Phishing: Difference between revisions

From xat wiki
m (hyperlinked 'terms of service')
No edit summary
(14 intermediate revisions by 7 users not shown)
Line 3: Line 3:
<translate>
<translate>
<!--T:1-->
<!--T:1-->
Have you ever been in a situation where you log into your account, only to find out that some of your xats, days and/or powers are missing? Do you suspect that an unauthorized user may have attempted to compromise your account and succeeded? You might be a victim of what we call "phishing."
Phishing is a fraudulent attempt to steal personal information, such as your e-mail address and password. On xat, you might encounter users who try to steal your e-mail address, password, xats, days, powers, and sometimes, your identity. Protect yourself whenever using xat by knowing how to recognize phishing attempts so you can report and not fall for phishing tricks.


==What is phishing?== <!--T:2-->
==Common phishing tricks== <!--T:2-->
 
</translate><span id="commontricks"></span><translate>


<!--T:3-->
<!--T:3-->
Phishing is a trick used by criminals to steal personally identifiable information, such as your e-mail address and password. It is not a security flaw and you are not getting hacked. As long as you know what to look for, you can prevent yourself from being phished. You've probably been warned before by your online bank about phishing websites, but most users don't think or worry about being phished when using their xat account. On xat, there are criminals who want to steal your e-mail address, password, xats, days, powers, and most of all, your identity.
* Linking a page that looks exactly the same or similar to xat's registered user account management page.
* Convincing users to click on a link by offering free xats, days, and/or powers.
* An urgent request for personal information: passwords, e-mail address etc.
* A message requiring immediate action to avoid a problem like losing access to your xat account or your account being deleted.
* Asking to download a third party program called ".sol Editor" and to provide the "Value" that's located above the category "Number."
* Impersonating administrators or [[<tvar|1>Special:MyLanguage/Volunteers</>|volunteers]] in an attempt to collect information or purchased items.  
 
'''NOTE:''' NEVER click on suspicious links/downloads or provide any personal information to unknown users.
 
==Tips for spotting a phishing e-mail== <!--T:4-->


==How does the scam work?== <!--T:4-->
</translate><span id="spotphishing"></span><translate>


<!--T:5-->
<!--T:5-->
A criminal will start off by creating a page that looks exactly the same as xat's registered user account management page. Then, the criminal will create a link (which will redirect to the page) and come up with a convincing way to lure a user into clicking on the link. An example might be offering xats, days and/or powers for free, as long as you click on the link and enter your e-mail address and password into the text box provided. That is definitely a {{Color|#FF0000|'''red flag'''}}. Under NO circumstances should you ever click on the link, nor should you enter your e-mail address and password, regardless of whether it's free. Just by clicking on the link itself, the criminal may already have your IP address.
* Always look at the 'from' e-mail address, and ensure it isn't suspicious. Even the e-mail can sometimes be spoofed.
* Scammers often attempt to make the e-mail look as legitimate as possible by including a logo or professional name such as "Account Support."
* Hover over links in an e-mail before clicking on them. The link could direct you to a suspicious address completely unrelated to the text in the link.
* Never open or download anything unless you are sure they come from a safe source.


<!--T:6-->
==Protecting yourself== <!--T:6-->
'''NOTE:''' If you come across a page that asks you for the password that's associated with your e-mail address (not your account), it's a phishing website. xat will NEVER ask you for that under any circumstances. Also, do NOT use the same password for any other e-mail addresses or accounts you may have, even if it has nothing to do with xat. You're only increasing your chances of other accounts you have getting compromised.


<!--T:8-->
</translate><span id="protectyourself"></span><translate>
Besides creating a duplicate page, there is also another way that criminals are using to steal personally identifiable information from users. What they're doing is either asking users for their flash shared object file, or asking users to download a third party program on their computer called ".sol Editor" and wanting users to provide them the "Value" that's located above the category "Number." Under NO circumstances should you provide them the value that's associated with your account. Giving them the value is just like giving them the password and you will end up being phished.
 
==How can I protect myself?== <!--T:9-->


<!--T:31-->
<!--T:31-->
In order to prevent yourself from getting phished by a criminal, we highly recommend you follow these precautionary steps:
To prevent yourself from getting phished by a criminal, we recommend the following:


<!--T:32-->
<!--T:32-->
'''Step #01:''' When you're logging into your account, ALWAYS make sure you're on xat's registered user account management [http://xat.com/web_gear/chat/register.php page]. You can find out if you're on the correct page by looking at the URL bar, which is located at the top-left corner of your web browser. If the link shows '''http://xat.com/web_gear/chat/register.php''', you're on the correct page. If it shows anything other than the link provided, do NOT enter your e-mail address or registered username and password on that page. Leave the page immediately and report the phishing website by submitting a [http://util.xat.com/support/open.php ticket] under the category "Report Phishing Site." You do not need to be a paid user to submit a ticket in this department.
*Consider reading the [[<tvar|3>Special:MyLanguage/Password</>|Password]] wiki article for tips on creating a strong password. Do NOT use the same password for any other e-mail addresses or accounts you may have, even if it has nothing to do with xat. You're only increasing your chances of other accounts you have from being compromised.
*ALWAYS make sure that you are on xat's registered user account management page by looking at the URL bar. The link should appear as https://xat.com/web_gear/chat/register.php or https://xat.com/login.
*Enable xat's account security features: [[<tvar|1>Special:MyLanguage/Account protection</>|Account Protection]] and [[<tvar|2>Special:MyLanguage/Account_Protection#Account_Locking</>|Account Locking]].
 
