This will be a quick post. We have received a phishing mail to our info@lemmy.world mail address telling that they are “lemmy.world Security Team”, telling that they will “disconnect” your account from our instance. This is ofc, not us. Do not fall for it! The attached image is how the mail looks like.

~Lemmy World Team.

  • TheGoldenGod@lemmy.world
    link
    fedilink
    arrow-up
    72
    ·
    1 year ago

    Jesus. Phishing emails like this have become so commonplace I actually miss the old Viagra spam emails in l33tspeak.

  • Annoyed_🦀 @monyet.cc
    link
    fedilink
    arrow-up
    57
    arrow-down
    2
    ·
    1 year ago

    How do you guys know it’s not you guys?

    Joke aside, i wonder why they wanna phish for user account in lemmy? Unlike the exploit like a few months ago that specifically target admin, this one seems like it target anyone, it so random.

  • Flying Squid@lemmy.world
    link
    fedilink
    arrow-up
    48
    ·
    1 year ago

    I got an almost believable phishing text yesterday from a ‘collection agency’ that wanted me to download a PDF and go to their website. It looked very official and I’m having some debt issues, but it didn’t tell me who it was representing or what I owed or anything like that, so I could tell it was phishing. But a less-savvy person could have totally been fooled by it because it looked very real.

    • henfredemars@infosec.pub
      link
      fedilink
      English
      arrow-up
      17
      ·
      1 year ago

      I got a spam message that was surprisingly well written until I realized wait a minute, if this is true, why do you need me to tell you who I am?

    • SnipingNinja@slrpnk.net
      link
      fedilink
      arrow-up
      15
      ·
      1 year ago

      It’s especially bad if you are half asleep and panic click on something, especially with session hijacking

  • dependencyInjection@sh.itjust.works
    link
    fedilink
    arrow-up
    39
    arrow-down
    1
    ·
    1 year ago

    Isn’t it a waste of time trying these scams on lemmy.

    I could be wrong here but I would argue the vast majority of users are somewhat tech proficient since it’s not reached mass adoption and the user base is well, just us nerds?

    • Bitrot@lemmy.sdf.org
      link
      fedilink
      English
      arrow-up
      27
      ·
      1 year ago

      Tech folks still fall for phishing. It takes a momentary lapse, failure to caffeinate, it happens.

      Lemmy is currently full of newly registered domains with weird suffixes, the kind that traditionally have been a phishing indicator. Lemmy.world is going to be harder to phish than some of the other ones where you have to read closely.

    • SgtAStrawberry@lemmy.world
      link
      fedilink
      arrow-up
      19
      ·
      1 year ago

      Well one of the best scam hunters on YouTube lost his account to a scam. So not really a waste of time, trying Lemmy.

      • Hazzia@discuss.tchncs.de
        link
        fedilink
        arrow-up
        5
        ·
        edit-2
        1 year ago

        There’s also variable levels of sophistication for scam messages based on the desired target. If you’re looking for a whole lot of people who don’t understand technology enough to see through your premise, you go with the generic “hello sir and/or madame I am hackor send gift cards or I will delet ur phone”.

        If you’re after a very specific person who is well known to be privy to the normal red flags, you’re more likely to create a custom spear phishing campaign and mimic as closely as possible the format, lexicon, domain names, etc of something reputable to avoid setting off their BS detectors.

        With that said, yeah there’s enough people on lemmy that this low-effort take is worth a shot

  • NOT_RICK@lemmy.world
    link
    fedilink
    English
    arrow-up
    37
    ·
    1 year ago

    Hello, it is I, John Security. Please respond to this message with your name and SSN or the FBI will arrest you for unpaid back taxes. Also, do you have any iTunes or Google play gift cards laying around?

  • Clbull@lemmy.world
    link
    fedilink
    arrow-up
    38
    arrow-down
    3
    ·
    1 year ago

    Why would they target Lemmy users?

    Your typical Lemming (for lack of a better term) is not technologically inept and would generally not fall for a phishing scam. They’d earn a lot more money from targeting Redditors.

    • I study cybersecurity. Technically inept or not, people in IT fall for phishing all the dam time.

      What I imagine is that they look at popular domains (in this case “lemmy.world”), turn that into a fake app name (“My Lemmy World”) and set up some kind of generic link somewhere. When you do that for enough domains, they’ll strike gold eventually.

      You’re not always at 100% concentration. At some point you’re going to get an email late at night after you’ve had a few shots, or after you’ve woke up from a terrible sleep, or your baby has been waking you up every four hours and your boss is threatening to fire you if you don’t get yourself together, and you’ll make a dumb mistake.

      Sure, most IT people don’t fall for the “this is the company’s password inspector please list all your passwords so I can check if they’re safe” level of scams, but phishing people is remarkably easy if you do it at scale. You send out a million email and less than one percent needs to fall for your scam for your attack to work.

      What’s worse is that because of all of that knowledge, IT people tend to think they’re too smart to get scammed. That’s incredibly useful for scammers, because that means those people will justify their mistakes for longer when they do eventually fall for something like this. Plus, they’re less likely to get help, because their peers who are also Very Smart will probably make fun of them for falling victim of a scam like this. Plus, if you work in IT, you probably make a nice chunk of money, and maybe have some cryptocurrency on your super secure local wallet that an app with the right exploits can steal.

      Emails are practically free and they only need a few mistakes to make a profit. Targeting IT professionals doesn’t increase your probability of success like targeting the elderly does, but it’s still a risk/reward situation that can make you money once you’ve set up your preexisting scam automation.

    • Stalinwolf@lemmy.ca
      link
      fedilink
      arrow-up
      9
      arrow-down
      4
      ·
      edit-2
      1 year ago

      Attention! u/spez demands that you suckle upon his prostate like a thirsty little pig!

      “OMG guys, ^ THIS!”

  • dreadedsemi@lemmy.world
    link
    fedilink
    arrow-up
    29
    arrow-down
    1
    ·
    1 year ago

    It’s weird that they target Lemmy, what would they get? Access to account that shitposts? Only important accounts are admin, even communities are small here

    • Dave@lemmy.nz
      link
      fedilink
      arrow-up
      30
      ·
      1 year ago

      My guess is they did not. It doesn’t appear to be targeting Lemmy, it’s just a generic spam email.

      Note the email was received at the info@lemmy.world address. The email most likely got the info@lemmy.world email address, took the domain from it, lemmy.world, and put this in their spam generator. The email doesn’t even make sense, because it says they need to install an app for their mail but it’s a custom domain.

      If you imagine most of the emails on their spam list are @gmail.com or @outlook.com, etc, then the email looks like it is coming from the gmail.com security team or the outlook.com security team. The email no longer makes sense when you have a custom domain.

    • Kayn@dormi.zone
      link
      fedilink
      arrow-up
      22
      arrow-down
      1
      ·
      1 year ago

      It’s not targeted at Lemmy. This phishing mail simply assumes that lemmy.world is an email provider, and that info@lemmy.world is a registered email account there.

  • Obinice@lemmy.world
    link
    fedilink
    arrow-up
    21
    ·
    1 year ago

    Why are these sorts of things always written by somebody who can clearly barely speak English?

    • bananabenana@lemmy.world
      link
      fedilink
      arrow-up
      46
      ·
      1 year ago

      I read that this was to weed out savvy people. People who aren’t skeptical of poorly written emails or messages are their target audience. Could be wrong though.

      • Chariotwheel@kbin.social
        link
        fedilink
        arrow-up
        15
        ·
        1 year ago

        Yes, exactly this. You want people who can’t see behind the simple facade. Because they are more likely to be easily fooled. You don’t want to work someone who is very sceptical or just moderately sceptical. In that time you could work through a bunch of people that can’t see behind this and pull out money from them.

        Scammers want easy marks. Why wouldn’t someone make it easier for themselves by naturally filtering out people that can’t be easily fooled?

      • Echo Dot@feddit.uk
        link
        fedilink
        arrow-up
        13
        arrow-down
        1
        ·
        1 year ago

        I’m sure that’s some of it, but also I think a lot of it is this is the kind of crap you do get if you run Chinese through Google translate and just copy paste the output.

        It’s almost fine but then it falls apart and doesn’t really make sense.

    • Koen967@feddit.nl
      link
      fedilink
      arrow-up
      16
      ·
      1 year ago

      What is unclear? All you have to do is resolve the Lemmy world app on Android and install the errors on your iPhone mail.

      • Echo Dot@feddit.uk
        link
        fedilink
        arrow-up
        9
        ·
        1 year ago

        Yeah I’m not actually quite sure I understand what the issue they are pretending is.

  • slazer2au@lemmy.world
    link
    fedilink
    arrow-up
    15
    ·
    1 year ago

    Do you have plans to enable DMARC, DKIM, and SPF to make the emais more likely to be flagged as spam by email filters?

  • cole@lemdro.id
    link
    fedilink
    English
    arrow-up
    11
    ·
    1 year ago

    I’ve gotten an email like this before for lemdro.id. I think it’s a generic phishing email since the community links look like email addresses (and actually often are)

  • nodimetotie@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    ·
    1 year ago

    I wonder what they thought of when they wrote “Security Team.” I just think of security guards.

  • jordanlund@lemmy.world
    link
    fedilink
    arrow-up
    3
    ·
    1 year ago

    I’d love to see what domain the “resolve issue now” link points to… Somehow I doubt it’s lemmy.world. :)

    Thanks for sharing!