Cloud storage payment scam floods inboxes with fake renewals
嗯,用户让我帮忙总结一篇文章,控制在100字以内,而且不需要特定的开头。首先,我需要通读整篇文章,抓住主要内容。 文章讲的是最近几个月出现的一个大规模云存储订阅诈骗活动。骗子通过发送大量钓鱼邮件,谎称用户的照片、文件和账户即将被封锁或删除,因为支付失败。邮件看起来像是来自不同的云服务提供商,比如Google Drive、OneDrive等。 这些邮件的目的是制造紧迫感,让用户赶紧点击链接解决问题。链接实际上会引导到一个钓鱼网站,要求用户提供信用卡信息购买无关的产品,比如VPN服务或安全软件。这些网站看起来很真实,甚至有云服务的标志和品牌。 文章还提到,合法的云服务提供商不会发送这样的邮件来解决支付问题,也不会直接删除用户的文件,而是限制访问或在较长时间后删除。因此,用户应该删除这些邮件,并不要点击链接或购买任何产品。 总结一下,主要内容是诈骗活动的手段、目标、钓鱼邮件的特点以及防范建议。我需要把这些信息浓缩到100字以内,并且用简洁的语言表达出来。 </think> 近期全球范围内出现大规模云存储订阅诈骗活动。骗子通过伪造来自Google Drive、OneDrive等云服务提供商的钓鱼邮件,谎称用户账户因支付问题即将被封锁或删除文件。邮件包含虚假账户ID和截止日期,并诱导用户点击链接至钓鱼网站购买无关产品。合法云服务不会通过此类方式处理支付问题。 2026-1-31 16:45:17 Author: www.bleepingcomputer.com(查看原文) 阅读量:0 收藏

Cloud storage

Over the past few months, a large-scale cloud storage subscription scam campaign has been targeting users worldwide with repeated emails falsely warning recipients that their photos, files, and accounts are about to be blocked or deleted due to an alleged payment failure.

Based on numerous emails seen by BleepingComputer, the campaign has escalated over the past few months, with people receiving multiple versions of the scam each day, all appearing to be sent by the same scammers.

While the email text, the messages all attempt to create a sense of urgency by claiming a payment problem or storage issue must be resolved immediately, or people's files will be deleted or blocked.

Wiz

The cloud storage scam email campaign

The phishing emails originate from a wide range of domains, with most appearing to be randomly generated for the spam campaign, as shown in the sample list below.

[email protected]
[email protected]
[email protected]
[name][email protected]

The emails themselves use a wide variety of subject lines, all designed to scare a recipient into opening the email.

Example subject lines seen by BleepingComputer include:

  • Immediate Action Required. Payment Declined
  • Cloud Storage 1TB: Payment overdue
  • [personal name]¸Your Account Has been Blocked! Your Photos and Videos will be Removed Fri,30 Jan-2026. take action!!
  • We've blocked your account!  Your photos and videos will be deleted . Renew your subscription for free now!
  • [personal name] - Your store is full , click to check and save 80% , ID#88839
  • [personal name], Your Cloud Account has been locked on Mon,26 Jan-2026. Your photos and videos will be removed!
  • Sorry [<personal email address>], We Have To Suspend Your Account Today ! Sat,24 Jan-2026
  • [name] - Your store is full , click to check and save 80%
  • Cloud Storage 1TB: Payment overdue

Many of the subject lines are personalized with the recipient's name or email address and include specific dates or identifiers to increase urgency and make the messages appear legitimate.

The email seen by BleepingComputer claim that a cloud subscription renewal failed or that a payment method has expired, with recipients warned that backups may stop syncing and that photos, videos, documents, and device backups could be lost if the issue is not resolved.

One of the many cloud storage lockout emails being sent worldwide
One of the many cloud storage lockout emails being sent worldwide
Source: BleepingComputer

The emails seen by BleepingComputer claim that a cloud subscription renewal failed or that a payment method has expired, and warn recipients that backups may stop syncing and that photos, videos, documents, and device backups could be lost if the issue is not resolved.

The messages frequently include made-up account IDs, subscription numbers, and expiration dates to add legitimacy.

"Your Cloud Subscription Is at Risk. We couldn't process your most recent payment. If not resolved, your Cloud storage and backups may be paused," reads an email seen by BleepingComputer.

"Immediate Action Required Please verify or update your payment method as soon as possible to avoid losing access to your photos, files, and device backups."

All spam emails in this campaign contained a link to https://storage.googleapis.com/, which is part of Google Cloud Storage, where threat actors hosted static redirector HTML files. When a visitor clicks this, the URL redirects them to a scam/phishing site hosted on random domains.

All of the links tested by BleepingComputer lead to the same set of scam pages.

The phishing pages impersonate cloud service portals and prominently display cloud-themed branding, including the Google Cloud logo. The web pages claim the user's cloud storage is full and warn that photos, videos, contacts, files, and private data are no longer being backed up and will be deleted.

"Because you've exceeded your storage plan, your documents, contacts, and device data are no longer backing up to Cloud and your photos and videos are not uploading to Cloud Photos. Cloud Drive and Cloud-enabled apps are not updating across your devices," reads the phishing site shown below.

"Your data will be lost without security protection if no urgent action is taken."

 Phishing page warns that your cloud storage is full
Phishing page warns that your cloud storage is full
Source: BleepingComputer

Clicking on the "Continue" button brings targets to a fake storage scan that always reports that Photos, Cloud Drive, and Mail are all full. The pages then warn that data will be lost unless the cloud storage is upgraded, claiming that the person is eligible for a limited-time "loyalty" upgrade at an 80% discount.

However, after clicking the update storage button, instead of being taken to a legitimate cloud services page, you are redirected to affiliate marketing pages promoting unrelated products.

Products promoted in this phishing campaign include VPN services, little-known security software, and other subscription-based offerings with no connection to cloud storage.

The pages ultimately lead to checkout forms designed to collect credit card details and generate affiliate revenue for the threat actors behind the campaign.

Unfortunately, many people who receive these emails may not realize they're scams and purchase a product they don't need, thinking it will solve the fake cloud storage issues.

It is important to understand that these emails and landing pages are not legitimate cloud service notifications. Furthermore, legitimate cloud providers do not send emails that lead to storage scans or third-party security or VPN products to resolve billing issues.

Furthermore, most legitimate cloud storage providers will block access to your additional storage when you fail to make a payment, rather than deleting your files immediately.

For example, Google says that if a Google Drive plan is canceled, you will lose access to your additional storage until you make a payment again, and your files will only be deleted after 2 years.

Microsoft OneDrive follows a similar approach but says it may delete files after 6 months if the account exceeds its allocated storage.

Users who receive these spam messages should delete them without clicking any links and not purchase anything promoted through the emails.

As the campaign's goal is to scare recipients into unnecessary purchases, ignoring these messages is the best course of action.

Any concerns about cloud storage or billing should instead be checked manually by visiting the official website or app of the legitimate cloud service.

Wiz

The 2026 CISO Budget Benchmark

It's budget season! Over 300 CISOs and security leaders have shared how they're planning, spending, and prioritizing for the year ahead. This report compiles their insights, allowing readers to benchmark strategies, identify emerging trends, and compare their priorities as they head into 2026.

Learn how top leaders are turning investment into measurable impact.


文章来源: https://www.bleepingcomputer.com/news/security/cloud-storage-payment-scam-floods-inboxes-with-fake-renewals/
如有侵权请联系:admin#unsafe.sh