Similar Searches

Related Posts

  • Phishers Target Shaw Communications Customers (November 22, 2009)

    Trend Micro threat analysts recently found a fake Shaw Communications phishing Web page http://{BLOCKED}nadaworld.net/{very long string containing random characters}/ that asks users for their customer care login name and password.Cybercriminals can lead their victims to the said site using ...

  • Phishers Hit the Bank of Nevada (February 24, 2010)

    TrendLabs Web content security analysts recently received spammed messages (see Figure 1) purporting to come from the Bank of Nevada. At first, the attack seems just like any other common phishing attack. However, users who are tricked into clicking the URL embedded in the spammed messages will be redirected ...

  • Phishers Target “Bloggers” (February 22, 2010)

    Trend Micro’s Web Reputation Services (WRS) Operations Team recently received a phishing email claiming to be from Blogger (see Figure 1), a free blog publishing tool from Google.The spammed message instructed users to update their Blogger accounts by clicking ...

  • Beware of Targeted Scams and Phishing Attacks! (March 2, 2010)

    According to Symantec’s latest State of Spam and Phishing report, scam and phishing messages accounted for 21 percent of all spam, which is the highest level recorded since the inception of the report. For comparison, these types of spam represented only 10 percent of total spam a year ago. Historically, ...

  • TinyURL Phishing Becoming Popular (March 13, 2009)

    The language has changed but the modus operandi remains the same. Spammed messages, this time in Spanish, again use TinyURLs to mask the exact destination of the links they contain. Here’s a sample email message:Figure 1. Sample spammed message. The message above claims to be from Bancaja, ...

Related News

Related Posts

  • Phishers Target Shaw Communications Customers (November 22, 2009)

    Trend Micro threat analysts recently found a fake Shaw Communications phishing Web page http://{BLOCKED}nadaworld.net/{very long string containing random characters}/ that asks users for their customer care login name and password.Cybercriminals can lead their victims to the said site using ...

  • Phishers Hit the Bank of Nevada (February 24, 2010)

    TrendLabs Web content security analysts recently received spammed messages (see Figure 1) purporting to come from the Bank of Nevada. At first, the attack seems just like any other common phishing attack. However, users who are tricked into clicking the URL embedded in the spammed messages will be redirected ...

  • Phishers Target “Bloggers” (February 22, 2010)

    Trend Micro’s Web Reputation Services (WRS) Operations Team recently received a phishing email claiming to be from Blogger (see Figure 1), a free blog publishing tool from Google.The spammed message instructed users to update their Blogger accounts by clicking ...

  • Beware of Targeted Scams and Phishing Attacks! (March 2, 2010)

    According to Symantec’s latest State of Spam and Phishing report, scam and phishing messages accounted for 21 percent of all spam, which is the highest level recorded since the inception of the report. For comparison, these types of spam represented only 10 percent of total spam a year ago. Historically, ...

  • TinyURL Phishing Becoming Popular (March 13, 2009)

    The language has changed but the modus operandi remains the same. Spammed messages, this time in Spanish, again use TinyURLs to mask the exact destination of the links they contain. Here’s a sample email message:Figure 1. Sample spammed message. The message above claims to be from Bancaja, ...

Caisse d’Epargne Customers, Beware!

It seems that cybercriminals will really stop at nothing to further their malicious activities. Trend Micro fraud analysts received yet another spammed message obviously designed to catch unwitting Caisse d’Epargne, a French semicooperative bank, customers into their phishing trap.

Founded in 1818, with around 4,700 branches in France, Caisse d’Epargne is active in both the retail and private banking segments. It also holds a significant stake in the publicly traded investment bank, Natixis.

The spammed message informs customers that the bank found some problems with their accounts. It then informs the recipients that the bank needs them to fill in additional information by clicking an embedded link in the email to keep them protected. Clicking the link, however,  redirects users to a phishing page that looks a lot like the bank’s official website.

As expected, the phishing site asks users to enter their personal identification numbers (PINs) to validate their accounts. There are, however, noticeable differences between the phishing site (marked in red in Figure 2) and the bank’s legitimate site (marked in green in Figure 3) if only users take time out to make sure they are not being victimized by wily cybercriminals.

In fact, the bank’s legitimate site even has a security warning (marked in green in Figure 4) to all of its customers regarding the said phishing attack since January 28.

...
Read the original story


Source: Luisa Villasabas (Fraud Analyst) @ TrendLabs | Malware Blog - by Trend Micro

Write a Comment

Copyright © 2010 The Security Blog. All rights reserved.
Web Statistics Homeland Security blogs & blog posts