Technology by Design

Technology news, reviews, and how to keep your technology running fast and smooth!

  • Home
  • About TbyD
    • Who is TbyD
    • Why Choose TbyD?
    • 16 Things
    • Your Computer Guy
  • Products and Services
    • Business Services
      • Monthly Service Plans
        • Enterprise Service Plan
        • Business Service Plan
        • Personal Service Plan
      • Performance Analysis
      • Optimization
      • Core Security Solution
      • Managed Backups
      • Computer and Network Systems
      • Computer Setup
      • Domain Names
      • Email Services
      • Extended Warranties
      • Network Cabling Services
      • Security Camera Systems
      • Managed Spam Filters
      • VoIp Phone Systems
      • Websites
    • Services
      • Monthly Service Plans
        • Enterprise Service Plan
        • Business Service Plan
        • Personal Service Plan
        • Computer Setup
      • Core Security Solution
      • Managed Backups
      • Extended Warranties
      • Performance Analysis
      • Optimization
      • Network Cabling Services
      • Security Camera Systems
      • Managed Spam Filters
      • VoIp Phone Systems
    • Products
      • Computers
      • Servers
  • Testimonials
    • What Our Clients Say About Us
  • Blogs
    • ALERTS
    • FAQ
    • How To Videos
  • Newsletters
    • TechTips Newsletters
  • Reviews
  • Media
    • Email Red Flags
    • E-Books
    • Disaster Prevention Planning Kit
    • Free Reports
  • Contact Us
    • Contact Us
    • Quick Support

ALERT: Comcast Triple-Threat

December 22, 2015 by The T By D Team Leave a Comment

ComcastALERT:  Comcast Triple-Threat

More and more, legitimate-looking advertising served on major websites turn out to be malicious.  CyberCriminals pay for and post ads, which they hope you click on.  BUT if you click on the malicious ads, you are redirected to a compromised website which may infect your computer and/or disply pop-ups that claim your PC has a virus and provide a toll-free number for “Tech Support” who will “fix” your PC, but really just want your credit card information.

Comcast is the largest ISP in the U.S. and have thousands of business users.  This makes them a prime target for a social engineering attack by CyberCriminals.

Comcast Triple Threat

Threat #1:  Malicious Ad

Comcast has a search page called Xfinity that serves tons of searches.  On this page is a malicious ad (served by Google) from “Sat TV Pro” which claims to compare Direct TV to Comcast TV.  If you click on the ad, you are redirected to a compromised site which has an Exploit Kit (EK) running.

Threat #2:  Infection

The EK first infects the workstation with ransomware, then redirects to a fake Xfinity site.

Threat #3:  Extortion

Comcast Tech Support

The fake Xfinity site pops up, with a message allegedly from “Comcast’s security plugin”.  The message states that the workstation is infection (which is correct, because they just did it!), and the user needs to call “tech support”, for which they provide a toll-free number.  If you call the toll-free number provided, you get fake “Tech Support”, which is actually scammers who try to get your credit card information to “fix” the box.  

How to Avoid This Scam
  1. Keep updates up-to-date to avoid security holes.  
  2. Use up-to-date software.  Old software versions may be cheaper and “familiar”, but they may no longer be supported by their manufacturer.  This means that the software manufacturer no longer releases security patches (to “patch” up known security holes).  This leaves your computer, and any computer on your network, vulnerable.  
  3. Do not click on any suspicious ads or links (in ads or in emails).
  4. Do not open emails or click on links from unknown senders.
  5. Do not open emails or click on links from “uncharacteristic” emails from known senders.  Example – it’s unlikely that the CEO of your company, or your Great-Aunt Freda, would send you penis-enlargement information.
  6. Make sure staff and employees know about current security alerts.  Not sure what they are?  Visit our ALERTS page to find out!
  7. Provide Security Awareness Training for your employees.

 

Not sure if your company is safe?  Ask us for a FREE Network Security Assessment!

Check out our “Email Red Flags”  for what to watch for in suspicious emails. 

Ask us about our “Core Security Solutions” package!
You can’t stop CyberCriminals from targeting your company or employees.
But you can be prepared for their arrival, and have full shields up.

Got CyberBugs?

Call 1-204-800-3166

For Cyber-Extermination!

#itthatworks

Filed Under: ALERTS, Blogs, Featured

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Sign Up For The Monthly TechTips Newsletter!

* = required field
unsubscribe from list

powered by MailChimp!

Recent Posts

  • ALERT: Celebrity Death Scams
  • ALERT: Uber Hacked
  • ALERT: Netflix Email Scam
  • ALERT: Bad Rabbit
  • Scam – Reset Password Alert

Recent Comments

  • ALERT: New Ransomware Targets MS Office 365 Users - Technology by Design on Managed Backups
  • ALERT: FBI Warns Email Extortion Heating Up for Summer! - Technology by Design on ALERT: AshleyMadison Hack Blows Up
  • ALERT: Evil Android Trojan Empties Your Bank Account - Technology by Design on Definition: Phishing
  • ALERT: HTML Attachments - Technology by Design on Definition: Phishing
  • ALERT: New Ransomware Also Steals Your Bitcoins - Technology by Design on Managed Backups

Copyright © 2025 · Dynamik Website Builder on Genesis Framework · WordPress · Log in