New Scam Impersonates QuickBooks to Steal Credentials, Extract Money

Stu Sjouwerman | Sep 15, 2023

Phishing as a Service Platform Financial InstitutionsEstablishing urgency through a false need to “upgrade” or lose services, this new attack takes advantage of the widespread use of the popular accounting app to attract victims.

Impersonation in phishing attacks only works if the target has an established rapport or relationship with the sender. And in the case of QuickBooks, there are about 8 million targets worldwide – large enough to send out mass emails and allow those that don’t use the software to self-filter, leaving the customers to determine whether they are going to be a victim or not.

This latest scam was identified by security researchers at Avanan. What’s particularly interesting about this scam is its methods used to establish urgency. Take a look at the email used:

undefined-Aug-15-2023-07-04-57-0725-PM

Source: Avanan

The email is about upgrading and the tone is one of urgency. It quickly establishes that the recipient needs to upgrade or they’ll lose services like payroll or the account’s data. It also uses the color red (which naturally grabs our attention).

Lastly, in the example above, note how this email scam changes mediums, requiring the victim to call a phone number – a relatively recent tactic used to remove the victim from an environment where security solutions can continue to assist in detecting malicious activity. The phone number is associated with a scam where callers are socially engineered into giving up their credit card details for the “upgrade."

This type of scam could just as easily be one that targets someone working in accounts payable impersonating a vendor, making it important to educate all users of scams like these with continual security awareness training.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.