Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Friday, August 2, 2019

How to spot a fake online store in 5 easy steps

One of the most prevalent scams on the internet is fake online stores. If you’re an online shopper, you need to be especially careful. Luckily, you can spot a fake online store if you know what to look for.

In this article, we’re going to over some easy steps to confirm that the site you’re visiting is real — before you click “Buy now.”

Can you tell a fake online store from a real one?

One reason fake websites continue to trick countless numbers of people is because of a cybercrime known as “phishing” or “spoofing.” In this context, it’s when a crook sets up a website that looks identical to a reputable institution.

The damage can seldom be undone if you enter your personal information onto a bogus site. You could have your bank account drained or even have your identity stolen.

It used to be that you could tell a legit website from the “HTTPS,” in the address bar. But research from cybersecurity firm Phishlabs indicates that more than half of phishing sites use HTTPS. The truth, they say, is:

Just because a site has HTTPS doesn’t mean you can trust it unequivocally.

Given the state of internet security, you may be wondering what can an ordinary online shopper do to feel safe before a purchase?

Here are 5 steps to spot a fake online store

1. Scrutinize the URL

How to spot a fake online store in 4 easy steps

Some fraudulent sites have URLS that look just like those of legit websites — at first glance. Before giving any of your personal information like your credit card number, study the URL.

If you used a search engine to get to the site, always look in the address bar to confirm that you are on the correct place.

2. Use a website checker

You can check the legitimacy of any website by using online verification services. Here are two sites that do just that:

Advertisement

  • Go to UrlVoid.com and enter the website’s URL into the bar. After that, you can see all kinds of details about the site. UrlVoid.com generates a threat analysis, a safety report and runs the suspicious website through multiple blacklists to see if any warning signs pop up.
  • Go to Google Transparency Report, which can tell you how safe a website is. Once you’re on the homepage, just click “Site Status” and enter the URL in the search bar.

For a deep dive on site security, explore the Transparency Report’s research on phishing, content delisting and safe browsing.

3. Hover over the address bar

How to spot a fake online store in 4 easy steps

In addition to studying the URL you’ll want to look for a green address bar or padlock. This signifies that the site has been verified.

How to spot a fake online store in 4 easy steps

It’s true, some phishing sites have been able to replicate the padlock icon in the address bar. But clicking the padlock can still tell you some valuable information about a site.

Chrome, Firebox and other major browsers have security checks in place to tell you whether a site can be trusted. Chrome, for example, tells you how many cookies the site has, the status of its certificate and more.

4. Rely on your browser

How to spot a fake online store in 4 easy steps

If you keep your browser updated and have antivirus software on your computer, it should tell you when you’ve run across an unsafe site. Listen to it!

If you see a “Not Secure” warning on your screen, back out of the site or close the page immediately.

5. Look for a trust seal

How to spot a fake online store in 4 easy steps

Advertisement

Trust seals or trust badges aren’t just for decoration. Whether it’s from the Better Business Bureau, PayPal or Google, trust seals are what tell online shoppers and other users that they can make secure transactions.

Here’s the thing: If an e-commerce site doesn’t have a trust seal, be leery of it.

In summary

Hackers and scammers are constantly coming up with ways to trick even the most capable browsers these days.

Using the internet safely involves a focused effort on your part to be aware of phishing sites and other scams. Some other telltale signs that a website may be fake are:

  • Bad grammar
  • No contact page
  • No refund policy

If you run across a fake website or malware, you can report it to the FBI’s Internet Crime Complaint Center, send an email to the Cybersecurity & Infrastructure Security Agency as well as tell these internet companies:

When shopping online, remember to always heed cybersecurity warnings, be smart and be cautious when you sense something isn’t right.

Want to learn more about how to safeguard yourself online? Check out Clark’s Free Virus, Spyware & Malware Protection Guide.

Avoid Google Calendar phishing scams with these 4 steps

A new scam targeting people who use Google Calendar makes them vulnerable to phishing attacks.

Criminals have figured out a way to access your Google Calendar and put phishing links in event invites, according to Kaspersky Labs, an intelligence firm that specializes in internet security.

Google Calendar phishing scam: ‘Scammers making appointments en masse’

“Spammers have recently taken to making appointments en masse,” Kaspersky researchers said in a blog post.

Here’s how the scam works: Users will see details about a fake event in the topic and location fields of Google Calendar. The scammers sometimes use the lure of money to get you to click on the links.

“Usually, their spam details consist of a short bit of text stating that you are entitled to a cash payment for some reason, and a link that supposedly lets you receive it,” the security firm says.

Because Google Calendar is installed on so many devices, this vulnerability is pretty widespread — but you don’t have to be a victim.

The #1 to not get scammed by phishing attacks and protect yourself?

Never click on suspicious links sent to you via email or your calendar.

Google Calendar phishing scam: 4 steps you must take to protect yourself

To fully protect yourself against this phishing scam, you must change your settings so invites from random users won’t show up. Once you follow these four steps, you should only see Google Calendar invites from people in your contact list:

1. From your device, open your Google Calendar and go to Settings. To find it, click on the gear icon in the top right of the page then click Settings.

Avoid the Google calendar phishing scam with these 3 steps

Advertisement

2. Scroll down to “Event Settings,” where you’ll see “Automatically add invitations.”

Avoid the Google calendar phishing scam with these 3 steps

3. Click on “Automatically add invitations” and it will open a collapsible menu. Click “No, only show invitations to which I have responded.” It will automatically save your preference.

Avoid the Google calendar phishing scam with these 3 steps

4. Finally, you’ll want to clear out all those invitations that might be bogus on your Google Calendar.

To do that, go to the vertical menu on the right side of the page and click “View options.” Make sure you uncheck “Show declined events.”

Just like that, you’re protected from the Google Calendar phishing scam.

After making these changes, you will still be able to receive emails with Google Calendar invites, but it will be up to you whether to accept them.

Here are some more scam-related articles from Clark.com: