[ad_1]
Main takeaways
Phishing is a cyberattack technique where scammers fish out sensitive credentials by impersonating a well-known person or company that you trust.
Common phishing techniques include impersonation, the use of urgent or threatening language, and the insertion of harmful links.
Attackers often alter their sender identity to make their email appear as if it came from a trusted source.
If you are unsure whether a Binance email is genuine or not, please contact Binance Support and provide them with the EML file of the emails along with the relevant screenshots.
Your Binance account could be a target for phishers. Learn how to secure your crypto funds with this comprehensive guide.
Your average hacker doesn’t have the know-how to break into Binances’ security system. However, what they most certainly have are the tools to trick you into giving them your username, password, and two-factor authentication (2FA) code.
Why break into a state-of-the-art safe when you could just convince the owner to let you in? This is the basis of phishing: exploiting human error and emotions.
Keep reading to learn more about phishing, how it works, and how to protect your crypto from common phishing techniques.
What is phishing and how does it work?
Phishing is a popular cyberattack technique where scammers fish out sensitive credentials by impersonating a well-known person or company you trust, such as Binance. The most popular method is by e-mail. These sneaky messages are easy to make, and some look almost identical to their legitimate counterparts.
It sounds simple, but they work, and that’s why most cyberattacks start with a phishing email. According to a study by email security company Valimail, more than three billion impersonation messages are sent every day, representing 1% of all email traffic.
To secure your cryptographic and personal data, it is crucial to know how to identify yourself and protect yourself from phishing emails. First, let’s look at some common examples.
Three examples of phishing emails
The following section is a brief overview of phishing email techniques, including impersonation, the use of urgent or threatening language, and the insertion of harmful links. We’ve also included real-life examples to help you better understand each technique.
1. Email spoofing
Spoofing is a deceptive technique where scammers create fake sender and domain names that look like an official source. The idea is that you will believe the email is legitimate because it contains something like binance.com in the sender address.
Here is a concrete example where scammers used the address [email protected]. It looks official until you notice that the sender address reads ses.binance.com.
2. Urgent or threatening language
Phishing emails often create a sense of urgency, fear, or curiosity to manipulate your emotions and trigger immediate action. For example, they may trick you into believing that there is an unexpected withdrawal from your account, causing you to reset your password. In reality, you just exposed your password to a scammer.
Here is an example of a phishing email that claims the recipient made an unexpected withdrawal. Note the language in the highlighted part. It is deliberately designed to confuse and scare you with words like lock your account and secure all your funds.
3. Malicious links and fake attachments
Phishing emails frequently contain links that direct you to fake websites that look like legitimate ones. They may also include attachments such as PDF files, executable files or repackaged applications that contain harmful scripts or malware. Opening these attachments may give attackers unauthorized access to your devices or allow them to steal sensitive information or transfer funds without your consent.
Below is an example of a phishing email containing a malicious link. By clicking [Verify Email] would take you to a fake Binance login page where you are prompted to enter your username and password. Crooks could then collect your data to resell it or steal your account and funds.
Four ways to identify a phishing attack
Now that we’ve gone through some examples of phishing emails, let’s look at different ways to identify a phishing email.
1. Binance Verification
Received an email from Binance, but something looks suspicious? First find the sender address on Binance Verify. If you receive an Unverified Source message, the email probably has bad intent.
However, the source address can still be a spoofed email even if it passes an initial check on Binance Verify. As mentioned earlier, email spoofing is a common technique used by scammers to make an email appear as if it comes from a trusted source. They do this by using similar sender domains or spoofing email headers via Reply-To or Return-Path fields.
Besides sender addresses, Binance Verify can also help validate any social media accounts or website links listed in the email content.
Social media accounts
If the email asks you to contact a Binance employee via social media platforms like Telegram, Facebook, or WeChat, be sure to verify the username on Binance Verify.
The image below shows what should appear if the account has a real Binance username. Note that criminals often pose as employees of our company. Binance Verify is just one of the many steps you need to take to verify someone’s identity.
Links to websites
Use caution when clicking on website links in emails. To verify a Binance URL, right-click the link and select Copy Link Address. Next, use Binance Verify to verify if the website is legit. The image below shows what Binance Verify should display if the website is an official Binance domain.
2. Anti-Phishing Code
We strongly encourage you to set up your anti-phishing code if you haven’t already. It’s simple and only takes a few minutes. Once set up, every authentic email you receive from Binance will include the unique combination of numbers and letters you set.
This is what an official Binacne email looks like with and without an anti-phishing code. Avoid Binance emails that do not contain your anti-phishing code.
To set up your anti-phishing code, follow the steps in our helpful guide: What is an anti-phishing code and how to set it up on Binance.
3. Checking the EML file
Downloading the email as an EML file provides additional hidden information for verification purposes. Although more technical, this method is very effective in detecting phishing attacks.
SPF/DMARC/DKIM
For example, you can open the file and perform an SPF/DMARC/DKIM check. If all three or some of the checks fail (for example, the check says dkim=fail), the email is probably from an unauthorized source.
IP reputation
You can also find the IP address in the EML file to check for any reported illicit activity. Simply copy and paste the address to an IP reputation checker, such as abuseipdb or virustotal. Note: These databases may not contain information if an IP address is too recent. Always check with several reliable sources before drawing a conclusion.
4. Contact Binance Support
If you suspect an email, we recommend contacting Binance Support with screenshots and the EML file. This is the most foolproof method among all the cheats listed in this guide. Once we receive your file, our security team, who have years of experience fighting phishing attacks, will help you verify the authenticity of your emails.
If you need help downloading the EML file, you can follow the steps listed in the next section.
How to upload an EML file
Let’s see how you can download email content as EML file on Gmail and Outlook.
gmail
Open the email you want to download as an EML file. Click on the three-dot icon located in the upper right corner of the email.
Select Download Message from the drop-down menu.
Outlook
Open the email you want to download as an EML file. Click on the three-dot icon located in the upper right corner of the email.
Select Download from the drop-down menu.
Once downloaded, right-click on the EML file and press [Open With]followed by [Other]. Then select TextEdit if you are using macOS or Notepad(++) if you are using Windows.
Stay alert to phishing attempts. Learn how to protect your funds today and you could save yourself from future disaster. Here is a short summary of good practices to follow:
Set up your anti-phishing code by following this guide.
First search for any Binance email address, username or URL on Binance Verify.
Do not click on suspicious links. You may unknowingly install malware on your device or end up on a spoofed site designed to collect sensitive information.
Do not share your personal information with a stranger, including user credentials, phone numbers, bank accounts, wallet seed phrases, or private keys.
Enable two-factor authentication (2FA). If your account details are stolen, 2FA can make it harder for scammers to take control of your account.
Only engage in activities with a legitimate business. Beware of freebies and airdrop invitations you receive via email.
If you’re still unsure about an email, contact Binance Support for help! We were more than happy to check the EML file for you.
Further reading
|
Sources 2/ https://www.binance.com/en/blog/community/how-to-protect-your-crypto-from-phishing-emails-5649491576884064316 The mention sources can contact us to remove/changing this article |
[ad_2]