How scammers swindle credentials out of Luno users (2024)

Scammers are sending fake transfer receipt notifications to Luno cryptoexchange users and stealing their credentials.

How scammers swindle credentials out of Luno users (3)

Since the advent of cryptocurrency, scammers of every stripe have sought to get rich from stealing virtual coins. With cybercriminals duping both buyers of mining equipment and cryptoinvestors, we spotlight a scam targeting users of the Luno cryptoexchange.

About Luno

The Luno cryptocurrency exchange has been in existence since 2013, and today it serves more than 5 million clients in 40 countries. Luno’s primary focus is on emerging markets, allowing users from countries such as Singapore, Malaysia, Indonesia, South Africa, and Nigeria to purchase tokens with local currency.

Luno is a centralized exchange (CEX), meaning clients’ cryptowallet keys are stored on the exchange. Typically, such sites are well protected against hacking and leakage. However, account protection becomes much harder when owners spill their credentials to cybercriminals.

A simple phishing scheme

The attackers who targeted Luno did not reinvent the wheel.Rather, they employed the tried-and-true method of playing on people’s desire for free cryptocurrency, sending potential victims e-mail messages, seemingly from the Luno team, saying that an incoming payment has been “placed on hold due to error(s)” in their profile data. The message includes a link for users to follow and solve the problem.

How scammers swindle credentials out of Luno users (4)

Fake incoming transfer notification with link — just not to Luno

As per usual with a phishing attack, the scammers forged the sender’s address, making the message look plausible. The strange address of the link lurking under the button, which looks nothing like luno.com and is located in the .ar domain zone (Argentina), might arouse suspicion.

If the victim doesn’t notice this discrepancy and simply clicks, the link takes them through a chain of redirects to an illegitimate Luno login page. The fake resource is very similar in design to the real Luno site, but the cybercriminals did not even try to disguise the URL, apparently counting on user carelessness.

How scammers swindle credentials out of Luno users (5)

The fake login page looks like the real one, although with an entirely different URL

To keep the cryptoinvestor victim from suspecting anything is amiss, the scammers even set strict security requirements. For example, to log in to the fake site, you need to enter a strong password with the same strict requirements as the official platform.

How scammers swindle credentials out of Luno users (6)

The password requirements on the fake exchange are as strict as on the real Luno site

Next, if the victim enters their credentials and tries to log in, the screen will display a 403 Forbidden error, and that’s it, the attackers now have the password — and access to the victim’s cryptocurrency.

How scammers swindle credentials out of Luno users (7)

Error message on the fake exchange

See Also
Luno Status

How to guard against cryptophishing

Phishing remains a viable method of stealing accounts and money on cryptocurrency platforms. That said, knowing a few simple rules will help minimize the risk of getting hooked.

  • Be vigilant. Unexpected messages about large transfers, gifts, and winnings are nearly always a trick;
  • Carefully check the URL in the address bar before entering credentials. Website spoofing is a common phishing technique;
  • Don’t trust links in e-mails. Instead, bookmark the URLs of cryptocurrency wallets, exchanges, and other important services, and open them using your bookmarks;
  • Use a unique password for each cryptocurrency service (and for all other sites and services as well) so that a hack or data leak on one resource won’t affect your other accounts;
  • Install a reliable antivirus solution to protect against phishing. For example, Kaspersky Premium‘s built-in antiphishing and antifraud modules warn users about potentially dangerous sites in good time.
Tips
Sign up to receive our headlines in your inbox
How scammers swindle credentials out of Luno users (2024)

FAQs

How can you tell a scammer on Luno? ›

How to spot an impersonator
  1. Message you directly on WhatsApp, Telegram or LinkedIn, or DM you on social media pretending to be a Luno employee or trader.
  2. Contact you from a non-Luno email address, such as Gmail, Hotmail, or Yahoo.
  3. Ask for access to your Luno account or bank account.

Can someone hack your Luno account? ›

If you suspect that someone gained unauthorised access to your Luno account (that you've been hacked or fallen victim to fraud), you can temporarily suspend your account by locking it.

How trustworthy is Luno? ›

Luno aims to be the safest and most compliant crypto investment platform in the world. We take a regulation-first approach, because we believe that's the best way to keep you and your investment safe. We also have some of the most intensive security processes in crypto, according to CCData.

Is Luno available in the USA? ›

In conclusion, Luno is available in the USA, but only in 35 of the 50 states. If you are located in one of the states where Luno is available, you can create an account and start trading cryptocurrency. However, you will need to verify your identity and deposit funds before you can start buying and selling.

How can you tell if someone is a crypto scammer? ›

No legitimate business or government will ever email, text, or message you on social media to ask for money. And they will never demand that you buy or pay with cryptocurrency. Never click on a link from an unexpected text, email, or social media message, even if it seems to come from a company you know.

How can I trace a scammer who took my Bitcoin from my wallet? ›

Blockchain surveillance systems can collect metadata to look out for IP addresses linked to specific payments. An IP address may shed light on the fraudster's physical location when a given transaction was made.

Can someone hack my bitcoin wallet with my wallet address? ›

Q: Can someone steal my cryptocurrency if they have my wallet address? A: While it's unlikely someone can steal cryptocurrency with your wallet address alone, crypto wallets can be hacked through other means, such as phishing, malware, or social engineering tactics.

Can someone steal your info from Bitcoin? ›

The concepts behind blockchain technology make it nearly impossible to hack into a blockchain. However, weaknesses outside of the blockchain create opportunities for thieves. Hackers can gain access to cryptocurrency owners' cryptocurrency wallets, exchange accounts, or the exchanges themselves.

Can you get your money back from Luno? ›

Unfortunately, the way blockchain is designed means that transactions are irreversible so if the receiving wallet is not associated with Luno we cannot reverse the transaction or restore your funds.

