NOW READ THIS
("Security Advisory")



Submitted by: Bill Hickey
NCVA List Master

NRT-0050 Better Business Bureau Phishing Scam:


The BBB agency has issued a statement on its web site, warning people of a spoofing scam that is using the agency's name and a false email address to lure users to click on links and connect with malicious web sites. A computer system in a Kennesaw, GA business was compromised late on 12FEB, the agency said. The compromised computers were then used to generate thousands of counterfeit messages, claiming to be a complaint filed with the agency.

The email has a phony return address of operations(at)bbb.org and a hyperlink citing a BBB complaint case number. The agency provided "DOCUMENTS FOR CASE #263621205" as an example. The links actually direct access to a subdirectory of the hacked firm's web site where users are asked to download documents related to the complaint. The download, however, is actually an executable file that is believed to be some form of a computer virus, according to the agency's release.

(http://www.informationweek.com 14FEB07)



Last Modified: Sunday, 18-Feb-2007 08:40:36 EST