Phishing: fake email Netflix gathers payment details

MX Lab,, started to intercept a phishing campaign targeting Netflix users. This campaign is not only an attempt to steal the login and password credentials but also the credit card number.

The email comes with the subjects like:

Your Netflix membership has issues
Your Netflix membership has unresolved issues

This email is send from the spoofed address ””  or “”and has the following body:

Dear Customer,
We recently failed to validate your payment information we hold on record for your account, therefore we need to ask you to complete a brief validation process in order to verify your billing and payment details.

Click here to verify your account

Failure to complete the validation process will result in a suspension of your netflix membership.

We take every step needed to automatically validate our users, unfortunately in this case we were unable to verify your details. The process will allow us to maintain our high standard of account security.

Netflix Support Team
This message was mailed automatically by Netflix during routine security checks. We are not completely satisfied with your account information and require you to update your account to continue using our services uninterrupted.

Screenshot of the email:

The embedded URL “Click here to verify your account” will lead the user to the non secure web site hxxp:// This page has a redirect towards the following host hxxp:// that will handle the process.

After (fake) login, you are asked for your billing information.

Further on in the process, your credit cards details are asked.

Once all the information is gathered, you have the final screen in this process.

When clicking on the button, the visitor is taken to the official Netflix web site.

MX Lab recommends to check similar incoming emails carefully before opening the URL. Only trust https connections when submitting personal or sensitive information.


Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s