cognitive cybersecurity intelligence

News and Analysis

Search

WordPress Plugin Exploited to Turn Legitimate Sites Into Phishing Traps

A WordPress plugin, PhishWP, is being used by cybercriminals to collect sensitive data such as credit card numbers, CVVs and billing addresses from victims by creating fake payment pages. The plugin’s data is relayed to the attackers in real time via Telegram, with the harvested data used for fraudulent transactions or sold on the dark web. The plugin’s ability to convincingly mimic legitimate payment pages and evade detection makes it particularly dangerous.

Source: securityboulevard.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts