Threat Intelligence Brief
Curated summary with source attribution
Source: waiver.smartwaiver.com
Threat Risk: Medium
Victim: Cash App users
Incident: Phishing campaign mimicking a data breach settlement process.
Impact: Potential compromise of personal and financial information via social engineering.
Attacker: Unidentified threat actors
Analysis: Threat actors are utilizing a fake settlement portal hosted on a third-party waiver site to harvest user information. The repetition of a specific phone number suggests a combined phishing and vishing operation designed to defraud users.
Recommendations: Avoid clicking links in unsolicited emails regarding financial settlements; Verify all legal settlements through official government or court-approved channels; Do not provide personal data or sign documents on unofficial third-party domains
Source: Observed phishing page
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source