 1


View Profile
October 21, 2020, 04:39:15 PM
 #8

Is it possible that Coinbase's emails were fake?
Mandarava
Full Member
***
Offline Offline

Activity: 742
Merit: 103



View Profile
October 21, 2020, 06:53:27 PM
Merited by DdmrDdmr (2)
 #9

I am a little surprised why Coinbase does not use an anti-phishing code, like Binance does. It's so simple. If you receive an email from Binance and see your own anti-phishing code in the first line of this letter, then you are 100 percent sure that this is an authentic email. Why not adopt this simple method? This would save everyone from phishing once and for all.
Taskford
Hero Member
*****
Offline Offline

Activity: 2534
Merit: 786



View Profile
October 22, 2020, 07:50:07 AM
 #10

One thing is certain that the number of victims of phishing scams is increasing due to inaccuracy in checking the sender address, the keyword "sender address" is to describe the sender's identity so that it can distinguish between official, and scammer e-mail addresses, ignore any incoming messages other than not the official sender address.

Unfortunately many users doesn't know about this and coinbase must do a right counteraction regarding on this I think they should create something as @Mandarava said like binance anti phising feature since it could really help the newbies to determine the phising attempts. Also best thing to put on simple short warnings on notifications on the app or site just to make people aware and will not forget the risk about those kinds of attempts.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
▄▄█▄▄░░▄▄█▄▄░░▄▄█▄▄
███░░░░███░░░░███
░░░░░░░░░░░░░
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░░░░███▄█░░░
░░██▌░░███░▀░░██▌
█░██░░███░░░██
█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀
.
REGIONAL
SPONSOR
███▀██▀███▀█▀▀▀▀██▀▀▀██
██░▀░██░█░███░▀██░███▄█
█▄███▄██▄████▄████▄▄▄██
██▀ ▀███▀▀░▀██▀▀▀██████
███▄███░▄▀██████▀█▀█▀▀█
████▀▀██▄▀█████▄█▀███▄█
███▄▄▄████████▄█▄▀█████
███▀▀▀████████████▄▀███
███▄░▄█▀▀▀██████▀▀▀▄███
███████▄██▄▌████▀▀█████
▀██▄█████▄█▄▄▄██▄████▀
▀▀██████████▄▄███▀▀
▀▀▀▀█▀▀▀▀
.
EUROPEAN
BETTING
PARTNER
mich
Legendary
*
Offline Offline

Activity: 3136
Merit: 1032


#1 VIP Crypto Casino


View Profile
October 22, 2020, 11:52:31 AM
 #11

Yes I am all so familiar with these phishing emails from Coinbase. 

I dont even use the exchange but somehow I keep getting floods of emails with suspicious links in them.

If you want to be extra cautious just never open a email from Coinbase unless it is addressed to you personally. 




.
.BITCASINO.. 
.
#1 VIP CRYPTO CASINO

▄██████████████▄
█▄████████████▄▀▄▄▄
█████████████████▄▄▄
█████▄▄▄▄▄▄██████████████▄
███████████████████████████████
████▀█████████████▄▄██████████
██████▀██████████████████████
████████████████▀██████▌████
███████████████▀▀▄█▄▀▀█████▀
███████████████████▀▀█████▀
 ▀▀▀▀▀▀▀██████████████
          ▀▀▀████████
                ▀▀▀███

.
......PLAY......
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
October 22, 2020, 11:56:42 AM
 #12

[...] and coinbase must do a right counteraction regarding on this I think they should create something as @Mandarava said like binance anti phising feature since it could really help the newbies to determine the phising attempts.

And then they receive a phishing mail from another service they are using (e.g. online banking, other exchange, etc..) and they fall for it.
Specific anti-phishing codes are helpful, but people need to learn to spot phishing mails. Even without anti-phishing codes.

Not everyone is using anti-phishing codes. And it most likely won't change anytime soon.


Checking the header and looking at the sending mail address and maybe even at the originating mail server can most often call out those phishing mails.
And if everything seems to be legit but you are still unsure, visit the website directly (not via the URL inside of the mail) and contact the customer service to check whether the mail is legit.

tbct_mt2
Hero Member
*****
Offline Offline

Activity: 2310
Merit: 835


View Profile WWW
October 22, 2020, 01:38:47 PM
 #13

The email in OP is not has a word relates to Coinbase and I feel a deeply regret to anyone who is scammed with that email. It is the official Help page of Coinbase: https://help.coinbase.com/en/contact-us

The page does not list all email addresses from Coinbase for customer support but you can see the hyperlink do has its domain name: coinbase.com. Legit email addresses will do have it too.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!