Phishing Scam Spreading on Twitter
A few minutes ago, I received a direct message from one of my twitter followers:
hey! check out this funny blog about you… jannawalitax . blogspot . com
And there’s another one:
Hey, i found a website with your pic on it… LOL check it out here twitterblog . access-logins . com / login
DO NOT VISIT the URL in question. It will redirect you immediately to a suspicious domain: twitter . access-logins . com – notice the subdomain? Worse yet, here’s what you’d see there right now:

This is NOT the Twitter login page, and it smells completely phishy! Suggestion: do NOT log in to your Twitter account through any site other than Twitter.com. This may go without saying, but consider how many third-party Twitter services you use? Seems it’s about time for some kind of verification / validation for applications using the Twitter API – so you can be sure you’re passing your credentials to the right people. I’m guessing this particular phishing scam is not using the API (but there’s no way for a user to properly verify).
This phishing domain appears to be registered in China, and I’m about to report ‘em to OpenDNS (via PhishTank.com):
Organization : zhang xiaohu
Name : zhang xiaohu
Address : changningzhonghuainanlu192hao
City : changning
Province/State : Hunan
Country : CN
Postal Code : 421500
Please, tell your followers to NOT VISIT or LOGIN THROUGH that site! Watch out for these direct messages. If you did happen to visit one of the offending URLs, you should be safe so long as you didn’t try to log into your Twitter account there.









83 Comments
dede
January 3rd, 2009
at 3:22pm
so, how did you mange to find out that the scam was in china and wouldn’t windows users have some sort of phishing filter???
Kevin
January 3rd, 2009
at 3:22pm
Thanks for that warning, Chris!
Greets from Germany
Kevin
Schmot Guy
January 3rd, 2009
at 3:25pm
It’s a bad thing. But what does the API have to do with it?
Karl Long
January 3rd, 2009
at 3:26pm
Yep, I had the same message and reported it to my network: http://twitter.com/karllong/status/1094163038
I think Twitter is in danger of getting crushed by MLM spammers, I wrote this up last month:
http://experiencecurve.com/archives/why-mlm-will-kill-twitter-hint-because-they-have-a-business-model
K
Maggie
January 3rd, 2009
at 3:37pm
And add these things to http://www.phishtank.com/ so that people (smartly) using OpenDNS can avoid it altogether.
Chris
January 3rd, 2009
at 3:37pm
Everyone reading this should visit this site in Firefox, and then click Help > Report Web Forgery. Soon the phishing block list will be updated so unsuspecting users will be warned of the danger.
James Savage
January 3rd, 2009
at 3:38pm
To me it is facebook so people should watch out for similar facebook scams too I guess. (screen shot as proof http://i43.tinypic.com/23vm3if.png)
Hans
January 3rd, 2009
at 3:40pm
yet another reason to use 1Password! :-) Have been using it for over 1 year and am still really happy with it!
Anatolie Diordita
January 3rd, 2009
at 3:43pm
Thanks for the warning, and be sure to report em to OpenDNS, also DO NOT VISIT access-logins . com — IT TAKES YOU TO A FAKE FACEBOOK PAGE; YES!! FACEBOOK!
SnowWrite
January 3rd, 2009
at 3:45pm
Thank you for the warning Chris!
Raymond T. Hightower
January 3rd, 2009
at 3:46pm
@SchmotGuy, in this case the phishers use the Twitter API to pass the login credentials along to the real Twitter.com. The user ends up logged on to their legitimate Twitter account, but the phisher/middle-man copies username & password in the process. The victim’s only clue is the fake URL shown in Perillo’s screenshot (above).
Saad Kamal
January 3rd, 2009
at 3:46pm
Thanks for the info :)
Best way to avoid these kind of situation is to not ‘follow’ everyone! Its just pointless as there is no way you can ‘really follow’ every single one of them..It just causes an information overload and makes this ‘useful service’ not so useful anymore..
If you are not following that person, he shouldn’t be able to send you a DM….Right? So if you follow people carefully, you can actually control how much ’spam’ you get.
Following everyone is like ..giving away your home address to everyone you meet so that they can send you Junk.
If someone has anything important to say to you, they should be able to send you a Public Msg – e.g. @username hay I need to talk to you.
And then you can probably DM him your Email or just follow him for exchanging DMs.
Wendi Dee
January 3rd, 2009
at 3:52pm
Thanks so much for alerting us, and for responding to my questions on behalf of friends who clicked on the link.