==How to report phishing== <!--T:20-->
 
</translate><span id="reportphishing"></span><translate>


<!--T:33-->
<!--T:33-->
'''Step #02:''' When you're logging into your account, you have the option of either entering the e-mail address that's associated with your account, or your registered username. When it comes to entering your password, ALWAYS make sure it's the password that's associated with your account and not your e-mail address. xat will NEVER ask you for the password that's associated with your e-mail address under any circumstances. In order to ensure your account is fully protected, use a password that isn't the same password as your e-mail address. Also, make sure your password is alphanumeric, which consists of both letters and numbers (but not symbols). Be sure to make it so it's easy for you to figure out, but hard for a criminal to figure out. As long as it contains at least 10 characters (or more), you will be fine. Don't make your password too long or you might forget it. We highly recommend you avoid using patterns or words in your password and always change your password on a monthly basis. It's better to be safe than sorry.
If you think you may be a victim of phishing or an unauthorized user may have compromised your account, change the password to not only your account, but your e-mail address as well.


<!--T:34-->
<!--T:34-->
'''Step #03:''' When it comes to fully protecting your account, we highly recommend you enable the following features: Account Protection, Account Locking and Account Authentication. For more information regarding Account Protection, click '''[[Account_Protection|here]]'''. For more information regarding Account Locking, click '''[[Account_Protection#Account_Locking|here]]'''. For more information regarding Account Authentication, click '''[[Authentication|here]]'''.
To report a phishing website, submit a [https://util.xat.com/support/open.php ticket] under the "Report Phishing Site" help topic. Provide proof about the occurrence, such as the date and time of when you went on the phishing website. The sooner you report the phishing website, the faster the phishing website will be shut down.
 
==What do I do if I think I've been phished?== <!--T:20-->


<!--T:35-->
<!--T:35-->
If you suspect that an unauthorized user may have compromised your account, do NOT panic. It will only make the situation much worse than it needs to be. The first thing you need to do is change the password to not only your account, but your e-mail address as well, for extra security measures. Also, if you remember the link of the phishing website you were on, report the phishing website as soon as possible by submitting a [http://util.xat.com/support/open.php ticket] under the category "Report Phishing Site" and provide as much sufficient proof about the occurrence as you can, such as the date and time of when you went on the phishing website and the date and time of when you got phished. The sooner you report the phishing website, the faster the phishing website will be shut down. Under NO circumstances should you EVER log into another user's account, even if you've been granted permission to. You will be in direct violation of xat's [http://xat.com/terms.html Terms of Service]. Failure to comply with xat's terms of service will result in your account being torched and/or deleted.
NEVER log into another user's account, even if you've been granted permission to. You will be in direct violation of xat's [<tvar|1>https://xat.com/terms</> Terms of Service]. Failure to follow xat's terms of service will result in your account being torched and/or deleted.


</translate>
</translate>


{{Category|Security}}
{{Category|Security}}

Revision as of 02:26, 5 June 2019

Phishing is a fraudulent attempt to steal personal information, such as your e-mail address and password. On xat, you might encounter users who try to steal your e-mail address, password, xats, days, powers, and sometimes, your identity. Protect yourself whenever using xat by knowing how to recognize phishing attempts so you can report and not fall for phishing tricks.

Common phishing tricks

  • Linking a page that looks exactly the same or similar to xat's registered user account management page.
  • Convincing users to click on a link by offering free xats, days, and/or powers.
  • An urgent request for personal information: passwords, e-mail address etc.
  • A message requiring immediate action to avoid a problem like losing access to your xat account or your account being deleted.
  • Asking to download a third party program called ".sol Editor" and to provide the "Value" that's located above the category "Number."
  • Impersonating administrators or volunteers in an attempt to collect information or purchased items.

NOTE: NEVER click on suspicious links/downloads or provide any personal information to unknown users.

Tips for spotting a phishing e-mail

  • Always look at the 'from' e-mail address, and ensure it isn't suspicious. Even the e-mail can sometimes be spoofed.
  • Scammers often attempt to make the e-mail look as legitimate as possible by including a logo or professional name such as "Account Support."
  • Hover over links in an e-mail before clicking on them. The link could direct you to a suspicious address completely unrelated to the text in the link.
  • Never open or download anything unless you are sure they come from a safe source.

Protecting yourself

To prevent yourself from getting phished by a criminal, we recommend the following:

  • Consider reading the Password wiki article for tips on creating a strong password. Do NOT use the same password for any other e-mail addresses or accounts you may have, even if it has nothing to do with xat. You're only increasing your chances of other accounts you have from being compromised.
  • ALWAYS make sure that you are on xat's registered user account management page by looking at the URL bar. The link should appear as https://xat.com/web_gear/chat/register.php or https://xat.com/login.
  • Enable xat's account security features: Account Protection and Account Locking.

How to report phishing

If you think you may be a victim of phishing or an unauthorized user may have compromised your account, change the password to not only your account, but your e-mail address as well.

To report a phishing website, submit a ticket under the "Report Phishing Site" help topic. Provide proof about the occurrence, such as the date and time of when you went on the phishing website. The sooner you report the phishing website, the faster the phishing website will be shut down.

NEVER log into another user's account, even if you've been granted permission to. You will be in direct violation of xat's Terms of Service. Failure to follow xat's terms of service will result in your account being torched and/or deleted.