Customers Of State Banks
Targeted By
Phishers
Internet fraud had
become a thing of
fashion in Costa Rica as
more and more bank
customers are reporting
money missing from their
accounts, victims of "phishing".
The single largest case
reported so far is of a
young woman who says she
lost ¢24 million colones
(us$46.150) from her
Banco Nacional account.
Though the state banks -
Banco Nacional (BN) and
Banco de Costa Rica (BCR),
are the only banks that
customers have reported
being hit, and are not
giving out many details.
The other state bank,
Banco Popular, and the
private banks have not
reported any problems.
The scam involves the
customers of the bank
receiving an email with
a link to a page that
appears to be from the
Banco Nacional, but in
fact if is not.
The email asks the
customer to click on the
link to update their
personal information.
The page directed to is
actually used by the "phishers"
to extract personal
information like log in
and password information
that is then used by
them scammers to access
the real page and
withdraw funds from the
account.
A number of Banco
Nacional customers have
come forward to say that
they have received such
emails, most saying that
they closed the fake
page at once, not
providing any
information.
However, a customer of
the Banco de Costa Rica
claims to be a victim of
phishing, though she
tells bank officials
that she never received
any emails or visited a
fake page of the bank's
website, claiming that
the had three accounts
ransacked by cybernetic
criminals.
Like the Banco Nacional,
Banco de Costa Rica
officials will not talk
or provide details of an
ongoing investigation.
A way not to be a victim
is to not click on any
links in emails from
your bank, be it in or
outside Costa Rica and
check your account
balances online
frequently and report
any irregularities at
once. Also, change your
password with frequency,
once a week or more
often if you feel your
account is at risk and
report any emails for
information, or that
someone has tried to
access your account, to
your financial
institution immediately.
Most financial
instituions do not ask
for customers to update
their account
information online and
any emails usuall
contain the customers
full name and not "dear
customer" or "account
holder".
What is Phishing?
Phishing is a criminal
activity using social
engineering
techniques.Phishers
attempt to fraudulently
acquire sensitive
information, such as
usernames, passwords and
credit card details, by
masquerading as a
trustworthy entity in an
electronic
communication. Online
banks are common
targets.
Phishing is typically
carried out by email or
instant messaging, and
often directs users to
give details at a
website, although phone
contact has been used as
well.
The first recorded
mention of phishing is
on the
alt.online-service.america-online
Usenet newsgroup on
January 2, 1996,
although the term may
have appeared even
earlier in the print
edition of the hacker
magazine 2600.
The term phishing is a
variant of fishing,
probably influenced by
phreaking,and alludes to
the use of increasingly
sophisticated lures to
"fish" for a user's
financial information
and passwords. The word
may also be linked to
leetspeak, in which ph
is a common substitution
for f. The popular
theory that it is a
portmanteau of password
harvesting is an example
of folk etymology.
Most methods of phishing
use some form of
technical deception
designed to make a link
in an email (and the
spoofed website it leads
to) appear to belong to
the spoofed
organization. Misspelled
URLs or the use of
subdomains are common
tricks used by phishers,
such as this example
URL, http://www.yourbank.com.example.com/.
Another common trick is
to make the anchor text
for a link appear to be
a valid URL when the
link actually goes to
the phishers' site.
Once the victim visits
the website the
deception is not over.
Some phishing scams use
JavaScript commands in
order to alter the
address bar. This is
done either by placing a
picture of the
legitimate entity's URL
over the address bar, or
by closing the original
address bar and opening
a new one containing the
legitimate URL.
Phishing example:
the following example is
a real email received by
insidecostarica.com on
Friday 7, 2007. At ICR
we receive about dozens
of such emails daily
from varying banks in
the U.S., all with
basically the same
message content.
From: Bank of
the West
<[email protected]>
To: [email protected]
Subject:
Official
Information!
Date: Fri
7/6/2007 10;58PM
Dear Bank of the
West client,
Bank of the West
Customer Service
requests you to
complete Bank of
the West
Business/Corporate
Customer Details
Update Form.
This procedure
is obligatory
for all business
and corporate
clients of Bank
of the West.
Please select
the hyperlink
and visit the
address listed
to access Bank
of the West
Business/Corporate
Customer Details
Update Form.
http://cib-id-34597171.bankofthewest.com/BOW/WebDirect/start.ac
Again, thank you
for choosing
Bank of the West
for your
business needs.
We look forward
to working with
you.
***** Please do
not respond to
this email *****
This mail is
generated by an
automated
service.
Replies to this
mail are not
read by Bank of
the West
Customer Service
or technical
support.
|
If you were to
click on the above link
(try it) you will get an
error. The text link on
the email is correct,
however, the link
actually takes you to:
http://cib-id-34597171.bankofthewest.com.prontoed.tw/BOW/WebDirect/start.ac/
which is a face
Bank of the West page.
Notice that the page is
really being hosted on
the "www.prontoed.ts"
website and not the "www.bankofthewest.com"
website.
A click on the "prontoed"
link will result in a
forbidden message,
however the link on the
email is very similar
tot he Bank of the West
website. .tw is a top
level domain located in
Taiwan. For a list of
top level domain codes
click here
See for yourself how
Phishing works. Click on
the above links
unless you are a Bank
of the West customer
and see for
yourself how easily the
unsuspecting can be
fooled.
Editor's note: neither
the editor or anyone
associated with
insidecostarica.com is a
client of the Bank of
the West. Until we got
the email, we had never
heard of the Bank of the
West. |