Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Scams & Phishing Security Education Videos Mobile Security Your Security Education Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
Phishing Scams Exploit Pricey Auto-Subscription Fears
Facebook   X   LinkedIn   Email

Phishing Scams Exploit Pricey Auto-Subscription Fears

May 20, 2025

With email among the top productivity tools in our everyday lives, we know cybercriminals have adopted it for their benefit, too. And now, according to an alert by the National Security Agency (NSA) and Cybersecurity and Infrastructure Security Agency (CISA), there’s a new and highly lucrative email phishing campaign making the rounds.

Both agencies are sounding the alarm about a particular version of this phish, wanting the public to know how it works. Awareness can help prevent it from taking a big bite out of our bank accounts and opening the door to further attacks.

The Fear Factor

The advisory warns a popular version of these phishing attacks happens when targets receive an email warning a subscription is “about to expire,” saying it will automatically renew for the price of several hundred dollars. Often, it’s anti-virus software. Hackers know most users will open the email and follow instructions to prevent being charged. Fear, especially combined with finances and pressure to act quickly are a motivating mix for criminal success.

Now on the hook, email recipients are told to call a “help desk” which, is controlled by the hacker. They’re told to download a remote monitoring and management (RMM) software to resolve the situation and cancel the subscription payment. The hacker also convinces the now-victim to open their bank account while the RMM is active. Once done, the attacker has unfettered access to the money, and a quick getaway is assured.

RMMs are legitimate software and are often used by IT departments to manage users computers on the networks without having to pay a visit to a desk, or more often now, a home. But hackers found a way to exploit them. RMMs can bypass anti-viral protections, administrative privileges, and software management controls. Once inside a system, other crimes like ransomware attacks and identity theft may not be far behind.

Thanks to this email phishing attack’s success, downloading RMMs now deserve our attention and suspicion. The advisory states, “Threat actors often target legitimate users of RMM software. Targets can include managed service providers (MSPs) and IT help desks, who regularly use legitimate RMM software…”

To protect yourself and your finances, be aware of email subject lines and content “warning” about unexpected subscription fees. Don’t fall for the fear factor and don’t download tools to your computers or devices unless you are 100% certain they are safe. It’s always advised to ask your manager or IT support if in doubt.

Awareness is a great prevention tool for avoiding email phishing and other cybercrimes, so be sure to share the news with friends, family, and co-workers. You never know, one day they may thank you for it!


Your Data For Sale On The Dark Web And What You Can Do About It

Identity Theft

Your Data For Sale On The Dark Web And What You Can Do About It

As much as we love the convenience of our digital world, we know a hefty price tag can come with it. The world is full of bad actors whose goal is to get their hands on our sensitive, personally identifiable information, or PII. Should you find your PII is for sale on the dark web, it helps to know there are options for doing something about it, even if you think it’s too late. Just some of that hijacked PII can include passwords, email and physical addresses, Social Security numbers, financial accounts, and much more. READ FULL STORY

Gift Cards Being Used For Payment In BEC Scams, And What You Need To Know

Scams & Phishing

Gift Cards Being Used For Payment In BEC Scams, And What You Need To Know

Over the years, gift cards have become an enormous “go to” way of giving. Mageplaza found the purchase of gift cards this year will reach nearly $450 billion globally. And like many things involving monetary value and being human, cyber-scammers are exploiting gift cards for profit. They’re now combining gift card fraud with the world’s most lucrative cybercrime, business email compromise (BEC) attacks. According to researchers at Cofense, organizations are getting hip to more traditional BEC tricks and have bolstered protections against them. As a result, fraudsters needed a new lure and turned their attention to gift cards. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...