Edens.nl: het laatste nieuws het eerst!

🔒
❌ About FreshRSS
There are new articles available, click to refresh the page.
Before yesterdayMain stream

Scammers Are Impersonating Spotify to Steal Your Credit Card Info

28 July 2026 at 17:00

Scammers love to impersonate trusted brands—ranging from big tech names like Microsoft and Google to password managers and payment apps—in their phishing campaigns to lure their marks, and their latest guise is Spotify. A new email is circulating alerting users to supposed payment issues, prompting them to hand over their credit card details and Spotify login credentials.

Phishing emails use Spotify branding

As The Guardian reports, Spotify users have received messages with the subject line "review billing info" claiming that the platform "encountered an issue while processing your recent payment." Recipients are urged to "review and update" their information to keep their accounts active. The button in the email directs users to a spoofed website, where users are prompted to enter their username and password, followed by their credit card number, address, and phone number—everything scammers need to make fraudulent purchases. One victim reported seeing a suspicious charge for more than $600 within minutes of handing over their information.

The emails closely replicate Spotify's branding, including its colors and logo, and appear to come from a sender called MySpotify. The fraudulent website also looks convincing at first glance. However, unlike some of the more sophisticated phishing schemes that exploit vulnerabilities in order to use real domains (like Google and PayPal), this one from Spotify breaks down when you look closer.

For one, both the sender's address and the website URL clearly are not connected to spotify.com or any legitimate subdomain. The subject line is all lowercase, and there are no specifics about users' subscriptions or accounts in the email body.

How to avoid getting scammed by Spotify impersonators

Payment issues are a common scam tactic, and you should always be skeptical of any communication that urges you to provide or update banking or credit card info (or sends you to a login page along the way, which is designed to harvest your credentials). If you receive a notification from Spotify about failed payments, don't click links, download attachments, or reply. Spotify won't request payment info, passwords, or other sensitive information over email.

If you're concerned about a payment or subscription problem, go directly to your account in the Spotify app or a web browser instead. If you've already entered your Spotify credentials into a suspicious site, change your password and keep an eye on your credit card transactions to catch any fraudulent charges. You can also forward phishing emails to spoof@spotify.com.

This Job Interview Scam Is a Ploy to Steal Your Google Credentials

8 July 2026 at 13:30

It's rough out there for job seekers, and scammers are preying on candidates hoping to get hired by well-known companies. A new phishing campaign uses fake interview invites—impersonating brands like Adidas, Netflix, Adobe, and FIFA—to steal users' Google account credentials.

Employment scams are nothing new, and they come in a variety of flavors, from fake job offers sent via text to fake applications distributed via Google Forms. Netflix impersonators even ran a similar recruitment email campaign last year. Bad actors are typically trying to phish personal information or convince you to send them money for various (fake) onboarding expenses.

How the fake job interview scam works

As BleepingComputer reports, this job scam primarily targets marketing professionals looking for positions with high-value companies across multiple sectors, including tech, hospitality, travel, food, entertainment, and luxury goods.

The fraud begins with a phishing email from a "recruiter" at one of more than 34 companies, inviting candidates to schedule a meeting to discuss further. Scammers appear to be using the names and photos of real recruiters at these companies, making them less likely to raise suspicion if targets try to verify their legitimacy.

If a job seeker clicks the link to the recruiter's calendar, they'll be redirected multiple times and ultimately land on a malicious website designed to look like a real interview scheduling page. From there, they'll be prompted to sign in with Google, which launches a fake login interface that looks like Google's authentication pop-up but is actually just part of the phishing page. (This is an example of a browser-in-the-browser (BitB) attack.)

Threat actors appear to be using a legitimate HR platform called PeopleForce and a domain operated by Salesforce to initiate the scam, though it's not clear whether they created accounts or are using stolen credentials.

Signs of a fake job scam

Like all scams, this one preys on emotion, like the excitement of being recruited for a highly desirable position in a competitive job market. If you receive an unsolicited message from a recruiter, whether via email, LinkedIn, or some other social platform, proceed with caution—especially if you haven't applied for a job or the opportunity sounds too good to be true. If you're not sure, go directly to the company's careers page to find the listing.

Just because a calendar or application link appears to go to a legitimate site doesn't mean you're safe. Obviously, scammers have many ways of spoofing URLs or redirecting traffic so you don't realize you're being phished. Look carefully at the address bar on the final window for sneaky characters or other URL tricks.

If you're being prompted to enter single sign-on credentials (such as Apple, Google, or Facebook) to schedule an interview or fill out an application, this is a red flag. Try to interact with the pop-up, such as by dragging it away from the main browser window or highlighting the URL. If you can't, it's likely a fake. A password manager can also protect against BitB attacks, as these tools won't fill credentials, except on the legitimate domain.

❌