Cybercriminals clone bank switchboard to trick worried customers

IT security and control firm Sophos is warning computer users to be extra vigilant about any emails which claim to come from financial institutions, no matter how genuine the correspondence appears.  The warning comes as customers of a small credit union, Kessler Federal, are being targeted with phishing emails that attempt to cash in on a phishing warning posted on the organisation’s website, and entice worried customers to call a fake phone number to verify their details.

Sophos experts note that to add credibility to the phish, the cybercriminals have stuck very closely to the text used on Kessler Federal’s website and have included legitimate URLs which link to official advice pages, as well as the proper email address for reporting abuse.  However, the phishers did change the date, text and phone number at the bottom of the email in an attempt to solicit phone calls to the posted number.

When dialled, users are greeted with an automated voice which assures callers that they will not be asked for any personal information such as a Social Security number.  It then goes on to ask for the customer’s bank card number, followed by the PIN – sufficient information for the cybercriminals to steal money from the user’s bank account at a cash machine, or to transfer funds to an off-shore account.

Sophos notes that this is not the first time that voice phishing (known as “vishing”) has been used to trick innocent victims’ into parting with their bank details.  In 2006, PayPal users were targeted by a similar scam.

Don't miss