Jul 21, 2023
SugarDaddyMeet has learned from A Report by a cyber security solution company named Sophos that an international cryptocurrency trading scam is moving to hack and defraud millions of dollars from dating app users.
According to reports, one victim with the most losses lost a total of $87,000, while in the UK, a user lost $45,000 after being contacted through Facebook. Another user lost $25,000 after talking to someone via Grindr. The latest findings indicate the attackers have been growing their area of attacks coming out of Asia and are targeting more people in the US and Europe.
Sophos has uncovered a Bitcoin Wallet that the attackers are using to hold an amount to the tune of 1.4 million dollars worth of cryptocurrency. The money was siphoned by the attackers from the victims. This type of scam was eventually given a code name "CyrptoRom" by Sophos. "The CryptoRom scam relies heavily on social engineering at almost every stage.", says Jagadeesh Chandraiah, a senior threat researcher at Sophos.
He explains that the attackers begin their fraud by posting fake but convincing profiles on popular dating sites. Once they establish contact with the would-be victim, they then suggest transferring their conversation to another messaging platform. After which, they try to convince the target to install and invest in a fake cryptocurrency trading app.
Initially, the returns would look good. However, if the victim requests their money back and attempts to withdraw, they are refused. And the money is nowhere to be found. Chandraiah adds that their research shows the attackers are pulling millions of dollars with this scam.
“Until recently, the criminal operators mainly distributed the fake crypto apps through fake websites that resemble a trusted bank or the Apple App Store,” said Chandraiah. He further advises users to avoid falling into these scams by installing only from the Apple App Store. He opines that if something seems risky or too good to be true, it must be a scam.
Sophos further reports that aside from stealing money, they have observed these fraudsters abusing the Apple Enterprise Signature system. They use it to access and remotely tamper with the victim's iPhone devices. This Apple system was created for software developers who help organizations test new iOS apps with selected iPhone users. Developers then should submit them to the Apple Store for final approval. This means attackers can use the Apple Enterprise Signature system to distribute apps without App Store reviews, only need an Enterprise Signature profile and a certificate.
It turns out, most of the victims of CryptoRom are users/members of dating apps like Bumble, Tinder, and Grindr, on their iPhone devices. Fortunately, SugarDaddyMeet has a stringent manual review system and prohibits any member from sharing unidentified links. And to date, there are no incidents of SugarDaddyMeet members being victims of CryptoRom.
Always be wary of the person you are talking to online, especially if it is someone you don't know. Do not be easily convinced of an easy profit over a suspicious investment scheme. So far, no less than 7,000 users have already been duped out of more than 80 million dollars. According to the US Federal Trade Commission. Cryptocurrency scams from October 2020 to March 2021 have seen a 1,000% increase.
Although there have been no reports of SugardDaddyMeets members being victimized, sugar daddies and sugar babies could still be prime targets for CryptoRom.As you can imagine, one rich sugar daddy deposits millions of dollars in the fake cryptocurrency trading app, which is enough to drive any cryptocurrency hacker crazy. And sugar babies who need financial support are more likely to be deceived.
Therefore, we remind every member to beware of cryptocurrency hackers: Only install apps from the Apple App Store / Google Play, and it is best not to click on any outbound links. If anyone recommends some ‘great’ online investment scheme to you, please report it to the support center. We will process it within 24 hours.