Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Friday, October 24, 2025

Reader Submitted: Fake SL Login Screen

 

 From The Orange Floof (FriendlyDaWusky Resident). This is an image of what looks like an SL login screen. But checking the Internet address, one can see this is a fake. This was almost certainly meant to to was to get passwords and account names as a "phishing" scheme, then hack the account and swipe all their Lindens.
 
A reminder to be careful when clicking on strange links, and double check what you're logging into.
  
 
 
 

Wednesday, September 4, 2024

EOTB: Linden Lab Reminds Residents To Be Wary of Scammers and Hackers

 
 

You may see viewer download links shared in local chat, DM, or even group chat. These links are usually unsafe and link to software that compromises your Second Life account or installs additional hidden software that gives a stranger control of your computer. Be wary of downloadable software links. Strangers may claim that their link is an early fix, a special version of the viewer, or an early release of an anticipated product. Don’t be fooled!

If you see a link advertising a Third-Party Viewer, don’t click it directly. Always check our Third Party Viewer Directory for a list of safe download locations. All approved third-party viewers are included here, and the official Second Life Viewer is available from the Second Life site. To help keep others safe, share this blog post and submit an Abuse Report if you see a suspicious link shared in world. 

 They would also offer five suggestions
 
Be wary of unsolicited messages or emails. If you receive a message from an unknown sender or even a friend (you never know if their account was compromised), be cautious before clicking any links. It’s always best to err on the side of caution. 

Check the website’s URL. Before logging into the website, ensure you’re on a legitimate site. A phishing website will often have a similar-looking URL, but with slight variations. Check for spelling errors or subtle changes in the website’s address. 

Look for security indicators. Legitimate websites will often have security indicators, such as a padlock icon or “https” in the URL. This indicates that your information is being transmitted securely. If you are unsure if a URL is legitimate, you can always send in a support ticket and ask for clarification. 
 
Use strong passwords. A strong password is at least 8 characters long and combines uppercase and lowercase letters, numbers, and symbols. You should also use a different password for each online account to reduce the risk of multiple accounts being compromised if one password is stolen. 

Enable Multi-Factor Authentication (MFA). This will add an extra layer of security to your account by requiring a second form of identification to access your account to make account changes.

 To see the blog post in full, Click Here
 
Bixyl Shuftan
 

Friday, July 12, 2024

Sneaky Discord Scam

 
 
 Been hearing about a diabolical scam on Discord. It's described as appearing as a very obvious one at first, but the REAL scam is the "dismiss message" link, which supposedly gives the scammer access to your computer. 

At the very least, it's a reminder to be a little careful with your computers. 

Tuesday, November 14, 2023

Phishing Scam Viewer Worries Get Linden Lab's Attention

 
It's a sad fact that the Internet is full of scammers. And unfortunately some have come to Second Life.  There's been some news going around recently about one particular phishing scam: a viewer that will supposedly give you unlimited Lindens, and allow you to build anywhere.

Hello,

Are you tired of spending your hard-earned Linden Dollars? We've got an exciting solution just for you! Introducing our SecondLive Viewer, where everything is not only free but also open for endless possibilities.

  • Unlock unlimited Linden Dollars (L$) for all your virtual adventures.
  • Fly to unlimited heights.
  • Build on any land of your choice, all for free.

But that's just the beginning.

Link: <Some URL, typically a tinyurl link>

We're sincerely thankful to everyone who joins us in our mission to make SecondLife completely free. Don't miss this incredible opportunity.

Best Regards.

Most residents would recognize right away these claims are bogus. Viewers can't create Linden dollars, only Linden Lab's computers can do that. One would have to hack into them, and keep hacking to get the virtual money, which would not only be extremely difficult, but easily discovered and traced. Nor can your viewer determine which land you can build on - the permissions of who can and can't are stored in the servers.

Firestorm would express worries of copybot viewers last month before I personally started hearing about the forementioned scam. The scam itself I first heard about when a few people passed me a link to a post made by FelixWolf on GitHub, who would be identified by Inara Pey of Modem World as Chaser Zaks of Team Firestorm who "risked taking a look under the covers of the code that is supplied."

What the viewer actually does is run a program called builddata.bat on your computer, which installs a number of remote administrative toolkits (or RATs). Once your machine is infested with these RATs, the scammer can:

Steal your Linden dollars and go through your inventory

Steal your password and hijack your account, and whatever they do, people (and Linden Lab) will think it's you.

Go into your computer and steal/delete your files.
 
Steal your banking and credit card information, and steal your real-world money, and possibly ruin your credit.
 
Discover real-life information on you, such as your city and street address. 
 
Activate your camera and take pictures of you and the contents of your room. If they get your real-life location, they may know where to find valuable items to steal. 

Last Thursday, Linden Lab would feel the need to remind it's residents of the dangers of phishing scams in general, "Ensuring A Secure Second Life Experience." It brought up this particular viewer, "
It is important to remember that downloading software from unknown sources has a very real risk associated with it. You could unintentionally allow someone to monitor your keystrokes or even gain complete control over your computer. It has the potential to expose not just your Second Life password, but all other important information you have on your computer. ... Be wary of suspicious links or attachments sent by other users. These may be attempts to compromise your account or computer. ... Only download and install the official Second Life viewer, or an approved Third-Party viewer directly from the links provided by our site."
 
