Open-Redirect vulnerabilities in American Express and Snapchat are being exploited to carry out phishing scams, researchers have revealed. Scammers are exploiting open-redirect vulnerabilities in a new phishing campaign targeting Microsoft 365 and Google Workspace users. These vulnerabilities are mainly impacting American Express and Snapchat domains. Open redirect is a security vulnerability. It occurs when a website cannot validate user input, due to which threat actors can manipulate the URLs of reputed domains and redirect victims to malicious pages. Phishing Emails Using Open-Redirect Vulnerabilities According to a report from INKY, automated URL redirects used by Snapchat and American Express to attract users to their websites have been hijacked to steal credentials. Attackers are sending phishing emails and include PII (personally identifiable information) in the URL to customize the malicious landing pages quickly and disguise them PII by converting it into Base 64. Hence, the information turns into a sequence of random characters. INKY’s report further revealed that they observed threat actors hijacking unpatched redirect vulnerabilities on Snapchat and American Express domains between May and July. What Makes the Attack Effective? A trusted domain such as Snapchat serves as a temporary landing page, after which the visitor is redirected to a malicious…
Read More