*blows kisses*
Lots of love to you,
Wendi
XOXOXO
lilxkid24
January 3rd, 2009
at 3:55pm
whats the point of these hackers seriously they need a life…..
Joshua
January 3rd, 2009
at 3:55pm
It now leads to a Facebook mock up. Odd change…
1Password still prevents you from giving your information, and I would suggest that people start using Password Managers to avoid crap like this
Brent
January 3rd, 2009
at 3:57pm
I completely agree with the comment by @Hans. I use 1password every day and it will catch things like this if you use the service. It is great for generating and storing your strong passwords and will let you know if you are visiting a site that is not the ligit log in site for http://Twitter.com. I would also suggest that users change their default DNS server setting to OpenDNS. OpenDNS will also let you block phishing, and other material that you do now want on your local machine or entire network.
Two Geeks and a Blog :: Geek News :: Phishing Scam on Twitter. Seriously?
January 3rd, 2009
at 4:01pm
[...] is quickly spreading that there’s a phishing scam spreading on Twitter. Really, spammers? Twitter? Sure, Twitter is awesome and going mainstream but I’d hazard a [...]
Matt
January 3rd, 2009
at 4:03pm
You’d have to be a dumbass to click that link, a link to Blogspot, and then not notice you’ve been sent to Twitter. There’s no logical correlation between clicking a blogspot post, one that’s not even shortened even, and going to the Twitter homepage. This isn’t a big deal.
Phishing Scam Spreading on Twitter « POLITISITE: Politics from the RIGHT Side of the WEB
January 3rd, 2009
at 4:04pm
[...] NOT VISIT the URL in question. It will redirect you immediately to a suspicious domain: twitter . access-logins . com – notice the subdomain? Worse yet, here’s what you’d see there [...]
Phishing Scam Spreading on Twitter « Iron Mill News Service
January 3rd, 2009
at 4:05pm
[...] NOT VISIT the URL in question. It will redirect you immediately to a suspicious domain: twitter . access-logins . com – notice the subdomain? Worse yet, here’s what you’d see there [...]
LizA
January 3rd, 2009
at 4:10pm
Seems Twitter’s pretty quick on the ball: http://status.twitter.com/post/68196572/dont-click-that-link
halwebguy
January 3rd, 2009
at 4:14pm
Here’s the question of the day. Who thinks it’s a good idea to log in everywhere with your twitter credentials? This is kind of like facebook connect, no? In this case they’re faking that you’re on the Twitter site, so this does not really apply, but it amazes me how trusting the Twittersphere is.
Anon
January 3rd, 2009
at 4:20pm
nmap says its doing lots of things
PORT STATE SERVICE VERSION
21/tcp open ftp Muddleftpd
22/tcp open ssh OpenSSH 3.9p1 (protocol 1.99)
25/tcp open smtp Postfix smtpd
53/tcp open domain ISC BIND 9.2.4
80/tcp open http Apache httpd 1.3.33 ((Unix) Resin/2.1.14 mod_throttle/3.1.2)
110/tcp open pop3 Courier pop3d
135/tcp filtered msrpc
139/tcp filtered netbios-ssn
445/tcp filtered microsoft-ds
593/tcp filtered http-rpc-epmap
3306/tcp open mysql MySQL (unauthorized)
4444/tcp filtered krb524
OS guesses: Linux 2.6.9 – 2.6.11
Schmot Guy
January 3rd, 2009
at 4:22pm
@Ray I get that. But why is that Twitter’s fault? It’s a man-in-the-middle attack, nothing in particular about Twitter’s API being the problem per se. This is the downside of an open system. I’d rather have the open system.
Twitter Users: Direct Message Blog Link Tries to Steal Your Password
January 3rd, 2009
at 4:27pm
[...] Twitter Users: Direct Message Blog Link Tries to Steal Your Password Saturday, January 3, 2009 A dangerous phishing exploit is currently making its way around Twitter, so be careful which links you choose to click. Tech blogger Chris Pirillo describes the exploit in “Phishing Scam Spreading on Twitter”. [...]
Albert Miliron
January 3rd, 2009
at 4:32pm
just added your story to Nowpublic.com tech and biz section with a link back here. Thanks for the heads up
Djdez92
January 3rd, 2009
at 4:35pm
Thanks for the warning because i’m always the first one to open spam links… I feel safe now !
