UPS phishing email wants your shipping credentials

Filed Under: Phishing, Spam

Do you ship packages via UPS? Do you have an account to track packages and authorize shipments? If so you should be on the lookout for a new phishing spam making the rounds.

The email comes from an account that appears to be "UPS Communication" with the subject of "Important Update". The email reads:

"Please note that we have made new and important changes to your account.

Login to view new updates. MY UPS

© 2011 United Parcel Service of America, Inc. UPS, the UPS brandmark, and the color brown are trademarks of United Parcel Service of America, Inc. All Rights Reserved."

UPS phishing campaign

The link MY UPS leads to a compromised website in the Seychelles. It appears the attackers have exploited a vulnerability in the Joomla CMS installed on the host.

The webpage is actually a screenshot of the real My UPS website with the form fields for login inserted in the correct location.

UPS phishing page

Sophos Web Security customers are protected against this scam as well as users of Google Chrome, Firefox and Safari through the Google Safe Browsing service.

It appears the Internet Explorer phishing filter is not yet detecting this page as a phishing site.

It is unlikely the phishers are really trying to access your UPS account, but rather are counting on the fact that most users reuse their usernames and passwords for multiple sites.

As usual the best defense is to never click a link in an email. If you think you are receiving a communication from an organization you do business with, do the safe thing and open your browser and type in their address directly into the location bar.

Update: It has come to my attention that money laundering schemes known as "reshipping" may wish to use purloined UPS accounts as a part of their scams. Brian Krebs has posted a post detailing this process called "Shady Reshipping Centers Exposed, Part I".

, ,

You might like

3 Responses to UPS phishing email wants your shipping credentials

  1. Mike P · 926 days ago

    Of course, the dead giveaway is the use of the Comic Sans (a/k/a "Winnie the Pooh) font for the "Login or Register" text.

    But seriously, people-have we, as a species, become so gullible as to fall for these phishing schemes? Apparently so...

    I'd never thought I'd have to say this, but, the average human today is making Forrest Gump look like Albert Einstein more and more every day...

  2. GREGT · 925 days ago

    it would be nice to know what the website url is so I can block it in our company firewall.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

About the author

Chester Wisniewski is a Senior Security Advisor at Sophos Canada. He provides advice and insight into the latest threats for security and IT professionals with the goal of providing clear guidance on complex topics. You can follow Chester on Twitter as @chetwisniewski, on App.net as Chester, Chester Wisniewski on Google Plus or send him an email at chesterw@sophos.com.