Lost24

A woman from the United Kingdom lost GBP 9,000, scammers created a fake advertising campaign using the image of a famous person - Elon Musk, owner of Tesla and SpaceX.


The deceived woman came across a specially crafted BBC website, from which she found out about the said campaign. The advertising campaign assured that after making a deposit in bitcoin, a payout of double the amount would be made. The victim, after realizing that she was a victim of fraud, immediately contacted her bank. However, the money was no longer recoverable as the transaction was made voluntarily.


According to the Ladbible portal, the BBC has taken steps to close the fraudulent website.



Lost24

A woman from the United Kingdom lost GBP 9,000, scammers created a fake advertising campaign using the image of a famous person - Elon Musk, owner of Tesla and SpaceX.


The deceived woman came across a specially crafted BBC website, from which she found out about the said campaign. The advertising campaign assured that after making a deposit in bitcoin, a payout of double the amount would be made. The victim, after realizing that she was a victim of fraud, immediately contacted her bank. However, the money was no longer recoverable as the transaction was made voluntarily.


According to the Ladbible portal, the BBC has taken steps to close the fraudulent website.



Wednesday 19 May 2021, Safety Guide

WhatsApp account hacking

Lost24

Scams based on hijacking WhatsApp user accounts are becoming more and more popular.


According to CyberDefence24, fraudsters take over the accounts of randomly selected users, which is possible thanks to reading the verification code during registration. The scammers then contact the target’s WhatsApp friends impersonating the person. The scam is similar in practice to the scams utilizing Blik, which are often used after hijacking a user's Facebook account.


The above method of deception is popular in India, where the fraudsters most often suggest to their victims that money is needed to support the health service fighting the coronavirus.



Lost24

In the issued announcement, PKO BP bank warns its clients against fraudulent emails. Be careful of messages with the subject “Invalid IBAN”.


The sender of the message polisysme@pkobp.pl. In the text of the message, the victim learns that, on behalf of another bank customer, the bank tried to send a transfer that was rejected. In order to receive the payment, the victim is prompted to click on the link confirming the correctness of the attached IBAN number.


The link in the email leads to malware. Clicking on a link may result in loss of money and control of your bank account.



Saturday 8 May 2021, Safety Guide

Fraudsters pretend to be PGNiG

Lost24

Polish Oil Mining and Gas Extraction (PGNiG) warns against fraudulent SMS messages, scammers suggest the need to settle a payment.


Example of the text message: PGNIG: Please be advised that due to debt in the amount of PLN 12.45, we ordered the gas to be disconnected for the next working day.


According to PGNiG, text messages are sent from different phone numbers and should be considered as SPAM. Moreover, PGNiG customers may receive fake emails where the subject of the email concerns information on arrears. The victim, as in the text message, is informed about the debt, which should be settled as soon as possible, using the link to eBOK (the message contains a hyperlink). Fraudulent emails come from no-reply@epgnig.pl, and t

Lost24

Persons who have used Passwordstate’s password manager must be careful as there has been a large data leak.


Hackers placed malicious files inside the application, breaching the security of 29,000 companies and 370,000 employees using Passwordstate.


According to the dobreprogramy portal, the scale of the leak is so huge, because the malicious code planted by hackers on Click Studios’ servers was sent as part of the update. The update was automatic and the malicious code made it possible to download information about the victim’s computers along with passwords from Passwordstate application.


The data leak is serious due to the fact that Passwordstate is used by many of the largest companies in

Sunday 2 May 2021, Safety Guide

Package seized by customs fraud

Lost24

Niebezpiecznik portal warns against text messages about the parcel being detained by the customs services.


The text of the message does not change: “Your package has been seized by the customs services: [LINK]”. However, messages are sent from different numbers and contain different links.


According to Niebezpiecznik, the link redirects you to a website claiming to be a courier company. Clicking on the link leads to the download of a malicious application on your Android device. Cybercriminals have one goal - to steal money from a bank account. According to the portal dobreprogramy, it is probably a FluBot Trojan. The goal of the malware is to hijack passwords and logins to the online banking application. The transaction

Wednesday 28 April 2021, Safety Guide

Fraudsters are impersonating InPost

Lost24

Fraudsters used the image of InPost to create a fake page, demanding payment for a courier delivery.


Potential victims are convinced that InPost branches have been closed to the coronavirus pandemic. The victim is encouraged to pay for the shipping in order to deliver it home by courier, rather than waiting for pickup at an InPost branch.


The scammers inform that after making the payment, the victim will receive an SMS notification along with a courier number. Additionally, we are assured that the package will be delivered within 24 hours.


According to the experts from Threat Labs, fraudsters have created a fake BNP Paribas payment gateway to extort money.