So once again, a reminder that one needs to be a little wary when going about Second Life (and the Internet in general), and don't let yourself get a RAT infestation. 
 
Bixyl Shuftan 

Wednesday, April 12, 2023

EOTB: Linden Lab Speaks Out On Phishing Scams

 
 It was a few days ago in which the Newser reported on Team Firestorm stating there was a phishing scam afoot. On Monday April 10, Linden Lab decided it was time to comment on the issue, posting on the official blog an article about spotting them.

One day you are in Second Life, minding your own business while you walk through your favorite store when all of the sudden you get a private message from someone with a link to an item on the marketplace. Without thinking about it, and curious what the item might be, you give it a click. The page loads up looking just like the marketplace, except you need to log in so you happily enter your username and password. Next thing you know, your linden dollar balance is suddenly gone, and you can no longer access your account. You just fell victim to a popular scam known as Phishing.

The Lab would state several things one could do to avoid getting tricked by these schemes.

  1. Be wary of unsolicited messages or emails. If you receive a message from an unknown sender, or really even a friend (you never know if their account was compromised), be cautious before clicking on any links. It’s always best to err on the side of caution. 
  2. Check the website’s URL. Before logging into the website, make sure you’re on a legitimate site. A phishing website will often have a similar looking URL, but with slight variations. Check for spelling errors, or subtle changes in the website’s address.
  3. Look for security indicators. Legitimate websites will often have security indicators, such as a padlock icon or “https” in the URL, this indicates that your information is being transmitted securely. If you are not sure if a URL is legitimate, you can always send in a support ticket and ask for clarification.
  4. Use strong passwords. A strong password is one that is at least 8 characters long and contains a combination of uppercase and lowercase letters, numbers, and symbols. You should also use a different password for each of your online accounts to reduce the risk of multiple accounts being compromised if one password is stolen.
  5. Enable Multi-Factor Authentication (MFA). This will add an extra layer of security to your account by requiring a second form of identification in order to access your account to make account changes.
As a reminder that the scammers were still out there, someone posted a picture of someone getting targeted. It was stated the culprit was ARed and later banned.

The Lab would also remind people that phishing, and other online scams, are always changing and evolving. So developing a habit of staying vigilant is important in order to avoid being surprised and robbed by one.

Click here to read the whole article.

Image credit: Nikkita Sugar Lefavre (Aubrytia)

Bixyl Shuftan

Thursday, April 6, 2023

New Phishing Scheme on The Firestorm Viewer

 
There is a new phishing attempt that surfaced today. A dialog box will say you are about to be logged off, and that you should enter your password. Obviously you should not enter your password, but instead file an abuse report against the sender.
 
From Team Firestorm 

Image credit: Duchess of Trikassi

Correction: The scam does not appear to be limited to Firestorm, but may appear on any viewer.

Saturday, July 10, 2021

Concerns About Suspicious Discord Posts

 

There's been a number of warnings on a few Discord channels about scammers trying to trick people ot click on a link that could lead to trouble. This was from the World of Warships Discord:

Players, good evening, morning and day!
It has come to our attention that lately there has been a rise in suspicious activity involving Discord users attempting to scam or share phishing links in our community and via direct messages.

Please do not click or open any suspicious links and report them immediately.
These scams often but not always involve fake Steam-related links such as "free" gifts or claims that your accounts were banned.

If you encounter suspicious activity please proceed to follow the instructions from the link below on how to properly report such users to Discord's Trust & Safety team or contact a member of our moderation team.

https://support.discord.com/hc/en-us/articles/360000291932-How-to-Properly-Report-Issues-to-Trust-Safety

Enjoy your weekend

 

Friday, February 22, 2019

Announcement: This Week At The Science Circle : Cyber Security


"Cyber Security"
Saturday February 23 at 10 AM PST

Moderator: Matthew Burr – Beragon Betts

Anyone who is interested in his security on the internet will soon come across worrying reports about phishing e-mails, cybercrime, industrial espionage, governments stealing each other’s data and cyber-terrorism. Closer to home, data mining affects us via Facebook, Google and Microsoft.

What started as a free sharing of data has gradually turned into an unsafe, lawless space where everyone is a target for malicious parties.

More information Harvard Cybersecurity Wiki

The Science Circle (61/127/32)

Saturday, September 23, 2017

Eye on the Blog: "An Important Reminder About Account Security"


The following was posted by Linden Lab yesterday.

It has come to our attention that some Residents are sending messages - which may appear as popup windows in some viewers - informing other Residents that their accounts have been compromised and encouraging them to contact Support, using a phone number that is not associated with Linden Lab.
 
