---
title: "Cyber Security News Update, Week 39 of 2019 | DuoCircle"
description: "We start this week with a repeat offender."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-39-of-2019/"
---

Quick Answer

Cybersecurity headlines for the week of September 27, 2019\. The Daily Mail reported a Netflix phishing campaign in Australia in which spoofed 'reactivate your subscription' emails point to a Netflix-branded page and a fake account-suspended notice that captures bank details. A Chase Bank phishing email asked recipients to verify accounts through a credential-harvesting page. A Venmo phishing scam used fake payment notifications to steal logins. OAuth-based phishing abused legitimate consent screens to bypass MFA and grant attackers persistent access to mailboxes. Magellan Health reported phishing-driven breaches at multiple subsidiaries exposing protected health information for tens of thousands of members. The phishing roundup covers other notable lures of the week.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-39-of-2019%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2039%20of%202019&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-39-of-2019%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-39-of-2019%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-39-of-2019%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2039%20of%202019 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2039%20of%202019&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-39-of-2019%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2019/09/spf-record-checker-3573.jpg) 

We start this week with a repeat offender. From the [Daily Mail](https://www.dailymail.co.uk/news/article-7497277/Netflix-phishing-scam-empties-Australian-users-bank-accounts-emailing-cancelling-subscription.html), news comes that “_Scammers have targeted Netflix customers in Australia with an email scam aimed at getting their bank account details_. The emails included a link for people to reactive their subscription, which takes them to a Netflix branded **phishing page**. Once the user logs into their account, they are taken to what appears to be a Netflix account page, with a notification at the top stating their account has been suspended and payment information needs to be updated.”

## Chase Bank Phishing

It wouldn’t be a week if some hacker somewhere wasn’t targeting a bank with **phishing emails**. This week’s target? Chase.

According to [Scamacide](https://scamicide.com/2019/09/21/scam-of-the-day-september-22-2019-new-chase-phishing-email/), “_Chase is a popular target for this type of phishing email because it is one of the largest banks in the United States_. Like so many phishing emails, this one attempts to lure you into responding by making you think there is an emergency to which you must respond. As phishing emails go, this one is pretty good. It looks legitimate and the version appearing in your email comes with a legitimate appearing Chase logo.”

[![Phishing Scam](https://media.mailhop.org/duocircle/images/2019/09/sender-policy-framework-8524.jpg)](https://media.mailhop.org/duocircle/images/2019/09/sender-policy-framework-8524.jpg)

## Venmo Phishing Scam

If old banks can be phishing targets, certainly new banks can be too. The newest form of banking is peer-to-peer payments being headed up by the company Venmo. [News](https://abc6onyourside.com/on-your-side/beware-of-a-common-venmo-phishing-scam-making-the-rounds-through-text-messages) comes this week a Venmo **phishing scam** making the rounds through text messages.

According to the report, “people will receive a text message on their phone saying their account is about to be charged. Victims are advised to log on and decline the charge if they’d like. The included link in the message takes you to a log-on page, which asks for your phone number and password. _Once logged in, you are asked to verify your identity with your bank and personal information_.”

## Phishing Phrontier

When it comes to advanced **phishing tactics**, hackers seem to have developed a pattern. They figure out what technology people are using to authenticate themselves and they go after it. For example, [single sign-on](https://en.wikipedia.org/wiki/Single%5Fsign-on) (SSO) is a way for users to authenticate themselves once and be able to access several websites.

_Now news comes [Cyware](https://web.archive.org/web/20221006002015/https://cyware.com/news/attackers-use-single-sign-on-in-phishing-pages-used-to-steal-credentials-ae8e2c16) that attackers are using single sign-on phishing pages to steal users’ credentials_. “Malicious pages have been reported to pretend to be the sign-in pages of applications such as Dropbox. When users enter their credentials, the data is harvested instead of logging them into the intended application. Before the popularity of SSO, hackers would create a separate page for each service to **steal credentials**. But now, they’re able to create a single phishing page.”

## OAuth Phishing

In keeping with a theme, hackers are now using OAuth for phishing attacks. [OAuth](https://en.wikipedia.org/wiki/OAuth) is a way to grant users access without passwords. So, it shouldn’t come as a surprise to you if hackers go after that.

