emails pretending to beAttack.Phishingfrom TV Licensing . The watchdog says it has already received over 200 reports about the phishing scamAttack.Phishing. The email luresAttack.Phishingyou in by saying you are owed a refund on your TV Licence payments . But , it ’ s a con and all the senders are really after is your bank details . What does the email say ? So far all the emails have been the same . They say : “ This is an official notification from TV Licensing ! “ We would like to notify you that , after the last annual calculation we have determined that you are eligible to receive a TV Licensing refund of 85.07 GBP . “ Due to invalid account details records , we were unable to credit your account . Please fill in the TV Licensing refund request and allow us 5-6 working days to the amount to be credited to your account. ” All this is untrue . If you receive this email the best thing to do is report it to Action Fraud and then delete it . Do not click on any links within the email . “ A small number of our customers have receivedAttack.Phishingscam email messages saying they are due a refund , ” a spokesperson for TV Licensing has said . “ A link directsAttack.Phishingcustomers to a fake version of the official TV Licensing website which asks them to enter personal information and bank details . “ If you receive a similar email message please delete it . If you have already clicked the link , do not enter or submit any information . TV Licensing never sends refund information by email and is investigating the source of the fraud. ” While these emails are a scam they carry an element of truth – you might be due a refund from TV Licensing . There are a number of ways you can avoid paying the full licence fee . If you are a student you are entitled to a £37 discount on the £147.50 colour TV licence . You can also apply for a refund if you ’ ve paid for a TV Licence beyond your 75th birthday . Anyone over the age of 75 is entitled to watch TV for free . TV Licences apply to households not individuals so if anyone if your household is a student , or over 75 then you all get the benefit of their discount . Similarly , if someone in your house is severely visually impaired they are entitled to a half-price TV licence . You can apply for a refund via the official TV Licensing Website .
A widely reported e-mail purporting to beAttack.Phishinga request to share a Google Docs document is actually a well-disguised phishing attackAttack.Phishing. It directsAttack.Phishingthe user to a lookalike site and grants the site access to the target 's Google credentials . If the victim clicks on the prompt to give the site permission to use Google credentials , the phishAttack.Phishingthen harvestsAttack.Databreachall the contacts in the victim 's Gmail address book and adds them to its list of targets . The phishAttack.Phishingappears to have been initially targeted at a number of reporters , but it quickly spread widely across the Internet . Some of the sites associated with the attack appear to have been shut down . The e-mail uses a technique that a Trend Micro report linked last week to Pawn Storm , an ongoing espionage campaign frequently attributed to Russian intelligence operations . The attack uses the OAuth authentication interface , which is also used by many Web services to allow users to log in without using a password . By abusing OAuth , the attack is able to present a legitimate Google dialogue box requesting authorization . However , the authentication also asks permission for access to `` view and manage your e-mail '' and `` view and manage the files in your Google Drive . '' The fake application used in the Pawn Storm phishAttack.Phishing( which posed asAttack.Phishinga Google security alert ) was named `` Google Defender . '' Today's phishAttack.Phishingasks the target to grant access to `` Google Docs '' —a fake application using the name of Google 's service . If the target grants permission , the malicious site will immediately harvestAttack.Databreachcontacts from the target 's e-mail and send copies of the original message to them . [ Update , 4:40 pm EDT : ] Google has struck hard at the worm . Not only have all the sites associated with the phishAttack.Phishingbeen taken offline , but the permissions associated with the worm have been dropped from victims ' accounts . The domains used in the attack were registered through NameCheap , and used a Panama-based privacy service to conceal the registration information . The hostnames were pointed at a server behind Cloudflare 's content delivery and denial-of-service protection network .