Orinthe
January 3rd, 2009
at 4:52pm
API has nothing to do with it… Even it does in fact use the API to do this (how do you know? Is it done via ajax right in the page?), there is NOTHING to stop them from just logging in the same way users do normally and returning information via screen-scraping or putting it in an iframe, etc. The fact is that if you have any sort of public-facing interface to a service it is vulnerable to this type of attack. Banks don’t have a twitter-style API, but they get phishing scams like this targeted at them, too. Inform, report, implement optional white/blacklists, etc., but don’t mistakenly blame the API!
BEWARE: Twitter Scam Emerges! [Briefly] | RazorianFly
January 3rd, 2009
at 5:03pm
[...] their Twitter account password immediately. For more information of the unfolding shenanigans visit Chris Prillo. You can also follow hash tags #phishing, #DMs, #scam and [...]
Financial Market Help
January 3rd, 2009
at 5:15pm
Hey thanks for the heads up!
I’m trying to spread your message around on tweeter!
Eddie Ringle
January 3rd, 2009
at 5:26pm
I’ve tweeted about this and it also inspired a blog post on my opinions on 3rd party apps and how they should be open source, so everybody wins! :)
tweetip
January 3rd, 2009
at 5:31pm
Twitter Phishing ~ 1st Tweets Timeline/Chart… http://tweetip.us/lkto7
Tom
January 3rd, 2009
at 5:34pm
This is already blocked in Firefox 3, I get a big Attack Site! warning.
Richard Drumm The Astronomy Bum
January 3rd, 2009
at 6:00pm
Sounds rather like the “fanebook” scam that I encountered last summer. I went to their site knowing all along that it was a fake just to see what was there. I put in all kinds of fake stuff in the fields instead of my real info. Usernames like F***YOU and passwords like eatsh**anddie, you get the idea. It probably didn’t slow them down for a moment, but it was satisfying to stick it to them in a small way.
M. LaRonde
January 3rd, 2009
at 6:21pm
Thanks for the heads up on this very important topic Chris.
M. LaRonde
J. D. Ebberly
January 3rd, 2009
at 6:34pm
Thanks for this timely article, Chris. Love your blog – I read it often. Great work.
Strong One
January 3rd, 2009
at 6:42pm
STRONG WORK. Thanks for the heads up!
Phishing on Twitter : Scott’s Morning Brew
January 3rd, 2009
at 6:45pm
[...] See his article here. [...]
Geno Prussakov
January 3rd, 2009
at 7:16pm
My advice (not only for this situation): do not click anything unless it’s coming from someone you personally know, or better yet, unless you’re expecting a link from someone you personally know. In doubt, double-check with the sender if the link is safe to click. This is only if you know the sender personally.
In the latest instances with Twitter, people are doing precisely the opposite – clicking links sent to them by complete strangers. Easy phishing prey.
Amanda
January 3rd, 2009
at 7:16pm
Thanks for this. I did get that DM.
Robby G
January 3rd, 2009
at 7:30pm
Good to know thanks. Just posted this link for my twitter followers to read. Bah, can’t trust anyone in this life…
Ro
January 3rd, 2009
at 7:38pm
Thanks for the heads up. The more people watching out for things like this the better.
Mashable, CNET, Chris Pirillo Warn of Urgent Twitter Phishing Scam | Twitter Statistics | Twitter Attraction
January 3rd, 2009
at 7:39pm
[...] Chris Pirillo took the time to track down the phishing domain and has reported them to OpenDNS via PhishTank.com. Not sure what this will do but it’s nice to know Chris is taking action for all of us! [...]
Twitter Phishing Scam | South Florida Web Marketing Blog
January 3rd, 2009
at 7:47pm
[...] Phishing Scam Spreading on Twitter From Chris Pirillo Saturday, January 3rd, 2009 at 3:15pm [...]
ModernGearTVTamara
January 3rd, 2009
at 8:01pm
Thank you for posting this…I got a similar sort of a message from a few Facebook friends – is this the same sort of thing?
Twitter Follow Notification URLs in Email [Phishing Scam Update]
January 3rd, 2009
at 8:11pm
[...] Chris Pirillo detailed the phishing scam on his blog earlier today… He received this DM from a phishing accout: hey! check out this funny blog about you… jannawalitax . blogspot . com [...]
Phishing Virus hits Twitter
January 3rd, 2009
at 9:33pm
[...] screen shot caputured by Chris Prillo) Tags: phishing, Security, Twitter, [...]
jd
January 3rd, 2009
at 10:20pm
I went to the link, typed some bogus stuff, and got redirected to my already authenticated twitter account. Feel free to flood them with bogus info, their domain has no access to your cookies.