According to [Cyberwarzone](https://web.archive.org/web/20191214001941/https://cyberwarzone.com/oauth-phishing-attacks-target-human-rights/), “_Amnesty International has reported that OAuth Phishing attacks targeted dozens of Egyptian human rights defenders since the beginning of this year._ Through the course of our investigation, we discovered that these emails were attempts to access the email accounts of their targets through a particularly insidious form of phishing known as **OAuth Phishing**. _We estimate the total number of targeted individuals to be in the order of several hundreds_.”

## Body Count

Another bad week for the healthcare industry. SPAMfighter [reports](https://www.spamfighter.com/News-22413-Phishing-attack-on-Artesia-General-Hospital-impacted-13905-patients.htm) a **phishing attack** on a New Mexico hospital. “The Artesia General Hospital based in Artesia, New Mexico, has discovered that PHI (Protected Health Information) of _13,905 patients was compromised as a result of a phishing attack_. Artesia is one of the cities in Eddy County of New Mexico in the United States. _The breach was first detected by the officials when an email account of one of their employees was found to have been used for sending the unauthorized emails_.” Doesn’t take much, does it?

## Phishing Attack at Magellan Health Subsidiaries

Not to be outdone, [news comes this week](https://www.hipaajournal.com/magellan-health-phishing-attacks-56226-presbyterian-health-plan-members/) of _56,225 Presbyterian Health plan members affected by phishing attacks at Magellan Health Subsidiaries_. “The Scottsdale, AZ-based managed care company, Magellan Health, has discovered two of its subsidiaries have experienced **phishing attacks** that exposed the protected health information of members of Albuquerque, NM-based Presbyterian Health Plan.”

[![email security service](https://media.mailhop.org/duocircle/images/2019/09/spf-record-tester-5478.jpg)](https://media.mailhop.org/duocircle/images/2019/09/spf-record-tester-5478.jpg)

_How many employee accounts were breached that lead to this phishing attack?_ **_Just two_.** That’s all it takes if you do not have [email security service](/). Two clicks. Fifty thousand compromised accounts. Doesn’t seem fair.

## Update

Ramsey County in Minnesota [admitted](https://www.hipaajournal.com/ramsey-county-expands-2018-phishing-attack-victim-count-from-599-to-117905/) that their 2018 phishing attack didn’t have 599 victims. Instead it had, **117,905 victims**. Two hundred times more than originally reported. How many employee accounts were breached that lead to this phishing attack? Two. See a theme here?

And that’s the week that was.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-39-of-2019%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2039%20of%202019&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-39-of-2019%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-39-of-2019%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Spam](https://media.mailhop.org/duocircle/images/2016/05/spf-permerror-3256.jpg)  April Spam Filtering Uptime Report News ](/blog/announcements/april-spam-filtering-uptime-report/)
- [ ![Spam Filtering](https://media.mailhop.org/duocircle/images/2023/02/spf-record-tester-7226.jpg)  Changes to Spam Filtering Technology News ](/blog/announcements/changes-to-spam-filtering-technology/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2020/01/spf-permerror-7312.jpg)  Cyber Security News Update, Week 1 of 2020 News ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 1m  April Spam Filtering Uptime Report  May 4, 2016 ](/blog/announcements/april-spam-filtering-uptime-report/)[  News 2m  Changes to Spam Filtering Technology  Feb 8, 2023 ](/blog/announcements/changes-to-spam-filtering-technology/)[  News 4m  Cyber Security News Update, Week 1 of 2020  Jan 3, 2020 ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 39 of 2019","description":"We start this week with a repeat offender.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-39-of-2019/","datePublished":"2019-09-27T17:48:38.000Z","dateModified":"2025-05-26T18:19:46.000Z","dateCreated":"2019-09-27T17:48:38.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-39-of-2019/"},"articleSection":"announcements","keywords":"","wordCount":789,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2019/09/spf-record-checker-3573.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 39 of 2019","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-39-of-2019/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 39 of 2019","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-39-of-2019/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 39 of 2019","description":"We start this week with a repeat offender.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-39-of-2019/","datePublished":"2019-09-27T17:48:38.000Z","dateModified":"2025-05-26T18:19:46.000Z","dateCreated":"2019-09-27T17:48:38.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-39-of-2019/"},"articleSection":"announcements","keywords":"","wordCount":789,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2019/09/spf-record-checker-3573.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
