Thursday 9 July 2020, Poradnik bezpieczeństwa

Scammers utilize Allegro brand

Lost24

Cybercriminals are trying to extort money by impersonating Allegro, the victim may also lose login credentials for the portal.


According to the Zaufana Trzecia Strona, the victim receives a message informing that the account needs to be verified and for this purpose the account should be activated using the online payment in the amount of PLN 1.01. In addition, the recipient of the message is assured that the entire amount will be returned to the account within 3 business days, once the registration data has been verified. According to the Zaufana Trzecia Strona, the sender is admin@allegro4.pl, and the amount of  PLN 1.01 is based on the amount used in the actual Allegro account activation process.


The activation link included in the message leads to the following website: https://allegro4./login/auth.php, https://allegro5.pl/login/auth.php. Both lead to the fake Allegro login page, once the data is provided the victim is redirected to the fraudulent quick payment panel and at this point red lamp should light up because the url is unusual https://allegrofinanse2.pl/MYNKgeHn/hz6hZnA. The rest of the campaign is impeccable.