COSTA RICA
 
 HOME  • WEEK IN REVIEW • CLASSIFIEDS • FOTO GALLERY • ONLINE STORE

 

Saturday  07 July 2007

Send this page to a friend

Customers Of State Banks Targeted By  Phishers
Fiscalía Requests For Capture of Quintavalle
Inflation Drops
Taiwanese Embassy Closes After 63 Years Of Ties
Talking On Cellular Phone Cause of Triple Collision
Fund for Fairness


Customers Of State Banks Targeted By  Phishers
Internet fraud had become a thing of fashion in Costa Rica as more and more bank customers are reporting money missing from their accounts, victims of "phishing". The single largest case reported so far is of a young woman who says she lost ¢24 million colones (us$46.150) from her Banco Nacional account.

Though the state banks - Banco Nacional (BN) and Banco de Costa Rica (BCR), are the only banks that customers have reported being hit, and are not giving out many details. The other state bank, Banco Popular, and the private banks have not reported any problems.

The scam involves the customers of the bank receiving an email with a link to a page that appears to be from the Banco Nacional, but in fact if is not.

The email asks the customer to click on the link to update their personal information. The page directed to is actually used by the "phishers" to extract personal information like log in and password information that is then used by them scammers to access the real page and withdraw funds from the account.

A number of Banco Nacional customers have come forward to say that they have received such emails, most saying that they closed the fake page at once, not providing any information.

However, a customer of the Banco de Costa Rica claims to be a victim of phishing, though she tells bank officials that she never received any emails or visited a fake page of the bank's website, claiming that the had three accounts ransacked by cybernetic criminals.

Like the Banco Nacional, Banco de Costa Rica officials will not talk or provide details of an ongoing investigation.

A way not to be a victim is to not click on any links in emails from your bank, be it in or outside Costa Rica and check your account balances online frequently and report any irregularities at once. Also, change your password with frequency, once a week or more often if you feel your account is at risk and report any emails for information, or that someone has tried to access your account, to your financial institution immediately.

Most financial instituions do not ask for customers to update their account information online and any emails usuall contain the customers full name and not "dear customer" or "account holder".

What is Phishing?
Phishing is a criminal activity using social engineering techniques.Phishers attempt to fraudulently acquire sensitive information, such as usernames, passwords and credit card details, by masquerading as a trustworthy entity in an electronic communication. Online banks are common targets.

Phishing is typically carried out by email or instant messaging, and often directs users to give details at a website, although phone contact has been used as well.

The first recorded mention of phishing is on the alt.online-service.america-online Usenet newsgroup on January 2, 1996, although the term may have appeared even earlier in the print edition of the hacker magazine 2600.

The term phishing is a variant of fishing, probably influenced by phreaking,and alludes to the use of increasingly sophisticated lures to "fish" for a user's financial information and passwords. The word may also be linked to leetspeak, in which ph is a common substitution for f. The popular theory that it is a portmanteau of password harvesting is an example of folk etymology.

Most methods of phishing use some form of technical deception designed to make a link in an email (and the spoofed website it leads to) appear to belong to the spoofed organization. Misspelled URLs or the use of subdomains are common tricks used by phishers, such as this example URL, http://www.yourbank.com.example.com/. Another common trick is to make the anchor text for a link appear to be a valid URL when the link actually goes to the phishers' site.

Once the victim visits the website the deception is not over. Some phishing scams use JavaScript commands in order to alter the address bar. This is done either by placing a picture of the legitimate entity's URL over the address bar, or by closing the original address bar and opening a new one containing the legitimate URL.

Phishing example:
the following example is a real email received by insidecostarica.com on Friday 7, 2007. At ICR we receive about dozens of such emails daily from varying banks in the U.S., all with basically the same message content.
 

From: Bank of the West <[email protected]>
To: [email protected]
Subject: Official Information!
Date: Fri 7/6/2007 10;58PM

Dear Bank of the West client,

Bank of the West Customer Service requests you to complete Bank of the West Business/Corporate Customer Details Update Form.

This procedure is obligatory for all business and corporate clients of Bank of the West.

Please select the hyperlink and visit the address listed to access Bank of the West Business/Corporate Customer Details Update Form.

http://cib-id-34597171.bankofthewest.com/BOW/WebDirect/start.ac

Again, thank you for choosing Bank of the West for your business needs. We look forward to working with you.

***** Please do not respond to this email *****

This mail is generated by an automated service.
Replies to this mail are not read by Bank of the West Customer Service or technical support.
 


If you were to click on the above link (try it) you will get an error. The text link on the email is correct, however, the link actually takes you to: http://cib-id-34597171.bankofthewest.com.prontoed.tw/BOW/WebDirect/start.ac/  which is a face Bank of the West page. Notice that the page is really being hosted on the "www.prontoed.ts" website and not the "www.bankofthewest.com" website.

A click on the "prontoed" link will result in a forbidden message, however the link on the email is very similar tot he Bank of the West website. .tw is a top level domain located in Taiwan. For a list of top level domain codes click here

See for yourself how Phishing works. Click on the above links unless you are a Bank of the West customer and see for yourself how easily the unsuspecting can be fooled.

Editor's note: neither the editor or anyone associated with insidecostarica.com is a client of the Bank of the West. Until we got the email, we had never heard of the Bank of the West.

 


 

 

 
ABOUT US  •  CONTACT US  •  ADVERTISE WITH US  •  SUBSCRIBE TO OUR NEWSLETTER
©2002-2007 Insidecostarica.com. All rights reserved.