Search Content


Content Categories



Phishing Scam Strikes in Twitter Direct Messages

A new phishing attempt has been circulating tonight that’s being distributed through direct messages. If you receive a direct message like this, delete it immediately.

Screenshot of Phishing Direct Message

The direct message will include the following text and link:

hey! check out this funny blog about you… jannawalitax.blogspot.com

As a measure of courtesy, you might want to inform the user who sent it to you that they’ve fallen victim. You can send them a reply or a direct message, whichever one you feel is more effective.

Protect Yourself

The link will take you to a site that looks very much like Twitter - but it is not. It’s a third-party site (twitter.access-logins.com) that just wants your password so it can spread further.

Access-Logins Twitter Phishing Site

It’s important to note that you should really treat direct messages like you treat email. As always, we advise practicing caution when using your Twitter credentials. If it looks suspicious, it probably is.

Oops! I clicked on the link, now what?!

If you did log in at the phishing site, change your password immediately. Without a valid password, there’s nothing the phishers can do on your behalf. Unfortunately, there’s not much else you can do right now. If we hear about an official point of contact, we’ll list it here.

Twitter’s On It

Biz Stone tweeted earlier that the operations team at Twitter is working on the issue, so expect to see a resolution fairly quickly. There’s also a post on the issue on the Twitter Status blog. We just wanted everyone to be aware of the issue before it affects you. We, and many others, have sent out warnings through Twitter - please do your part and retweet or redistribute the link to this article.

Update: It looks like the phishers are also hitting Facebook, as pointed out by @jamescarr (via @hillabean). Beware of anything linking to access-logins.com. Rob also pointed out that Firefox is reporting anything at that domain as web forgery.

Update 2: Twitter has a great post on their blog about what phishing is and what you can do to avoid phishing scams.


Related Force Foundation Articles

$15 Million from Bessemer


Tomorrow morning we will announce that we've raised another $15 million to help Intacct to grow our business. This is on top of $14 million we raised in June 2007 and raises the total amount invested in Intacct since its founding to just more than...

Read more about $15 Million from Bessemer...

My Favorite Blogs & Websites of 2008


Following are the top 20 websites / blogs that I pay most attention to as per FeedDemon. The snapshot on the left was captured in June (for comparison) while the one on right reflects my current reading...

Read more about My Favorite Blogs & Websites of 2008...