Watch out - that Netflix offer might be a phishing scam

Fake Netflix Landing Page
(Image credit: Kaspersky)

As streaming services have become the go-to way to watch content online, cybercriminals have begun capitalizing on their popularity by tricking unsuspecting users into signing up for fake services or giving up the credentials to their legitimate accounts.

According to a new report from the cybersecurity firm Kaspersky, phishing scams impersonating Netflix, Disney Plus and other popular streaming services are increasingly being used to coax users into giving up their credit card details and other payment information. These scams involve creating fake landing pages for streaming services and getting users to login using their existing credentials to harvest them or having them create an entirely new account. See anything off about the image at the top of this article for instance?

Another way in which scammers are targeting streaming service users is by threatening to block access to their existing subscriptions. One recent example found by Kaspersky appeared as an email saying a user's account was on hold and asked them to update their payment method with a big, red button with the text: “UPDATE YOUR ACCOUNT NOW”. However, this example was easy to spot as a phishing attempt since customer was spelled as “costumer” and the email was signed “Your friends at Netflix”.

Cybercriminals have also started using popular shows to attract fans that don't have subscriptions by offering them the opportunity to watch a show on a fake website. For instance, Kaspersky found an unofficial page that invites fans to watch or download The Mandalorian. This page also showed a short clip cut from trailers to make it look like a new, previously unaired episode. If a user falls for this scam, they are then asked to sign up for a low-cost subscription to continue watching while unknowingly handing over their payment details and email address to scammers.

Hijacked streaming accounts

In addition to stealing credit card details, cybercriminals are also interested in obtaining streaming service account credentials which they then sell on the Dark Web.

Since Netflix, Hulu and most other streaming services allow multiple people to watch content from the same account, a user could log on to find that their credentials have been sold to others and they'll need to wait for them to finish watching before they can do so themselves.

As password reuse across multiple online accounts continues to be a problem, cybercriminals could get access to your credentials for one site and then login to your other accounts. This is why it's highly recommended that use a password generator to create strong, unique passwords for all of your accounts and many password managers also have this feature built-in.

To avoid falling victim to streaming service scams online, Kaspersky recommends that users avoid clicking on links in emails and go to the official website instead, pay attention to phishing red flags such as misspelled words, use different passwords for all of their online accounts and as always, keep in mind that if something seems too good to be true, like a long lost episode of Disney's The Mandalorian, then it probably is.

Also check out our roundup of the best identity theft protection and our list of the best malware removal software

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Paper craft illustration of a suspicious email that contains a snake
How to spot a phishing email
Fraude en ligne phishing
Google forced to step up phishing defenses following ‘most sophisticated attack’ it has ever seen
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Everything you need to know about phishing
A man falling into a mobile phone screen.
Safer Internet Day: how to avoid online scams and stay safe online
An illustration of a hooded hacker with an obscured face holding a large fingerprint against a red background.
ID theft – what happens when someone steals your identity
A TV remote pointing at YouTube logo
YouTube warns of phishing video using its CEO as bait
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand