EE email scam tricks users into giving away payment details

(Image credit: Shutterstock / La1n)

EE customers have been told to take care concerning any messages they receive from the company following the detection of a dangerous new phishing threat.

Security researchers at Cofense have uncovered a new spear-phishing campaign that spoofs messages from the UK's largest mobile phone network, to try and steal personal information. 

The emails detected by the Cofense Phishing Center used official EE imagery, luring victims with the subject line "View Bill -Error". The message within reported there has been an issue with the customer's payment, urging them to update their details with EE.

EE phishing

The campaign appears to largely target the login and payment details of corporate executives, which could give hackers access to lucrative business networks.

However clicking on the hyperlink included in the email (pictrued below) takes the victim to a phishing page. Although this fake page sports a supposedly-secure HTTPS URL, this looks to be down to the hackers obtaining SSL certificates to make the site look legitimate. 

(Image credit: Cofense)

After completing the form on the fake site, which in the process sends this information to the criminals, the user is then redirected to the actual EE login site, making them think their session may have timed out, or their password was typed incorrectly.

Cofense notes that users can often spot phishing emails due to errors and shortcomings in the design of the messages, despite the use of legitimate-seeming design. The team note that in this example, EE’s trademark and company name is not included in any part of the full email address, which instead comes from a completely separate domain.

Having an updated and thorough cybersecurity platform is also vital in protecting users from threats, as the page still seems to be live and active now.

Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
MacBook Air mute key
The new M4 MacBook Air finally fixes an Apple keyboard annoyance that's been around for decades
A collage of Ellie and Joel in The Last of Us season 2
The Last of Us season 2's new trailer teases a huge showdown between Bella Ramsey's Ellie and Pedro Pascal's Joel, but the big moment I'm waiting for is still being held back
Apple iPhone 16 Pro Max REVIEW
New iPhone 17 Air leak may have revealed some key specs – and how it compares to the iPhone 17 Pro Max
Gaming with AI
I asked Gemini to play a text-based adventure game with me and the AI whisked me away to a word-based fantasy
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price