Which country owns Luno? ›

Luno was founded in 2013 by South Africans, Marcus Swanepoel and Timothy Stranex. It is a wholly-owned investment of US-based Digital Currency Group (DCG).

Is Luno safe now? ›

Luno's industry-leading security measures work to keep your crypto safe. Luno stores 95% of crypto in “deep freeze” – multi-signature wallets protected by many layers of encryption.

How long does Luno verification take? ›

Verification should take a few minutes, or a couple of days if there are any issues. Then you're all set to be part of the cryptocurrency revolution. You don't need to verify your account if you don't plan to buy any Bitcoin. Unverified accounts can still receive, store and send cryptocurrency.

What is the most secure crypto wallet? ›

The best software wallets
  • Guarda. ...
  • Crypto.com DeFi Wallet. ...
  • Trust Wallet. Best for Binance and Binance.US users. ...
  • Exodus. Best for customer support. ...
  • ZenGo. Best for easy account recovery. ...
  • Ledger. Best hardware wallet for hot wallet integration. ...
  • Trezor. Best hardware wallet for security. ...
  • KeepKey. Best hardware wallet for price.

Which bank uses Luno? ›

When making an EFT deposit to your ZAR wallet, if you bank with ABSA, Standard Bank, Capitec, Nedbank or TymeBank, we've made things a little easier for you! Just search for “Luno” under “Public Beneficiaries”, instead of manually entering our bank details.

What is the best crypto wallet in the USA? ›

Coinbase, Ledger and Safepal offer the best bitcoin and crypto wallets according to our testing. Your cryptocurrency is only as safe as your private key. The safest place to keep this alphanumeric sequence that allows you to access your funds is in a cryptocurrency wallet. Hot wallets are connected to the internet.

How do you catch a crypto scammer? ›

Signs of a Cryptocurrency Scam
  1. Promises of Guaranteed Returns: One of the most common red flags of a cryptocurrency scam is the promise of guaranteed returns. ...
  2. Lack of Project Transparency: Legitimate cryptocurrency projects value transparency and provide detailed information about their team, technology, and roadmap.
Jul 13, 2024

Is my money safe in Luno? ›

Our infrastructure is hosted on Amazon Web Services, which offers a secure environment for Luno services to ensure the safest possible access control, data encryption, monitoring and isolation. Our internal networks are protected by firewalls and not exposed to the internet.

Can Luno reverse a transaction? ›

The simple answer is no, you can't alter crypto transactions once they've been made. These transactions are set in stone, or rather, very secure blocks.

Top Articles
Can I Retire at 62 With $400,000 in a 401(k)?
How To Save For Retirement When You Are In Your 50s | Bankrate
Jack Doherty Lpsg
Katie Pavlich Bikini Photos
Po Box 7250 Sioux Falls Sd
Methstreams Boxing Stream
Stretchmark Camouflage Highland Park
Belle Meade Barbershop | Uncle Classic Barbershop | Nashville Barbers
Craigslist Mpls Mn Apartments
Body Rubs Austin Texas
Txtvrfy Sheridan Wy
Brgeneral Patient Portal
Volstate Portal
True Statement About A Crown Dependency Crossword
LeBron James comes out on fire, scores first 16 points for Cavaliers in Game 2 vs. Pacers
Red Heeler Dog Breed Info, Pictures, Facts, Puppy Price & FAQs
Vichatter Gifs
Thotsbook Com
Inevitable Claymore Wow
Spartanburg County Detention Facility - Annex I
[Birthday Column] Celebrating Sarada's Birthday on 3/31! Looking Back on the Successor to the Uchiha Legacy Who Dreams of Becoming Hokage! | NARUTO OFFICIAL SITE (NARUTO & BORUTO)
Used Sawmill For Sale - Craigslist Near Tennessee
Log in or sign up to view
Alexander Funeral Home Gallatin Obituaries
Best Mechanics Near You - Brake Masters Auto Repair Shops
R. Kelly Net Worth 2024: The King Of R&B's Rise And Fall
Craigslist St. Cloud Minnesota
Imouto Wa Gal Kawaii - Episode 2
Tuw Academic Calendar
Santa Barbara Craigs List
Our 10 Best Selfcleaningcatlitterbox in the US - September 2024
FSA Award Package
Uky Linkblue Login
A Small Traveling Suitcase Figgerits
Hypixel Skyblock Dyes
Robot or human?
Pickle Juiced 1234
Ljw Obits
2007 Jaguar XK Low Miles for sale - Palm Desert, CA - craigslist
Wordle Feb 27 Mashable
Catchvideo Chrome Extension
Studentvue Calexico
White County
Tlc Africa Deaths 2021
John Wick: Kapitel 4 (2023)
Oakley Rae (Social Media Star) – Bio, Net Worth, Career, Age, Height, And More
Understanding & Applying Carroll's Pyramid of Corporate Social Responsibility
Unpleasant Realities Nyt
The Hardest Quests in Old School RuneScape (Ranked) – FandomSpot
Bloons Tower Defense 1 Unblocked
Latest Posts
Article information

Author: Patricia Veum II

Last Updated:

Views: 5871

Rating: 4.3 / 5 (44 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Patricia Veum II

Birthday: 1994-12-16

Address: 2064 Little Summit, Goldieton, MS 97651-0862

Phone: +6873952696715

Job: Principal Officer

Hobby: Rafting, Cabaret, Candle making, Jigsaw puzzles, Inline skating, Magic, Graffiti

Introduction: My name is Patricia Veum II, I am a vast, combative, smiling, famous, inexpensive, zealous, sparkling person who loves writing and wants to share my knowledge and understanding with you.