Pinterest has burst onto the social networking scene, and it has caught everyone's attention--including the online scammers. Pinterest has exploded onto the social networking scene as the new hot thing to do. Beware what you click on or pin, though. The skyrocketing popularity of the site isn’t lost on cyber criminals, and the very nature of the site makes it ripe for exploitation by online scammers.At the root of the issue is that Pinterest is built on a behavior that is generally frowned upon from a security perspective–clicking on things. Users pin linked images to virtual corkboards, and followers click on the images/links to see what all the fuss is about, and perhaps re-pin it to their own Pinterest boards.So, what happens when someone inserts an image linked to a malicious script or site? According to Symantec, survey scammers have discovered the wonder of Pinterest, and have begun to take advantage of it.Survey scams usually come with the promise of some reward–“just take 30 seconds to complete our survey and we’ll reward you with a $100 gift card.” If a Pinterest user takes the initial bait and clicks on the image, he or she is redirected to an external website, and that is where the “fun” begins. First, these scams typically require that the user re-pin the image to their own Pinterest boards in order to continue on to access the survey and earn the reward. Re-pinning the image helps propagate it to a wider audience of Pinterest users who will likely click on the image as well because the person re-pinning it is a person they trust. Rinse and repeat as those users click through and also re-pin the image to participate in the survey themselves.Eventually, the scam will ask the user to complete a survey, or register for something, or share personal information, or some other shady thing the Pinterest user should not be doing. According to Symantec, the scams are typically tied to some sort of cost-per-action based compensation network. Each duped Pinterest user represents somewhere between one and 64 dollars. These attacks may be new to Pinterest because Pinterest itself is new. But, the concept of survey scams and other phishing attacks is certainly nothing new. The same security practices and common sense that shield users from attacks on Facebook, or Twitter, or the Internet at large apply on Pinterest as well.Simply put–don’t click on anything if you don’t know what it links to. Granted, as mentioned earlier that’s virtually impossible on Pinterest. The whole point of Pinterest is to share things visually, and click on stuff in order to find out what it is.But, users should still exercise some cautious skepticism and be careful. When a link starts taking you to sites that seem shady, or demand that you re-pin the image as well as a condition of learning more, that should be an automatic red flag. Related content news analysis Attackers breach US government agencies through ColdFusion flaw Both incidents targeted outdated and unpatched ColdFusion servers and exploited a known vulnerability. By Lucian Constantin Dec 06, 2023 5 mins Advanced Persistent Threats Advanced Persistent Threats Advanced Persistent Threats news BSIMM 14 finds rapid growth in automated security technology Embrace of a "shift everywhere" philosophy is driving a demand for automated, event-driven software security testing. By John P. Mello Jr. Dec 06, 2023 4 mins Application Security Network Security news Almost 50% of organizations plan to reduce cybersecurity headcounts: Survey While organizations are realizing the need for knowledgeable teams to address unknown threats, they are also looking to reduce their security headcount and infrastructure spending. By Gagandeep Kaur Dec 06, 2023 4 mins IT Jobs Security Practices feature 20 years of Patch Tuesday: it’s time to look outside the Windows when fixing vulnerabilities After two decades of regular and indispensable updates, it’s clear that security teams need take a more holistic approach to applying fixes far beyond the Microsoft ecosystem. By Susan Bradley Dec 06, 2023 6 mins Patch Management Software Threat and Vulnerability Management Windows Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe