We have relaunched: What's new at ZDNet Asia?

Fraudsters target Apple .Mac customers

Summary

Phishers apparently take advantage of the difficulties that occurred when Apple transitioned users from .Mac to Mobile Me service last month.

Events

Microsoft MSDN/Developer Event
25 Mar 2010

One Marina Boulevard, Microsoft Singapore

IT Architect Regional Conference Singapore 2010
20 - 21 Apr 2010

Singapore Management University, Singapore

The Internet Show 2010
21-22 Apr 2010

Suntec Singapore

When Apple rolled out its Mobile Me service last month, it provided phishers with a golden opportunity to scam users of .Mac, according to a credit card protection service.

"We confirmed this," said Dan Clements, vice president at Affinion Group, the company that owns Card Cops. "We called some of the .Mac users" found on a trading site used by the Internet underground.

Card Cops includes among its customers major banks worldwide. For the last eight years, the group has been helping its clients and law enforcement track down those who are trading personal information online.

Clements said his company routinely examines caches of "full profiles", meaning the files contained the social security numbers, birth dates, mothers' maiden names, and credit card numbers from customers of savvy users that were tricked. He said one day there was a "disproportionate amount of what we usually see" of victims using the .Mac e-mail address.

Of the 300 profiles provided to CNET News, more than 100 had .mac addresses.

"The attack looked very realistic; the graphics were well done," said Clements, and this snared some sophisticated victims, he said. Some had businesses accounts with Apple "because their mother's maiden name was already on file".

One version of the e-mail solicitation included links to help set up your desktop, PC, iPhone, or iPod Touch. It also stated that Apple was "unable to process your most recent payment," and to "please update your billing information today" so your service is not interrupted. Victims then entered their personal information on a site that appeared to be hosted by Apple, but was actually overseas.

The .Mac phishing attack coincided with Apple's rollout of its Mobile Me service in early July. MobileMe lets Apple customers synchronize mail, calendars, contacts, photos, Safari bookmarks, Dashboard widgets, and more among Macs, the iPhone, and iPod Touch. However, all was not perfect; MobileMe experience too many glitches in the first few weeks of operation.

Clements agreed that Apple was also a victim here, but commented that the company might have been "more preemptive by saying what Apple was going to do" with the e-mail and also warn users to be careful of phishing attacks.

Apple did not provide a comment for this story at press time.

This article was first published as a blog on CNET News.com.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment
Transform your business interactions with real-time voice, video and telepresence solutions.
Tech Vendor: Cisco

ZDNet Asia Live

there are couples who would prefer a small family, there are also couples that would prefer medium size families however, there are also ...

30 minutes ago by masoncrumac on Philippine antipiracy drive focuses on enterprises

We have no plans to attack anyone. But we consider it necessary for all our partners in the world community to clearly understand that to...

33 minutes ago by masoncrumac on ZDNet Asia goes global on local

We have no plans to attack anyone. But we consider it necessary for all our partners in the world community to clearly understand that to...

33 minutes ago by masoncrumac on ZDNet Asia goes global on local

ZDNet Asia features IBM collaboration roadmap story from LCTY Singapore - http://bit.ly/9CuSbZ #lotusknows

50 minutes ago by lotusknows on topsy

Internet Jobs in Malaysia - ZDNet Asia http://bit.ly/d0o8Ce

1 hour 33 minutes ago by jamesmt39 on topsy

BTW blog by Eileen Yu: ZDNet Asia goes global on local. http://tinyurl.com/yd554ql

2 hours 40 minutes ago by zdnetasia on topsy

HEADLINE: IT Management - IT Infrastructure - Service Level Management ... - http://bit.ly/bW1rqY

3 hours 22 minutes ago by itilpedia on topsy

RT @charlesmok: Caller ID spoofing more damaging than e-mail http://ping.fm/0D77z

4 hours 12 minutes ago by makechoice on topsy

[TECH] URL Shorteners slow Web redirection. - http://bit.ly/bySnWK @zdnetasia

URL shorteners are great but they can slow web redirection & you pray it would never go down http://bit.ly/bySnWK via @zdnetasia

Temasek Holdings eyeing tech stocks, indicating optimistic outlook on IT sector. http://bit.ly/aM7VwU

URL shorteners slow Web redirection. http://bit.ly/bySnWK

Chinese agencies cry foul over Google. http://bit.ly/by6rwV

Philippine antipiracy drive focuses on enterprises. http://bit.ly/aWryDC

Gartner: China to become world's fastest-growing enterprise software market. http://bit.ly/bqJTtb

all of sg's isps have been practising compulsory invisible proxy for all home subscribers at their backend since many years back alre...

1 day 51 minutes ago by melvinchia on Web filters mean bad news for business

it is not to good for china.
Proactol

1 day 36 minutes ago by nathonastle on Chinese ad partners beg Google for information

RT @zdnetasia: HP touts new products and management and productivity tools to address business computing pain points. http://bit.ly/dudgA6

For those with a computer science background, or interested in the high performance computing scene: http://bit.ly/9vFC3i

HP touts new products and management and productivity tools to address business computing pain points. http://bit.ly/dudgA6

** S'pore govt launches traffic Web app. http://www.zdnetasia.com/s-pore-...

the new look site is very nice @zdnetasia @zdnetaustralia

Big up to my peeps at www.ZDNet.com.au (and www.ZDNetasia.com and www.ZDNet.com.uk). Loving the redesign!

McAfee steps up cloud assurance - Zd Net Asia.com
http://www.zdnetasia.com/mcafee-...

Interesting take on social analystics. http://www.zdnetasia.com/blogs/w...

Very good explanation of JMX

2 days 41 minutes ago by Babith B on Managing applications with JMX

The reaction to a report issued Tuesday by Flurry Analytics managed to completely overlook some interesting news--the Android-based Motorola Droid outsold the original iPhone over the same period of time following their respective launches--to focus instead on the sales numbers for the Nexus One.

2 days 45 minutes ago by lonemavericks on diggs

Another ZTE story....

2 days 47 minutes ago by Moderate Your Greed on Philippines opens bid for final 3G license

We at www.fifosys.com have also seen a growth in IT outsourcing and anticipate it as a growing field.

2 days 20 minutes ago by sarah Jane on Companies' outsourcing spend to increase

I agree with you. The iSiVaL is super portable and TVs can't expand their image size. I recorded a video that might bring some ideas to...

2 days 51 minutes ago by Jesse B Andersen on Buying a projector? Try an LED TV instead

hermm... he deserved it.. he shud not talk abt sensitive things like tat, well, he shud think twice before saying all those things, event...

2 days 29 minutes ago by ... on Facebook user charged in Malaysia

Password manager tools are potential security threat. Criminals who hack into the computer can use the password manager to log onto any s...

3 days 29 minutes ago by ohanae on What defaults should random password generators use?

I've found the cross platform utility unetbootin to be rather handy for this kind of thing as well.

3 days 3 minutes ago by Jim on Use Live USB Creator to install Fedora 12 from a USB stick

Thanks for the article. I think the debug command has an "\" after "C:" it should say w32tm /debug /enable /file:C:\l...

3 days 3 minutes ago by Roger Biefer on Manage time accuracy with W32Tm

available in singapore now
http://www.portablemall.com.sg/goods-71-Microsoft+Zune+HD+32GB+-+Platinum.html

3 days 40 minutes ago by steve on Microsoft coy on apps for Zune HD

How about just using http://www.random.org/strings/? It is very configurable, satisfies all of the flexibility requirements you have ment...

3 days 46 minutes ago by Varun V Nair on What defaults should random password generators use?