These messages are phishing attempts to gain access to your Second Life account. Neither Linden Lab, nor Second Life Customer Support, would attempt to contact you in this manner. You can always find Linden Lab’s official customer support contact methods within the following links:
 
 
As always, please be wary of suspicious messages and contact from other users. If you believe your account has been compromised, please contact us via support case at https://support.secondlife.com/

Hat Tip: Fuzzball Ortega 

Monday, September 23, 2013

Hacked

Earlier this month, a warning was sounded in the Angels and Sunweaver groups. Brandi Streusel, one of the more popular members, noted for her "Brandi's Panties" line of outfits, had been hacked. An amount of Lindens were swiped from her account, a number of items on her were compromised, and the most visible example of what happened, Castle Mousehold was wrecked. The possessed avatar deleted about half the place.

As soon as she realized what was happening, Nydia sounded the alarm in the Sunweaver and Angel groups, in addition to several other groups, urging the account be barred from their places until it was confirmed she was back. And above all, not to click on links she was sending out.

As you all probably know by now, Brandi's account has been hacked, I have banned her where I could, but not before the castle was destroyed, right now...our home is gone. I have asked Rita for a roll back that should fix that, as for when we get Brandi back ….I don't know.


Unfortunately, someone else did click on a link sent by the hacker before word got around, Dusk Griswold. So word went out about the second hacked account, warning that if they clicked on anything sent by them, "you need to change all your passwords NOW, and anything your account is linked to."

If  you are ever sent a website link that tries to be something from Second Life.  Make sure that it is actually from secondlife.com

This   http://markettplacefree.altervista.org/index.html   IS NOT from Second life.  Never click on a link, or log into a page that isn't an Actual Second Life web page.  If you're not sure,, be safe and just don't. 


Eventually, Brandi and Dusk were back. Linden Lab didn't give Brandi the Lindens she lost back, and she had to go through her inventory to examine what might have been compromised. But the sim rollback was carried out and the castle restored. Dusk reported the hackers tried to rob her, but the Lab took care of the details.

Just wanted to let everyone know LL has restored my account after the hacking incident. The person first tried taking all my Lindens, then buying Lindens. They did succeed in making a few small transactions on Paypal, but they have been notified, and I should get credit for those. The Lindens they took from me here have been restored, and all my passwords have been changed.  

And so the hackers were stopped. Thanks to the community spreading the word, no more found themselves locked out of their accounts. But this was a warning to all about "illicit links and the problems they cause."

" …. people will understand the peril they put themselves in if they don't take 5 seconds to simply check links. They can lose everything and not even be here for it, everything including their own financial holdings. A hacker if they can get your account and log in, they can get access to your personal money line account numbers, and that leads to things far far worse than this world. I know... it's happened to me. I fought tooth and nail to get everything back … "

Words of warning to listen to. And of course, a reminder if one suspects anything funny, don't hesitate to change your password.

Press Pass Media also wrote an article recently on the subject of phising scams (click here). 

Bixyl Shuftan

Thursday, April 19, 2012

Phishing Scams Target Phoenix & Firestorm


The development team at Phoenix/Firestorm are warning residents who use their viewers about a phishing scam that is targeting them.


The scammers claim that the people at Phoenix are paying Lindens to residents who take a survey. There is a link where the residents are led to a fake (but very realistic looking) login page. When the residents log in, their account name and passwords are taken. The scammers can then log in and steal the resident’s identity, Lindens and inventory. The scammers have even used the resident’s contact/friends list to send out phishing notes. This practice leads people to believe they are getting safe links since the information is coming from a friend.



Jessica Lyon of Phoenix/Firestorm stated that they are not paying Lindens for any type of survey. They are warning residents to be very careful about logging into fake sites. If residents believe they have been a target, they should immediately go to Secondlife.com to change their password.



For more information go to the Phoenix/Firestorm support site at http://www.phoenixviewer.com/. The site has detailed information on what URL to look for whenever you are asked to log into your account.



Information for this article was taken from http://www.phoenixviewer.com/.

Grey Lupindo

Editor's Note: Treminari Huet also wrote on the subject: http://treminarisecondlife.blogspot.com/2012/03/scammers.html

Monday, January 9, 2012

Phishing Scam

Xymbers Slade recently found something in one of his groups, "Just got this out of one of the Mentor groups I'm a part of --- those scammers just never seem to give up. So spread the word, that this one's a scam."


Dear Second Life user,

Due our latest IP Security upgrades we have limited access to sensitive Second Life account features.
Protecting the security of your account is our primary concern
We understand that this may be an inconvenience.
Please understand that this temporary limitation is for your protection.

How can I restore my account access?

Please download the form attached to this email and open it in a web browser.
Once opened, you will be provided with steps to update your account.
We appreciate your understanding as we work to
ensure account safety.

If we detect a sign in with your username from another country we may decide that we want to
confirm that it's really you. You must complete all steps otherwise you will not be able to use
the online service until we have completed additional security checks.


We apologize for any inconvenience

Copyright 2011 Linden Research, Inc. Linden Lab 945 Battery St. San Francisco, CA 94111


It should be reminded that it's not just Mentor groups open to such swindels, but any with open enrollment.