Email Scam Targets Netflix, AOL, Comcast Users

Be skeptical of any email warning you that your Netflix, AOL or Comcast account has been "suspended due to suspicious activity" — it might be part of a new email scam making the rounds.

The scam tries to scare you into paying hundreds of dollars for customer support you don't actually need, according to anti-malware consumer software company Malwarebytes.

MORE:9 Tips to Stay Safe on Public Wi-Fi

These emails contain links to websites designed to look like a valid login page. However, if you try to log in to these fake pages, you'll not only be giving cybercriminals your username and password; you'll also be redirected to a scary-looking error page, where the cybercriminals will try to sell you hundreds of dollars of "customer support."

This type of scam, known as "phishing," uses disguises and scare tactics to trick users into visiting bad websites and divulging their passwords, credit card numbers and other sensitive information. Malwarebytes has seen this particular phishing scam disguised as emails from Netflix, AOL, Pogo, Comcast and CenturyLink.

In addition to email, the scam has been seen in pop-up ads that either specify one of these services or merely claim that "your email account has been temporarily suspended."

"We suspect crooks are buying online ads for each brand and redirecting people to fake login pages, which, upon authentication, always fails," Malwarebytes security experts wrote in their blog post.

If you click on these pop-ups or the links in the emails, you'll be taken to an official-looking website. But one glance at the URL should be enough to tell you that you're not in the right place. For example, fake AOL websites will have URLs such as "aolrisk.com" and "aolfix.us."

"It's worth noting the extra effort to register domain names ... which are not affiliated with AOL whatsoever but yet sound reasonably credible," Malwarebytes noted in its blog post.

On these fake sites, you'll first be asked to enter your username and password. If you do so, you'll pass on that information to the cybercriminals behind the scam. The website will pretend to try to log you in, but it will then redirect you to an error page claiming that you need to call customer support. You'll see a telephone number and even a live chat manned by the scammers.

Masquerading as customer-support employees, the scammers will tell you over phone or Web chat that someone has hacked into your account, and they will try to sell you expensive support packages. Malwarebytes recorded a video of one such fraudulent phone call, in which one of the scammers told the Malwarebytes researcher (posing as a customer) that his computer was infested with malware.

Malwarebytes had previously identified the scam when it was targeting only Netflix users back in February. At that time, the criminals were also trying to get their victims to install software that they claimed would help them fix the "problems," but would actually upload all the computer's personal files to the criminals' servers.

You should always be skeptical of links in emails and exercise caution before clicking on them. For password reset emails or other login notifications, it's best to go to the supposedly affected website directly instead of using an embedded link.

Email jscharr@techmedianetwork.comor follow her@JillScharrandGoogle+. Follow us@TomsGuide, onFacebookand onGoogle+.

●     13 Security and Privacy Tips for the Truly Paranoid

●     10 Simple Tips to Avoid Identity Theft

●     Top 10 Apps for Remembering Your Passwords

TOPICS

Jill Scharr is a creative writer and narrative designer in the videogame industry. She's currently Project Lead Writer at the games studio Harebrained Schemes, and has also worked at Bungie. Prior to that she worked as a Staff Writer for Tom's Guide, covering video games, online security, 3D printing and tech innovation among many subjects. 

Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Latest in News
Apple Watch Series 10
Future Apple Watch models could get a surprising new feature — what we know
NYTimes Connections
NYT Connections today hints and answers — Monday, March 24 (#652)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #386 (Monday, March 24 2025)
iPhone 16 Pro vs iPhone 16 Pro Max in hand showing displays
Forget iPhone 17 — iPhone 18 could get this huge upgrade
The new Husqvarna iQ series robot lawn mower.
Husqvarna’s new robot mowers offer GPS for less
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
  • HiTechObsessed
    The '...Has been Temporary Suspended...' should be a red flag lol

    I swear, if you're going to scam, at least use correct grammar.
    Reply
  • irish_adam
    If your stupid enough to click such links and input your details then you deserved to be robbed.
    Reply
  • ddpruitt
    I'm actually kind of impressed that they used the event logs and hide their message while running tree to do this. They've put some effort into making it look real. Sounds like someone's really put some effort into this, I can't imagine how many people this would catch.

    On the other hand they did miss that this was system with a fresh install.
    Reply