Attackers use Eventbrite messages to impersonate known brands like Qantas and DHL. Photo Credit: Adobe Stock/nateejindakum
Cyber criminals are targeting the event management and ticketing website Eventbrite to scam potential targets with phishing emails.
Cybersecurity researchers Perception Point claims to have seen 900% growth in the rate of such email attacks since July.
Attackers are using Eventbrite’s platform to mask their activities under the pretense of authentic Eventbrite notifications.
Eventbrite enables users to discover, set up, and advertise local and virtual events. Organisers can use it to sell tickets and track attendance.
Its tools can support different events, from concerts and festivals to workshops and conferences, while consumers can use it to search for events and purchase tickets.
Perception Point researchers observed phishing emails delivered via '[email protected]'.
Perception Point warned on its website, “Despite being presented as legitimate events created on the Eventbrite platform, attackers use these messages to impersonate known brands like Qantas, DHL, and Qatar Post.
“Each email urges the recipient to take action: reset your PIN code; verify your delivery address; pay for an outstanding bill; pay for a package. These time-bound requests employ a social engineering tactic threat actors use to prompt the target to act fast.”
Messages are sent in multiple languages. “By personalising emails by language and branding, the campaign is not only global but also highly adaptable, evading detection by traditional security measures,” PerceptionPoint noted.