Major multinationals such as BBVA, Santander, Correos, and now Movistar: victims of online identity theft; a fraudulent communication containing a virus in an email signed by Movistar as an invoice

25/06/2015
|

Movistar is alerting its customers and other users about a virus that has spread through a fake email with an apparent Movistar invoice, which contains a virus sent to its customers in the form of a bill.

Another case of attacks on the identity of large companies online, a problem originating in cybersecurity that affects corporate reputation
Movistar warns of a virus sent to its customers in the form of an invoice

The company states that it is a fraudulent email sent from Telefónica
It recommends deleting said message if received and not opening the attached content

  
A few weeks ago, at the start of the preparation for a report with TV3, we pointed out the second major wave of ransomware attacks originating from Correos.

During the week of filming, we contacted Correos to ask what their stance was on the matter.

As professionals in digital identity management for corporations online, if one of our clients, as a large corporation, were affected by an attack of these characteristics and had hundreds of secondary victims, we would propose:

  • Perform continuous monitoring of the network to locate victims 
  • Contact and inform each of them and carry out a massive media campaign indicating the origin of the fraud and the measures to be taken into account
  • Inform employees at all levels (operational, executive, and management) about the issue and train them so they know how to respond to any questions, from the mail carrier to the telemarketer, as well as office staff.
  • Signage in Correos offices throughout Spain.
  • A fund for digital protection insurance for the company’s clients. A good way to implement CSR and branded content.

Why take part in such a campaign? Let’s take an example: someone has their Facebook account stolen and messages are sent to the victim’s contacts requesting financial help as a ransom; the victim, before regaining control, already asks other contacts to warn others and spread the word so that no one is scammed using their false identity.

And once control is regained, measures must be put in place so that people remain aware of what happened and what solutions are being provided.

 In the case of Movistar, and here we must point out a best practice, the company states that it is a fraudulent email sent from Telefónica

It recommends deleting said message if received and not opening the content.
Other cases such as

Correos

  
BBVA

  

Digital Identity

Methods for analyzing and
assessing online
reputation damage