The National CERT of the Republic of Serbia warns users about a current phishing campaign that is being distributed via email. As part of this campaign, users are sent fake emails asking them to update their user data.
The content of the email states that the update is necessary in order for the user to smoothly continue using email or other online services. The message contains a link through which the user is asked to perform the alleged update of the data.
By clicking on the link, the user is redirected to a fake website, where they are asked to enter their username and password for email or other online account, which allows attackers to gain unauthorized access to the account and its further misuse.
The National CERT recommends that users who receive such an email do not access the link in the message, do not enter their username and password, and delete the message.
Special attention should be paid to the sender's address and check whether it belongs to the organization listed as the sender. If you have any doubts about the authenticity of a message, you should check the information through the company's or organization's official communication channels. The image below shows an example of a phishing email that illustrates the described method of fraud.
