Phishers are always thinking of new ways to increase their chances of collecting sensitive information. Symantec recently observed a phishing where data was collected through a fake website that suggested its visitors vote. The malicious website asks users to vote on the question “WHO IS GREAT BOYS OR GIRLS?”

The phishing page is hosted on a service that offers free hosting and targets Facebook users. The scammers behind the malicious campaign, to make it more believable, have posted charts representing the percentage of votes. The data is fake and is assumed to show the total votes over the past four years.

The first phishing page contains a button to start the voting process. After you click the button, a pop-up window appears, asking for your name and Facebook password, as shown below:
Using voting websites as bait is not unusual, and it is advisable to follow the steps below for your protection
Check the URL in the address bar when you log in to your account to make sure it belongs to the website you want to visit.
Don’t click on suspicious links in emails.
Don’t give out your personal information in emails.
Don’t give out personal information in pop-ups.
Make sure the website you are about to enter your payment information on is encrypted with an SSL certificate and has a padlock icon, “HTTPS”, or a green address bar.
Use comprehensive security software that protects against phishing and social media scams.
Be careful when clicking on links with tempting topics that come via email or posted on social networks.