Monday 26 April 2021, Safety Guide

Anti-crisis shield SMS

Lost24

In connection with the new wave of benefits planned by the government the fraudsters decided to use the excuse and execute attacks utilizing so-called anti-crisis shield.


Niebiezpiecznik portal warns against a scam in which scammers try to rob victims of their savings accumulated on a bank account.


Fraudsters send SMS messages that read as follows:
"Sender: Shield You can collect PLN 800 from the anti-crisis shield. To pick up, make a identity confirmation transfer of PLN 1. You will receive the funds within 24 hours. www.urzedy9 [.] net / XXXX ”.


Clicking on the link leads to a fraudulent page with PayU payment gateway. If the login and password are provided, the victim is asked to

Monday 19 April 2021, Safety Guide

Cryptocurrency scam

Lost24

The police from Złotów, Greater Poland Voivodeship, were informed about a cryptocurrency fraud.

A 24-year old man that invested in cryptocurrencies has let down his guard when he was contacted by a “broker”. He was informed that he had earned a considerable amount of money on cryptocurrencies. In order to gain the caller’s trust scammer was stalling the conversation, explaining slowly the operation of the system.

The “broker” requested the victim to provide a credit card number, which was to be necessary to transfer the money earned in the amount of several thousand zlotys to the victim’s account. In the next step, the victim was asked to log into their bank account. At this point, the victim noticed that control of his account h

Thursday 15 April 2021, Safety Guide

Investor fraud - PKN Orlen

Lost24

The Computer Security Incident Response Team of the Polish Financial Supervision Authority (KNF CSIRT) warns against false investments. Fraudsters pretend to be PKN Orlen. Scammers tempt with promises of fast and high earnings, without any risk.


For this purpose, a fraudulent website and a Facebook profile have been created, where an attempt is made to trick users into fake investments in gas and oil trading. There is a “calculator” on the website, which displays the amount of investment we are able to earn.


In order to start the “investment”, you need to register by filling out the application form by providing your personal data, email address and phone number. In the next step, you must confirm the registration by

Friday 9 April 2021, Safety Guide

Scammers target Amazon users

Lost24

Fraudsters took advantage of Amazon’s image to create a website featuring a fake contest. Experts from CERT Orange Poland warn against this form of attack, as the fraudsters want to extort payment card details. For this purpose, they create competitions that tempt users with expensive or unobtainable products.


In this case, in order to win the “Huawei Mate 40 pro 5G Full Netcom 8G + 256 GB” you only had to complete the survey. In addition, in order to spread the bogus website, a requirement was introduced to share the contest with 20 friends via WhatsApp messenger. After sharing the competition with the given number of friends you had to provide the payment card details in order to cover the shipping fee.


It is known th

Thursday 8 April 2021, Safety Guide

Vaccines in the darknet - COVID-19

Lost24

At the beginning of the coronavirus pandemic, we wrote about the ways how the current situation can be abused by criminals. Since the emergence of COVID-19 vaccines, the black market of the so-called darknet was filled with offers to buy preparations from such producers as AstraZeneca, Sputnik, Sinopharm and Johnson & Johnson.


The cost of the vaccine ranges from PLN 1,900 to PLN 2,900. According to the portal dobreprogramy, if you buy two doses of the vaccine, the buyer can qualify for a promotional offer where the next preparation is free. In urgent cases, criminals deliver the order on the next day. Additionally, you can buy a virus vaccination certificate for less than PLN 580.


CheckPoint experts have seen a large

Thursday 1 April 2021, Safety Guide

A new method of scam on OLX

Lost24

The attack on users of OLX classifieds portal that we wrote about recently has been modified, possibly due to the spread of the described scam scheme on the web.


The Computer Security Incident Response Team of the Polish Financial Supervision Authority noticed that scammers on OLX are trying new methods, aimed at one thing - extorting money.


Until now, the attack consisted in sending the seller on OLX a link to a fraudulent website pretending to be OLX or a courier company in order to accept the receipt of money for the purchased item. On the website, the seller is asked to provide payment card details, there is also a request to provide credentials to the bank account, personal data such as PESEL number, mother’s maiden na

Lost24

Niebezpiecznik portal warns against the growing wave of attacks targeting OLX users. Niebezpiecznik claims that the problem has grown to a scale that has not yet been seen on the Polish Internet.


The attack is based on pretending to be a buyer and obtaining the payment card number from the seller along with other data under the pretext of receiving payment for the purchased product.


Scammers communicate with the buyer via OLX or ask for an email address to which they send a fake message pretending to be the classified ad service. There is also an option to call back via WhatsApp messenger if the seller has provided a phone number in the listing.


In the next step, scammers send a link to the fake we