Netflix and Disney Plus fakes are stealing personal data - here’s how to stay safe

(Image credit: Shutterstock / wutzkohphoto)

Researchers have identified more than 700 malicious Netflix and Disney+ clones being used by scammers to scrape victims’ personal data.

The fraudulent websites either steal funds directly via fake subscriptions, or harvest credit card data and login credentials to be used at a later date.

Some of the clones are said to look extremely convincing, although the majority are reportedly characterised by their amateur design and syntax errors.

Netflix scams

Between April 6 and 13 alone, cybersecurity firm Mimecast identified roughly 700 websites mimicking Netflix, the world’s most popular streaming service. The firm also discovered four clones of smaller streaming platform Disney+ in the same period.

The appetite for content streaming has skyrocketed in recent weeks as people endeavour to entertain themselves under coronavirus lockdown. As a result, Netflix’s market value has surged to $192 billion, in a period in which the vast majority of businesses have seen their share price fall through the floor. 

Although the precise increase in Netflix subscribers is unknown, the company is expected to announce its quarterly earnings on April 21, which should shed light on the extent of its recent success.

According to Carl Wearn, cybercrime lead at Mimecast, the increase in streaming on all manner of platforms is likely to pique the interest of hackers.

“We have seen a dramatic rise in suspicious domains impersonating a variety of streaming giants for nefarious purposes,” he said.

“These spoof websites often lure unsuspecting members of the public in with an offer of free subscriptions to steal valuable data. The data harvested includes names, addresses and other personal information.”

The theft of data of this kind can open the door to a practice known as credential stuffing, whereby cybercriminals use stolen credentials to gain unauthorised access to a host of online services.

For this reason, users are advised to use unique passwords and protect accounts with multi-factor authentication where possible, especially if they suspect they have fallen victim to a fraudulent website.

Users should also check websites for spelling errors and incongruous formatting, and ensure URLs do not contain any irregularities.

Via The Guardian

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Latest in Security
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
AMD logo
Security flaw means AMD Zen CPUs can be "jailbroken"
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
A hacker wearing a hoodie sitting at a computer, his face hidden.
Experts warn this critical PHP vulnerability could be set to become a global problem
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
A close-up of a phone screen showing the Telegram, Signal and WhatsApp apps
Agentic AI has “profound” issues with security and privacy, Signal President says
Latest in News
DVDs in a pile
Warner Bros is replacing some DVDs that ‘rot’ and become unwatchable – but there’s a big catch that undermines the value of physical media
A costumed Matt Murdock smiles at someone off-camera in Netflix's Daredevil TV show
Daredevil: Born Again is Disney+'s biggest series of 2025 so far, but another Marvel TV show has performed even better
Nintendo Switch 2
A Nintendo Switch 2 FCC filing confirms Wi-Fi 6 and NFC support for the upcoming console
Google Pixel 8 review Pixel 8 Pro cameras
Is your Google Pixel 9 screen flickering or are the haptics a lot more intense? You aren't alone, and thankfully there's a fix
Motorola Edge 50 Pro lavender
Your next Android bargain? Major Motorola leak teases details of multiple 2025 phones – including the Edge 60 series
Matt Murdock holding a phone to his right ear in a prison in Daredevil: Born Again episode 2
What time is Daredevil: Born Again episode 3 going to be released on Disney+?