Security News Mailboxes are currently flooded by password reset, newsletter or account confirmation mails – it's an attack

Gandalf_The_Grey

Level 76
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,601
A German blog reader contacted me this week and reported a worrying observation made by one of his customers. The customer is receiving a flood of requests to reset his passwords, to confirm a newsletter or a now user account. The messages really do come from the services in question. At the moment, it is still somewhat unclear what exactly is behind this. But my suspicion is, that this email flood shall hide a breach of an account.

It's suspected, that attacks on various content management systems (CMS) and websites are made, where password resets are triggered automatically. Or bots created newsletters and new accounts on different services in behalf of a victim. It is possible that something is triggered in brute force attack attempts on these systems in terms of password resets. However, I have a case in mind from 2020 where a PayPal account hack was to be concealed by something like this. Here is, what I know so far.
 

n8chavez

Level 17
Well-known
Feb 26, 2021
818
I have been getting a lot of email, supposedly from pcloud, that says my account was signed into and to verify it was me. However, the from address is not a pcloud address. But it looks identical to one that pcloud has sent before. Be on the look out for things like that too, I guess.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top