Bob
January 3rd, 2009
at 10:34pm
Yeah, it’s the same thing that has been hitting people on Facebook. It’s 2009, and users will click on anything. Still.
Douglas Sowash
January 3rd, 2009
at 11:10pm
Twitter has lots of spam who still uses it seriosuly?
I don’t use it anymore – I frequent a Porn forum and some spammers got my twitter information and started pouding me with messages and follow requests asking me to buy some sort of sick twitsted products.
Syber News » Phishing Scam Hits Twitter
January 4th, 2009
at 12:43am
[...] get the direct message in question, you’ll get a message like the following, which Chris Pirillo received.hey! check out this funny blog about you… jannawalitax . blogspot . comGo to that URL, and you [...]
Thor Erik
January 4th, 2009
at 3:33am
It appears that the twitter community defeated the site, now it’s a facebook fishing site, time to spread this on facebook?
links for 2009-01-04 at adam hoyle presents suckmypixel
January 4th, 2009
at 4:30am
[...] Phishing Scam Spreading on Twitter | Chris Pirillo (tags: twitter security phishing) [...]
Jay
January 4th, 2009
at 4:48am
Thank you for saying this aloud. Recently, i get more tweet from unknow twitter accounts. I wonder if there is any way to filter those out (some of those accounts are already suspended). But at the same time, i do not wish Twitter to become the monitoring dog for every tweets
Kash78
January 4th, 2009
at 5:39am
This is annoying! Just RT your tweet & http://twitter.com/karllong/status/1094163038 to my followers.
Thank you.
http://twitter.com/kash78
helruna
January 4th, 2009
at 5:40am
Thanks for this.. seen other twits but no explanation!
ilaxi
January 4th, 2009
at 6:20am
I guess even websites are affected due to Twitter …My site bg was changed and I found this:
http://s3.amazonaws.com/twitter_production/profile_background_images/3080822/tweetila.jpg
click just : http://s3.amazonaws.com/twitter_production/ and you find rss feeds? amazon hacks???
I could change main bgs but some pages I updated yet the bg remains!
Is this some promotion gimmick of amazon developer? the url leads to theirs!
Confused me!!!
Betsy Devine
January 4th, 2009
at 7:19am
A different Twitter scam? I have started getting email that (some random computer-generated name) is following me–when I click through to that “person’s” Twitter page they are following not even one Twitter person other than Betsythedevine, e.g. http://twitter.com/gilywu Awww, I feel so special. But wtf is that about?
Danielle Hatfield
January 4th, 2009
at 7:34am
Thanks for the heads up Chris!
Phishing scam hits Twitter
January 4th, 2009
at 8:30am
[...] blogger Chris Pirillo reports that the web site is registered in China while the company does acknowledge that a phishing scene is active on the micro-blogging [...]
Webdesi3
January 4th, 2009
at 10:37am
Thanks for the heads up!
This is nuts, can’t believe people get away with this!
» WARNING: Phishing Scam Spreading on Twitter | Office of Information Technology Blog
January 4th, 2009
at 11:25am
[...] Read the rest of the post [...]
Mom On The Run
January 4th, 2009
at 11:32am
I got one of those DM’s today. Thankfully FireFox 3 warned me that it was a phishing site. Yet another reason to use FireFox!
Martin Newham
January 4th, 2009
at 12:50pm
Chris; thanks for the warning, but its unfortunate that the message appears as a DM – a “secured message: so to speak. The link could also be disguised within a tinyurl (or similar) link hiding the destination completely.
I think its wise not to type in passwords whenever you’re presented with a login screen; as you’ve shown. Always verify the site you are connecting with – if it looks suspicious close it, if in doubt contact the person that sent you the DM.
Tourtraining
January 4th, 2009
at 1:18pm
I am a victim of the phishing DM’s and they are now using my twitter name. I unfortunately logged-in to the phishing and now they sending out DM’s from ‘me’. I have sent out two messages to my contacts and sent back responses to those that have contacted me NOT LOGIN. I have also changed my password. I just want you to know I’m not doing it!
It’s easy to get caught. I received an email and wasn’t logged into Twitter at the time. It seemed okay to login. I am so, so sorry now.
Bwana
January 4th, 2009
at 1:45pm
And now, there’s yet another variant. Twitter’s officially a phishing pool: http://www.bwana.org/2009/01/04/twitter-phishing-exploits-are-here-a-new-variant/
Jeff
January 4th, 2009
at 5:53pm
Lol, I went to that website a while ago and when I clicked on the Twitter header there, it led me to the fake Facebook!
Darius A Monsef IV
January 4th, 2009
at 6:07pm
Maybe I missed an update on this problem being fixed recently by Twitter… but considering I just got a DM with the phishing URL, I think it hasn’t been taken care of.
All twitter needs to do is to add a line of code on the DM form page that checks for blacklisted words, urls, etc. in the message.
For example, if the message trying to be sent includes “access-logins.com” either:
A. Don’t send the message at all and alert the user that the message contained malicious content.
OR
B. Send the message but strip the string and replace it with “malicious content removed.”
*They can also continue to add blacklisted words and urls to this filter over time.
Eric Gonzalez
January 4th, 2009
at 7:13pm
Just checked out the link, and it appears to mimic facebook now.
Geno Prussakov
January 4th, 2009
at 8:00pm
I have just received my first spammy Twitter DM from *someone I know*! Apparently, the situation is more complex than I thought. Stay alert, folks!! Refrain from clicking on *any* DM links (even if the message came from a trusted contact/follower). Double-check with the sender first.
Log Into Twitter And Change Your Password | chrisbrogan.com
January 4th, 2009
at 10:03pm
[...] Here’s why. (amended to please Steve Garfield) [...]
scott
January 4th, 2009
at 10:12pm
What do you do if you were drunk on Saturday night and filled in your information?
Tara Kelly
January 5th, 2009
at 3:11am
Exactly why you need a password manager folks. If you get suckered into giving your twitter password away — at least it’s not the same one you use everywhere else too.
http://tinyurl.com/online-vs-offline-pwd-managers
Choose and use a password manager please (and tell your friends to do the same).
Network Security Blog » Four information points on Twitter phishing
January 5th, 2009
at 8:22am
[...] Phishing Scam spreading on Twitter – This was the first article I read on the Twitter Phishing this weekend. [...]
Phishing scam spreading on Twitter. | Hello (a blog from Stratepedia)
January 5th, 2009
at 11:14am
[...] Chris Pirillo) By Aaron | January 5th, [...]
Got Hacked?
January 5th, 2009
at 11:54am
[...] the phishing scam via Direct Message, as reported by many including Read Write Web, Mashable, and Chris Pirillo. The victims include Twitter accounts for Barack Obama, Fox News, Britney Spears, and Rick [...]
Twitter Gets Hacked (Twice!) | housley.me
January 5th, 2009
at 3:11pm
[...] know. Chris Brogan posted a warning asking all bloggers to change their passwords, which links to a post from Chris Pirillo that describe a number of rogue direct messages with links to a fake Twitter login [...]
Twitter hit by phishing : Snug’d
January 5th, 2009
at 4:37pm
[...] Twitter users were lured into giving away their passwords in a phishing attack. If you receive an email notification that takes you to any site similar to Twitter look at the URL [...]
Vorsicht: Twitter phishing | Uhl & Friends – The Media and Marketing Company
January 5th, 2009
at 5:46pm
[...] einen Tweet von Chris Brogan wurde ich auf folgenden Erfahrungsbericht “Phishing Scam Spreading on Twitter” von Chris Pirillo aufmerksam. Er schreibt über die ersten Versuche des Phisings bei [...]
Internet Evolution - Security Clan Editor's Blog - Twitter Tweaks Tweet Security
January 7th, 2009
at 10:51am
[...] large enough and sufficiently integrated into users’ daily online routine to draw the attention of phishers and hackers, who’ve launched apparently unrelated attacks on the micro-blogging site in the last [...]
Dick Tracey
May 4th, 2009
at 12:23pm
I often check out DNS records to see where phishing attacks and spam are coming from. Been doing this for at least 10 years now. China is behind most of it and send phishing emails daily. (I get hundreds per day)
Nothing is ever done to stop them and I doubt authorities here can or will do anything about it because as you know just about every product we use in North America comes from China. (smallwares)
The solutions are really fairly simple but that would mean ICAAN would have to take action and we all know that will never happen! These scammers and spammers are all buying their domains from an ICAAN approved outfit. You and anyone else can easily trace domains back to a Chinese acredited register of domains. ICAAN has had thousands and thousands of complaints about this register but does not act.
adijuh.com
January 18th, 2010
at 9:35pm
This phishing domain appears to be registered in China
Alex
February 8th, 2010
at 2:32pm
looks like the domain has been taken down. Bye bye baby. The amount of phishing websites coming live everyday is no doubtly increasing but my question is that is it really worth it hacking into someones twitter account? its not like u are hacking into someones bank account.