Chinese Bank Hosts Phishing Site - InformationWeek
IoT
IoT
News
News
3/13/2006
12:05 PM
50%
50%

Chinese Bank Hosts Phishing Site

A Chinese bank's server is hosting spoofed sites that phishers are using to dupe customers of American banks, an Internet monitoring company said Sunday.

A Chinese bank's server is hosting spoofed sites that phishers are using to dupe customers of American banks and e-tailers, a U.K.-based Internet monitoring company said Sunday.

According to Netcraft, this is the first time one bank's network has been used by criminals to steal information from another bank's customers.

The identity theft attack started Saturday when e-mails were sent to Chase Bank customers that directed them to a site hosted on IP addresses assigned to a Shanghai branch of the China Construction Bank Corp. (CCBC). The spoofed Chase and eBay sites were tucked away in hidden directories, and the CCBC's server's main page displayed a configuration error, said Netcraft.

The Chase attack takes a new phishing tack: rather than directly con gullible users into giving up account passwords or PINs by pretending to be a message from customer support, the e-mail poses as a survey of Chase's online banking sites.

Anyone who fills out the survey will supposedly receive $20 for their trouble. Naturally, the survey is bogus. Among the fields to fill out are several demanding Chase card number, PIN, Social Security number, and other private information.

"Scammers are looking for new ways to fleece the unwary, and this time [they] have come up with a new twist: asking people to help in a survey for a cash reward," said Graham Cluley, senior technology consultant for Sophos, a British security company, in a statement.

Astute users will likely notice that the URL in the phished message is a raw IP address, not a domain. That, said Netcraft, is a strong sign of a phish.

The same CCBC Shanghai server was also used Saturday to host a page that spoofed the eBay log-in screen.

China Construction Bank Corp., one of the country's "Big Four" state-owned banks, has more than 14,200 branches across China.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
How Enterprises Are Attacking the IT Security Enterprise
How Enterprises Are Attacking the IT Security Enterprise
To learn more about what organizations are doing to tackle attacks and threats we surveyed a group of 300 IT and infosec professionals to find out what their biggest IT security challenges are and what they're doing to defend against today's threats. Download the report to see what they're saying.
Register for InformationWeek Newsletters
White Papers
Current Issue
Digital Transformation Myths & Truths
Transformation is on every IT organization's to-do list, but effectively transforming IT means a major shift in technology as well as business models and culture. In this IT Trend Report, we examine some of the misconceptions of digital transformation and look at steps you can take to succeed technically and culturally.
Video
Slideshows
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Flash Poll