HomeSecurityDisney+ used in brand impersonation attack

Disney+ was used in a brand impersonation attack

According to a new report from Abnormal Security , brand impersonation in cyberattacks has increased and become more sophisticated, as demonstrated by a recent incident involving Disney+.

Disney+

Traditionally seen in financial institutions and social networking sites, threat actors are now using multi-stage attacks with a high degree of personalization

According to Mike Britton, CISO of Abnormal, hackers impersonated the popular streaming service Disney+ as part of a complex scheme.

See also: Fraudsters earn $50,000 a day impersonating cryptocurrency researchers

Hackers pay attention to detail

The cybercriminals began the attack with an email that purportedly contained a notification about a pending charge for a new Disney+ subscription. Each email contained a PDF attachment with the recipient’s name on it – a rare tactic that requires manual effort and shows the level of personalization of the attack. The PDF describes a large charge ($49.99), which is above and beyond regular subscriptions, and includes a seemingly legitimate customer service number.

The hackers made the sender email look like the legitimate Disney+ address. This is what happens in most cases of phishing and brand impersonation attacks. However, here, they also incorporated brand colors, personalized subject lines and greetings, making it all much more realistic. The emails did not have obvious signs of phishing, such as spelling errors or malicious attachments. This makes them difficult to detect by both traditional security solutions and individuals.

“What sets this attack apart is the level of personalization and attention to detail used by the perpetrators, making it difficult for traditional security and even vigilant individuals to recognize it as malicious,” Britton wrote.

“Based on initial investigation in late September, the threat actor targeted 44 individuals across 22 different organizations with this brand impersonation attack that used Disney+.“.

See also: Samsung owners can get up to a year of free Disney+ subscription

brand impersonation

Although Abnormal did not provide many technical details about the attack, the main attack vectors appear to include a combination of phishing emails, attachment-based tactics, social engineering over the phone, and brand impersonation.

The study highlighted the difficulty for Secure Email Gateways (SEGs) to detect such attacks, given the absence of clear signs of fraud. Users, on the other hand, also have difficulty recognizing such an elaborate scam.

To combat such attacks, Abnormal's research paper suggests email security solutions that use artificial intelligence , including machine learning, behavioral AI, and content analysis.

Also, we should not forget that a brand impersonation attack is dangerous for the company itself - the brand used to deceive users. A possible result of this attack is the undermining of consumer trust in the company's brand. If consumers fall victim to counterfeit products or services, they may question the quality and reliability of the company. This can lead to a decrease in sales and loss of customer base.

See also: Disney+: Takes steps to limit password sharing

Furthermore, the attack can have a negative impact on the company’s prestige and reputation. If the company cannot protect its trademark from counterfeits, it may be seen as incapable or indifferent to protecting its rights. This can have a negative impact on the company’s image and affect its relationship with its customers, investors and partners.

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS