Skip to content

Scam: fake 'server migration' phishing got my credentials

General Discussion by wendy 25 replies 3.9K views
#21

I have been in this since BBS days and I will tell you what I tell every client: the weakest link is always the human. You can have perfect DKIM, perfect SPF, perfect backups, and someone will still click because the email came at 9 AM on a Monday when they are rushing.

In São Paulo I see this targeting local bank customers more than hosting, but the psychology is identical. Urgency, authority, fear of loss. The only defense is slow down and verify through another channel.

5 #22

I am in Montreal and I run a small MSP. I have forwarded this thread to my clients. The Vultr angle is especially relevant because so many of them use it for VPN exit nodes. I am also checking: does anyone know if Contabo's Canadian presence is actually coming? I heard rumors of Toronto but I see nothing on their site.

#23
lukapath said:
Contabo's Canadian presence

I have not heard anything and I would be surprised. Their expansion has been Asia-Pacific and US first. London was the most recent European addition and that was already a year ago. If you need Canadian data residency now, OVHcloud Beauharnois or Vultr Toronto are your realistic options in this price bracket.

Have you tried restarting it?
#24

I am in Paris and I use OVHcloud for my personal projects. The phishing email I received was slightly different: it claimed to be from "OVHcloud Network Operations" and asked me to confirm my NIC handle password. The real OVHcloud panel calls it a password, not the NIC handle specifically. Small clue.

I have 2FA and I did not click. But I am tired of this. We need providers to implement proper BIMI or at least consistent branded headers. The inconsistency trains users to accept anything that looks roughly right.

4 #25

Did anyone else notice the phishing sites are using BunnyCDN for assets? I saw that in the source when I inspected one safely. Not blaming Bunny, anyone can sign up, but it means the images load fast and look legitimate. That is a relatively new trick. Usually these kits hotlink directly and break when the real site changes paths.

#26
NailIce3 said:
BunnyCDN

Good catch. That explains why the pages loaded so fast for my client too. I assumed it was just Cloudflare caching but Bunny makes more sense for a disposable domain. The kit is evolving.

To the person asking about Authy: it is fine but the backup is tied to your phone number. I prefer Aegis on Android or TOTP built into my password manager. The important thing is not the app, it is having the seeds exportable so you are not locked in.

Also to steven_dzire: check if your photography blog had any newsletter subscribers or commenter emails exported. The attackers often grab databases for resale even if they do not use them immediately. I would notify anyone whose data you held. GDPR or not, it is the right thing.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft