‘Monster’ phishing of recruitment website
Fraudsters look to target credit-crunch affected jobseekers, and find that new phishing kits are making their jobs even easier

A new phishing scam targeting users of the recruitment website Monster.com has been discovered by researchers at McAfee.
It is part of a trend by criminals to target recruitment websites, which like social networks, contain personal and sensitive data carried in carried in CV's and databases.
Monster.com has been targeted by criminals before last year it was victim of two security breaches caused by a trojan attack, which resulted in the details of 1.3 million US job seekers being exposed.
The latest attack works by sending potential victims emails which ask users to click through and update their profile, but is traced back to a bot in Turkey.
McAfee said that the scammers were trying to get through to recruiter's accounts and gain access to CVs which can sometimes hold valuable information.
Like the recent trend for scammers targeting social networks, McAfee security analyst Greg Day felt that criminals were taking advantage of the current economic climate, with users increasingly using the internet to find new jobs to see what is available.
He said: "The repercussions of this are potentially huge. If a cyber criminal is able to access a large number of CVs, the information obtained could easily be used for malicious intent.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"As far as cyber criminals are concerned, CVs offer a goldmine of information, so this would be a major result for them."
A RSA Online Fraud Report' was also released which said that collecting the data given by victims through phishing attacks was being made much easier thanks to new phishing kits that are designed to directly store data in a MySQL database on a phishing server.
Previously the stolen information would have been sent as text to the fraudster's email address coded within PHP files, or simply stored on the server as a text file.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
'You need your own bots' to wage war against rogue AI, warns Varonis VP
News Infosec pros are urged to get serious about data access control and automation to thwart AI breaches
By Rene Millman Published
-
CrowdStrike CEO: Embrace AI or be crushed by cyber crooks
News Exec urges infosec bods to adopt next-gen SIEM driven by AI – or risk being outpaced by criminals
By Rene Millman Published
-
Microsoft security boss warns AI insecurity 'unprecedented' as tech goes mainstream
News RSA keynote paints a terrifying picture of billion-plus GenAI users facing innovative criminal tactics
By Rene Millman Published
-
APIcalypse Now: Akamai CSO warns of surging attacks and backdoored open source components
NEWS Apps and APIs bear the brunt as threat actors pivot to living off the land
By Rene Millman Published
-
AI is changing the game when it comes to cyber security
News With AI becoming more of an everyday reality, innovative strategies are needed to counter increasingly sophisticated threats
By Rene Millman Published
-
RSAC Chairman urges collaboration to ensure collective defense in security
News Chairman emphasizes the critical need for cooperation among cyber security experts
By Rene Millman Published
-
McAfee and Visa offer 50% off antivirus subscriptions for small businesses
News UK Visa Classic Business card holders can access the deal starting today
By Zach Marzouk Published
-
McAfee Total Protection review: Expensive at full price
Reviews Protects your PC and includes a decent firewall, but costly and less effective than some rivals
By K.G. Orphanides Published