Cybercriminals are exploiting Venmo to carry out phishing attacks.

Venmo is a payment service owned by PayPal and is quite popular in the United States. It allows for the instant exchange of money between individuals and between businesses and customers. However, the popularity of the service (over 62.8 million active users) has attracted the attention of cybercriminals.
Phishing attacks exploit Venmo
Hackers are sending phishing emails that appear to come from Venmo and trying to convince targets to call the supposed customer support (fake phone numbers) to fix some charges.
See also: CryptoChameleon phishing kit: Hackers target FCC
Harmony Email researchers spotted this new wave of phishing attacks and notified Venmo on February 13th.
In one message they spotted, the scammers informed the recipient about a supposed $99.99 payment to Coinbase via Venmo. The email urged the recipient to call a phone number to cancel the charge. The scammers’ goal is to steal personal and financial information.
See also: Phishing emails: Warning signs and protection tips
Venmo: Phishing attacks with sophisticated techniques
These emails manage to pass standard security, such as SPF and DKIM, and contain legitimate links, making them appear as trustworthy messages from Venmo.
The scam can only be detected by the fraudulent phone number.
When victims call the number provided in the email, the scammers attempt to steal sensitive information. Additionally, by recording the victim, they can launch additional attacks via SMS, WhatsApp, or direct calls.
See also: TimbreStealer malware spreads via phishing scams

Protection against phishing attacks
To combat these sophisticated phishing attempts that exploit Venmo, the following are recommended:
- Use security solutions AI-powered that analyze multiple phishing indicators.
- Use powerful URL protection services that can scan and mimic websites to detect malicious content.
- Implement security measures with the ability to scan phone numbers .
- Learn about the techniques used by phishing attacks (e.g. Venmo impersonation) so you can identify suspicious messages.
- Be careful with links included in emails. Before clicking on a link, you should check the URL to make sure it leads to a safe website.
- Use different passwords for different accounts. If one password is leaked, then only that account will be exposed.
- Update your software and applications . Updates often include security fixes that can help protect against phishing attacks.
Source: cybersecuritynews.com
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
