WhereIsTheOne?!
Junior Member
Cybersecurity is a large part of my job. A little while back one of our customers was compromised through an AiTM MFA-stealing phishing attack (nasty) and during that, the attackers stole company signatures and grabbed the customer list. This was for a solicitor that deal with conveyancing.Here is an example of how subtle fake urls can be. If you don't have the two side-by-side, you probably wouldn't notice.
This is why I never ever buy from social media ads. It's tricky enough when you are trying to find the correct url yourself.
After I secured our customer's accounts there was still email activity reported between the criminals and our customer's customers. Turned out that half an hour after I'd secured everything, the criminals registered a URL that simply pluralised the company name from &$#*(#Solictor.net to &$#*(#Solictors.net
It took me three weeks to get the scam domain shut down and ultimately got shut down only because I contacted the CEO of the domain registrar that the criminals had used via LinkedIn and pointed out the issue. This was after going through their 'official' reporting channels, etc. Once I'd contacted the CEO it got shut down in 20 minutes. In the end we registered half a dozen adjacent domains to our customer's domain to try and limit this happening again.
In this case, 50K was stolen from one of customer's customers as the scammers had targeted people that were about to pay house deposits and in this case, a 500K house was being purchased with a 50K mortgage deposit.
Not the most money that I've personally seen stolen but in this instance, the fraud was very good and I've seen people fall for much, much less.