---
title: "Cyber Security News Update, Week 29 of 2019 | DuoCircle"
description: "Most phishing emails contain a malicious link in the hope that the recipient will click on it."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-29-of-2019/"
---

Quick Answer

American Express customers are being targeted with phishing emails that hide the malicious URL by splitting it across the HTML  tag, which sets a base URL for relative links and lets attackers slip past URL scanners and reputation gateways. Mobile phishing volumes are up 85% year over year since 2011, including a 'trusty iPhone' voice-phishing scam where caller ID spoofs Apple, Inc. Nescafe coffee fans are being lured by survey scams that drop malware via a fake PDF. Phishing-as-a-Service kits, including SharePoint, Office 365, LinkedIn, and Adobe templates, sell for $30 to $80 with hosting included. The 16Shop kit, previously used against Apple, is now targeting Amazon. Office 365 phishing using HTML attachments hosts the fake login locally to dodge URL reputation scoring.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-29-of-2019%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2029%20of%202019&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-29-of-2019%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-29-of-2019%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-29-of-2019%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2029%20of%202019 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2029%20of%202019&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-29-of-2019%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2019/07/SMTP-server-mail-5836.jpg) 

Most phishing emails contain a malicious link in the hope that the recipient will click on it. **Phishing prevention** **technology** is wise to this tactic, which has forced attackers to adapt. Their latest adaptation is a novel new **phishing technique** targeting [American Express customers](https://www.bleepingcomputer.com/news/security/american-express-customers-targeted-by-novel-phishing-attack/), by breaking the malicious link up into two parts.

The technique uses the `<base>` HTML element. “This allows attackers to specify the base URL that should be used for all relative URLs within the phishing message, effectively splitting up the phishing landing page in two separate pieces. It also helps to hide it from the target since, on hover, the hyperlink will only show the end part of the malicious link, without the domain used to host the landing page.”

“_This tactic helps the attacker evade URL filters and gateways that have active URL scanning services_, which currently do not have the capability to combine these inert pieces into a scannable malicious URL.”

[![Phishing mobile devices](https://media.mailhop.org/duocircle/images/2019/07/email-sending-services-6824.jpg)](https://media.mailhop.org/duocircle/images/2019/07/email-sending-services-6824.jpg)

[Phishing mobile devices](https://www.infosecurity-magazine.com/opinions/protecting-mobile-phishing-1/) is big business. “_Phishing attacks on mobile has increased by an average of 85% year on year since 2011_.” This week we learned about a new phishing scam targeting iPhone users.

### Trusty iPhone

According to iGeekBlog, the new scam involves “trusty iPhone.” According to Marjorie Stephens, CEO of BBB, “The scam was so realistic that even a BBB executive was nearly fooled.”

The scam involves getting a call from Apple, Inc., or at least that’s what the caller ID on the iPhone says. Scammers then leave “a pre-recorded message saying that there’s a serious threat to your phone or computer.” When you call back, the scammers ask for personal information or payment to fix the problem.

### Nescafé Coffee

It was only a matter of time before hackers went after coffee drinkers. Their scam of choice? Free coffee. According to [Metacompliance](https://www.metacompliance.com/blog/scam-of-the-week-nescaf%C3%A9-coffee-fans-urged-to-avoid-social-media-phishing-scam/), “Nescafé coffee lovers are the latest to be targeted with a **phishing scam** designed to steal their personal details and infect their devices with malware.”

The scam asks targets to complete a survey for a chance to win coffee makers and free coffee packs. To take the survey the targets have to download a PDF, which of course isn’t a PDF at all but rather malware. “Once installed, attackers can _use the malware to spy on their online activities, steal personal and financial information or use the device to hack other systems._“

### Phishing Phrontier

Back in the 1840s, during the California gold rush, it was said the people who got rich weren’t the prospectors, but the ones who sold the prospecting equipment. That understanding has carried over to the world of phishing.

Apparently, it’s more profitable to offer phishing tools than to actually do the phishing yourself with the rise of **_Phishing-as-a-Service_**. That’s right. Websites now exist where you can purchase everything you need to launch your very own phishing attack.

These Phishing-as-a-Service companies offer phishing kits, which include phishing templates, as well as hosting the landing pages. It’s completely turnkey. According to an article on [Bleeping Computer](https://www.bleepingcomputer.com/news/security/phishing-as-a-service-fuels-evasion-methods-email-scam-growth/), “The phishing templates that are available include SharePoint, Office 365, LinkedIn, OneDrive, Google, Adobe, Dropbox, DocuSign, and many more. These templates range from $30 to $80 and include one month of hosting for the page.” Really? Thirty bucks?

