New phishing scam is on the loose in the tumblr community… let’s help stop it.

I have been seeing a disturbing trend lately involving fraud and phishing scams with people following me and I want everyone else to be vigilant about this. You may ask,
“Why do I need to worry if I never go on their page?”
Because others on your blog do and you’re exposing them to a site which might have fraud on it. I’m not saying you need to go around policing tumblr, but if you see a site where the URL is not tumblr.com or www.tumblr.com, this should send off red flags for you and you should block that follower immediately.
(Click to see larger image)
(Click to see larger image)
Often what will happen is if a person’s account is compromised, the compromised account will try to mass follow people and when your followers click on the link to your other followers on your blog, the compromised blog will have a piece of code in the tumblr template set in the user blog which will redirect you to sites like this:
(Click to see larger image)
Which will then try to trick you into giving your login credentials for them to then compromise your account.
You can block any follower by using the http://www.tumblr.com/block section of tumblr and enter in the URL of the tumblr account that has been compromised, then flag it for SPAM.
(Click to see larger image)
A good Tumblr URL will ALWAYS have the word tumblr and .com bumped up right next to each other in the address bar at the top of your browser. If you see something like tumblr.freespace.com or tumblr.host.com or some other derivative of such nature, sound the alarms in your head because these sites CAN NOT be trusted. This goes for a lot of other sites such as Facebook and banking sites in general. If you see the domain name and its TLD (.com,.net.org, etc) together, you’re generally pretty safe.
(Click to see larger image)
While this solution will not be a magic bullet, slowing down the spread of malware/phishing scams is important because the more difficult and time consuming it is for the scammers and malware writers to implement a scam or piece of code the less likely they will have incentive to deploy it.
For further help securing your Tumblr if you think you’ve been phished, check out this guy’s Tumblr: http://antiphishingontumblr.tumblr.com/




