Hackers Use Free Email Accounts from QuickBooks to Launch Spoofed Phishing Attacks

Stu Sjouwerman | Jul 28, 2022

Hackers Use Free Email AccountsA new attack uses one brand email domain to increase the chances of reaching an Inbox, while spoofing another brand to trick users into transitioning to a vishing attack.

I’ve covered attacks involving the brand QuickBooks previously this year. An attack earlier this year impersonated the QuickBooks brand, targeted its’ users with an email informing potential victims that their account was being put on hold.

But a new attack identified by security researchers at Avanan takes a different approach while still taking advantage of the reputation of the QuickBooks brand. QuickBooks allows users to create free accounts that have been used to send emails spoofing the Norton and Microsoft 365 brands.

In their emails, a fake invoice is sent, inviting the recipient to call if there are questions.

H04zKUOMj13tCHyvH4lqD_7R0hqeNCVdcCSvulvbiOKd3N65OcY7cJuohs3yFEmZvSOQ7e7Xx6xct62F96T-USqlsbusaUwB4c7Xfg8TchUd6Y2WX3h4doM0xHwHCaelel4VAmhhGy_exio8ow

Source: Avanan

Avanan researchers see this tactic as having two purposes:

  • The hackers get the phone number of the victim, which can potentially be used in future attacks likely using texting or WhatsApp communications.
  • The hackers get credit card information from the victims, which have obvious nefarious uses.

This attack demonstrates how the simple use of anything that establishes credibility can be used against unsuspecting users. Keeping them vigilant when interacting with email – particularly ones that deliver an unexpected message – should be treated with suspicion. This can be accomplished by maintaining that vigilance through continual Security Awareness Training designed to educate users to see these kinds of impersonation attacks for what they really are, before they fall prey to them.

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.