In keeping with a theme, according to [IBM Security Intelligence](https://securityintelligence.com/news/digital-attackers-now-using-16shop-phishing-kit-to-target-amazon-users/), “Digital attackers are now abusing the 16Shop phishing kit to target Amazon users for the purpose of stealing access to their accounts.”

[![Phishing protection](https://media.mailhop.org/duocircle/images/2019/07/email-smtp-service-5869.jpg)](https://media.mailhop.org/duocircle/images/2019/07/email-smtp-service-5869.jpg)

People receive email attachments all the time. Most are business documents like Word, Excel or PDF. [Phishing protection](/email/phishing-protection) software scans these documents for malicious content so it’s getting harder for hackers to use these documents to launch a **phishing attack**. Unfortunately, hackers evolve.

Now comes [word of a new phishing trend](https://web.archive.org/web/20190916061422/https://www.avanan.com/resources/phishing-trend-targeting-office-365-uses-html-attachments) targeting Office 365 with HTML attachments. “These HTML attachments host webpages on the victim’s device instead of the public internet, which is a strategic way for hackers to avoid URL reputation checks. This attack is particularly dangerous in collaboration suites such as Office 365.”

### Body Count

The health sector is always a big target for hackers, not so much for direct financial gain, but for access to patient records. This week was no exception. According to an article on [Health IT Security](https://healthitsecurity.com/news/phishing-attack-on-california-vendor-breaches-data-of-14500-patients), “An employee of vendor California Reimbursement Enterprises fell victim to a phishing attack, which potentially breached the data of 14,500 patients, including those from Los Angeles County DHS.”

Mickey Mouse must be horrified. According to the [Orlando Sentinel](https://www.orlandosentinel.com/business/tourism/os-bz-disney-reedy-creek-phishing-20180625-story.html), “An employee at Reedy Creek Improvement District believed she was receiving emails from a legitimate landscaping vendor and paid out nearly $722,000.” Reedy Creek Improvement District handles building codes, road construction, fire rescue and landscaping throughout Disney-owned land.

### Email Forwarding

Making news this week is all the trouble you can get into by mindlessly forwarding emails. Problems with **forwarding emails** range from [copyright infringement](https://www.netmanners.com/229/rules-for-forwarding-emails/) to [disseminating misstatements made by someone](https://www.law.com/newyorklawjournal/2019/07/12/think-twice-before-you-forward-that-email/) else to [forwarding sensitive information](https://news.uthscsa.edu/beware-of-auto-forwarding-email/). The bottom line: look before you forward.

And that’s the week that was.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-29-of-2019%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2029%20of%202019&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-29-of-2019%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-29-of-2019%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Spam](https://media.mailhop.org/duocircle/images/2016/05/spf-permerror-3256.jpg)  April Spam Filtering Uptime Report News ](/blog/announcements/april-spam-filtering-uptime-report/)
- [ ![Spam Filtering](https://media.mailhop.org/duocircle/images/2023/02/spf-record-tester-7226.jpg)  Changes to Spam Filtering Technology News ](/blog/announcements/changes-to-spam-filtering-technology/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2020/01/spf-permerror-7312.jpg)  Cyber Security News Update, Week 1 of 2020 News ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 1m  April Spam Filtering Uptime Report  May 4, 2016 ](/blog/announcements/april-spam-filtering-uptime-report/)[  News 2m  Changes to Spam Filtering Technology  Feb 8, 2023 ](/blog/announcements/changes-to-spam-filtering-technology/)[  News 4m  Cyber Security News Update, Week 1 of 2020  Jan 3, 2020 ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 29 of 2019","description":"Most phishing emails contain a malicious link in the hope that the recipient will click on it.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-29-of-2019/","datePublished":"2019-07-24T15:42:44.000Z","dateModified":"2025-05-20T15:22:01.000Z","dateCreated":"2019-07-24T15:42:44.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-29-of-2019/"},"articleSection":"announcements","keywords":"","wordCount":827,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2019/07/SMTP-server-mail-5836.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 29 of 2019","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-29-of-2019/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 29 of 2019","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-29-of-2019/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 29 of 2019","description":"Most phishing emails contain a malicious link in the hope that the recipient will click on it.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-29-of-2019/","datePublished":"2019-07-24T15:42:44.000Z","dateModified":"2025-05-20T15:22:01.000Z","dateCreated":"2019-07-24T15:42:44.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-29-of-2019/"},"articleSection":"announcements","keywords":"","wordCount":827,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2019/07/SMTP-server-mail-5836.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
