Skip to main content

Dear Mews Community,


As a Customer Success Manager at Mews, I'm writing to alert you to a serious phishing threat affecting some of our customers. Fraudulent websites posing as the official Mews login page have led to data breaches by tricking users into entering their credentials. Here’s how you can protect yourself:

🔷The Phishing Threat

Cybercriminals have created fake sites that mimic our Mews login page, appearing in search results for "Mews login." A common deceptive URL is:

  • Official URL: https://app.mews.com
  • Fake URL: https://app.mewsz.com (Note the extra "z")

These sites aim to steal your login information.

🔷How to Stay Safe

  • Don't Google "Mews Login"

Always type the URL directly: https://app.mews.com or use a bookmark to access the official site.

  • Check the URL

Before logging in, double-check that you are on the correct Mews page. Be cautious of any slight changes in the URL.

  • Use Two-Factor Authentication (2FA)

Enable 2FA for an added layer of security. This will help protect your account even if your credentials are compromised. Read more here.

  • Inform Your Team

Educate your team and clients about these phishing threats. Regular reminders can help prevent accidental logins on fraudulent sites.

  • Report Suspicious Activity

If you think you’ve visited a fake site or accidentally shared your credentials, report it to our support immediately. Quick action can help protect your account and others.

🔷Conclusion

Staying vigilant is key to protecting our systems and client data. If you have any questions or need assistance, please reach out to me or our support team.

Thank you for your cooperation!

Hello!

You should add, that 2FA should be used!

Although, it would not necessarily help in that phishing attempts, because user entered 2FA can be routed through the phishing portal website in real time!!

This proves that TOTP 2FA alone is not enough, even though it IS annoying!

What would better help against these attacs:

  • passkeys
  • IP range restrictions (would help even without 2FA)
  • certificate based or trusted device based 2FA

Best regards,

Jean-Philipp


Reply