U.K. Residents are Victims of the Latest Phishing Scam Targeting Starbuck Customer Credentials
Analysis of a new phishing attack highlight just how easy it can be to spot these kinds of attacks if recipients were properly educated.
Action Fraud, the U.K.’s national fraud & cyber reporting center, recently warned U.K. residents of a scam impersonating Starbucks. The email-based scam purports to be from the global coffee brand, telling the recipient they’ve won a “Starbucks Coffee Lovers Box.”
Source: PBS
In reality, it’s a phishing attack designed to take victims to a fake Starbucks landing page intent on getting the victim to enter in their Starbucks customer credentials.
These credentials are then used by scammers to attempt access to other web-based services, online banking, and more – in the hopes that the credential’s owner uses the same email address and password combination.
It’s a simple enough scam to spot – the image above shows just how bogus the actual sender email address is, the email content doesn’t look remotely up to the level of what Starbucks would actually put out, and then there’s the whole “like Starbucks is just going to give me a free gift!” aspect of that. But it does require a vigilant mindset when interacting with email. The need to always assume anything out of the ordinary is “guilty until proven innocent” is something taught via security awareness training that helps instill the sense of vigilance necessary to keep from falling for these scams.
KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.
Will your users respond to phishing emails?
KnowBe4’s Phishing Reply Test (PRT) is a complimentary IT security tool that makes it easy for you to check to see if key users in your organization will reply to a highly targeted phishing attack without clicking on a link. PRT will give you quick insights into how many users will take the bait so you can take action to train your users and better protect your organization from these fraudulent attacks!
Here’s how it works:
- Immediately start your test with your choice of three phishing email reply scenarios
- Spoof a Sender’s name and email address your users know and trust
- Phishes for user replies and returns the results to you within minutes
- Get a PDF emailed to you within 24 hours with the percentage of users that replied
PS: Don’t like to click on redirected buttons? Cut & Paste this link in your browser: https://info.knowbe4.com/phishing-security-test-partner?partnerid=001a000001lWEoJAAW