Phishing Scam Claims Payroll Fraud

Not, strictly speaking, about payroll processing, but important news, nevertheless:

According to SC Magazine, a publication for IT security professionals, a new phishing scheme tries to install malicious software on employee computers by duping them into thinking their employer has committed payroll fraud.

The phishing emails appear to originate from the National Payroll Reporting Consortium (NPRG). Recipients are told that their employer has tried to cut costs by making “numerous misrepresentations regarding worker classification.”

They are then asked to download and fill out a form attached to the email — only problem is, the attachment installs a bit of spyware that steals information from the infected machine. Every time the employee fills out a form on the web, the spyware collects the information they enter to the form and attempts to forward it to a Romanian crime syndicate.

Anyone receiving such a message is advised to delete it immediately, without clicking on or viewing the attachment.

More information and a screenshot of a sample phishing email are available by viewing alert from Websense reporting the problem.

No Comments

No comments yet.

Comments RSS TrackBack Identifier URI

Leave a comment