U.K. Residents are Victims of the Latest Phishing Scam Targeting Starbuck Customer Credentials



blog.knowbe4.comhubfsBEC Email Scams PhishingAnalysis of a new phishing attack highlight just how easy it can be to spot these kinds of attacks if recipients were properly educated.

Action Fraud, the U.K.’s national fraud & cyber reporting center, recently warned U.K. residents of a scam impersonating Starbucks. The email-based scam purports to be from the global coffee brand, telling the recipient they’ve won a “Starbucks Coffee Lovers Box."

GaAHQhZX0AAFo4H

Source: PBS

In reality, it’s a phishing attack designed to take victims to a fake Starbucks landing page intent on getting the victim to enter in their Starbucks customer credentials. 

These credentials are then used by scammers to attempt access to other web-based services, online banking, and more – in the hopes that the credential’s owner uses the same email address and password combination.

It’s a simple enough scam to spot – the image above shows just how bogus the actual sender email address is, the email content doesn’t look remotely up to the level of what Starbucks would actually put out, and then there’s the whole “like Starbucks is just going to give me a free gift!” aspect of the scam.

But it does require a vigilant mindset when interacting with email. The need to always assume anything out of the ordinary is “guilty until proven innocent” is something taught via security awareness training that helps instill the sense of vigilance necessary to keep from falling for these scams.

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.


Will your users respond to phishing emails?

KnowBe4's Phishing Reply Test (PRT) is a complimentary IT security tool that makes it easy for you to check to see if key users in your organization will reply to a highly targeted phishing attack without clicking on a link. PRT will give you quick insights into how many users will take the bait so you can take action to train your users and better protect your organization from these fraudulent attacks!

PRT-imageHere's how it works:

  • Immediately start your test with your choice of three phishing email reply scenarios
  • Spoof a Sender’s name and email address your users know and trust
  • Phishes for user replies and returns the results to you within minutes
  • Get a PDF emailed to you within 24 hours with the percentage of users that replied

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-reply-test



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews