HSBC Internet Banking scam - heads up

HSBC Internet Banking scam - heads up

Author
Discussion

texasjohn

Original Poster:

3,687 posts

237 months

Sunday 24th January 2010
quotequote all
Just a heads up if you use HSBC internet banking.

When you log in, on the page that you see after entering your 'IB number', if a third box appears asking for your full security number do NOT enter it. Close your browser and contact HSBC fraud dept 08456 100194.

Seems to be a very clever scam.

The address bar reads https://www.hsbc.co.uk

I was on the internet via a secure VPN link (work laptop) when I saw this last night.


Gibson70

464 posts

211 months

Sunday 24th January 2010
quotequote all
Thanks for the warning. My wife has HSBC online banking so I'll tell her about this.

Thanks

ShadownINja

77,366 posts

288 months

Sunday 24th January 2010
quotequote all
How'd they do that then?

texasjohn

Original Poster:

3,687 posts

237 months

Sunday 24th January 2010
quotequote all
God knows

When I spoke to the fraud team they didn't say anything to indicate that this is affecting lots of people today, but then I guess you don't want your customers to know if that is indeed the case!

See the enclosed picture. I have 'circled' the part which is not normal and leads to your full code number being visible to the fraudster.


V8mate

45,899 posts

195 months

Sunday 24th January 2010
quotequote all
I'd say that it's a genuine page and that it's an internal cock-up or employee-driven scam.

texasjohn

Original Poster:

3,687 posts

237 months

Sunday 24th January 2010
quotequote all
Tell me about it.

Emails asking you to verify your login details are one thing, but this is another matter. Address bar looks legit, etc.

One thing I did notice is that the first time I went onto the HSBC website my IE window closed itself and I had to open IE again, on the second opening of IE some of the IE tools were switched off (phishing filter was turned off).

R60EST

2,364 posts

188 months

Sunday 24th January 2010
quotequote all
On RBS login , when you are on the genuine page the address bar goes green. Does this normally happen with HSBC when all is legit ?

texasjohn

Original Poster:

3,687 posts

237 months

Sunday 24th January 2010
quotequote all
Not in my experience it doesnt...

R60EST

2,364 posts

188 months

Sunday 24th January 2010
quotequote all
The green bar is supposed to make it much harder for the scammer to replicate , although I'm sure they're on the case


texasjohn

Original Poster:

3,687 posts

237 months

Sunday 24th January 2010
quotequote all
Not sure if it makes a difference but work laptop I saw it on is Windows XP with IE7

I was connected to the net via our 'secure' VPN at the time I took the screenshot too.

R60EST

2,364 posts

188 months

Sunday 24th January 2010
quotequote all
I think the green is part of anti phishing stuff that comes with IE8 . It turns red when the site is suspect

jagracer

8,248 posts

242 months

Sunday 24th January 2010
quotequote all
texasjohn said:
Just a heads up if you use HSBC internet banking.

When you log in, on the page that you see after entering your 'IB number', if a third box appears asking for your full security number do NOT enter it. Close your browser and contact HSBC fraud dept 08456 100194.

Seems to be a very clever scam.

The address bar reads https://www.hsbc.co.uk

I was on the internet via a secure VPN link (work laptop) when I saw this last night.
That link looks and appears genuine and leads to the normal log on page. I tried it and it went to the normal DOB and password requests although I didn't use my proper ib number and stopped at the next page. Whilst it hunts for the next page the progress bar at the bottom does say "searching hsbc for data" so maybe what you hve is a cock up or internal scam.

R60EST said:
On RBS login , when you are on the genuine page the address bar goes green. Does this normally happen with HSBC when all is legit ?
The favicon section of the HSBC site turns green as it logs on.

Edited by jagracer on Sunday 24th January 18:11

TonyToniTone

3,627 posts

255 months

Sunday 24th January 2010
quotequote all
A lot of these scams do use the genuine home page..

http://en.wikipedia.org/wiki/Cross-site_scripting
http://www.theregister.co.uk/2008/06/25/hsbc_scrip... <- from 08 I know..

TooLateForAName

4,818 posts

190 months

Sunday 24th January 2010
quotequote all
I was thinking some sort of cross site exploit.

But why on earth are you using XP and an old version of ie for internet banking?

might be interesting to look at the page source for that page. Worth taking a copy and forwarding to their fraud team (make sure to get any script pages as well)

Edited by TooLateForAName on Sunday 24th January 21:45

JumboBeef

3,772 posts

183 months

Monday 25th January 2010
quotequote all
texasjohn said:
Just a heads up if you use HSBC internet banking.

When you log in, on the page that you see after entering your 'IB number', if a third box appears asking for your full security number do NOT enter it. Close your browser and contact HSBC fraud dept 08456 100194.

Seems to be a very clever scam.

The address bar reads https://www.hsbc.co.uk

I was on the internet via a secure VPN link (work laptop) when I saw this last night.
I don't understand this thread. We have three business HSBC accounts, and it ALWAYS asks for the full number to be entered, which we do. That's the way it has always been, what's the problem?

jagracer

8,248 posts

242 months

Monday 25th January 2010
quotequote all
JumboBeef said:
texasjohn said:
Just a heads up if you use HSBC internet banking.

When you log in, on the page that you see after entering your 'IB number', if a third box appears asking for your full security number do NOT enter it. Close your browser and contact HSBC fraud dept 08456 100194.

Seems to be a very clever scam.

The address bar reads https://www.hsbc.co.uk

I was on the internet via a secure VPN link (work laptop) when I saw this last night.
I don't understand this thread. We have three business HSBC accounts, and it ALWAYS asks for the full number to be entered, which we do. That's the way it has always been, what's the problem?
The problem is that if someone has hacked your computer they have your full number. I have a few different internet bank accounts and none of them ask for the entire password.

V8mate

45,899 posts

195 months

Monday 25th January 2010
quotequote all
JumboBeef said:
texasjohn said:
Just a heads up if you use HSBC internet banking.

When you log in, on the page that you see after entering your 'IB number', if a third box appears asking for your full security number do NOT enter it. Close your browser and contact HSBC fraud dept 08456 100194.

Seems to be a very clever scam.

The address bar reads https://www.hsbc.co.uk

I was on the internet via a secure VPN link (work laptop) when I saw this last night.
I don't understand this thread. We have three business HSBC accounts, and it ALWAYS asks for the full number to be entered, which we do. That's the way it has always been, what's the problem?
My HSBC business account needs a number from the little key-ring thingy; no remembered numbers involved.

texasjohn

Original Poster:

3,687 posts

237 months

Monday 25th January 2010
quotequote all
JumboBeef said:
texasjohn said:
Just a heads up if you use HSBC internet banking.

When you log in, on the page that you see after entering your 'IB number', if a third box appears asking for your full security number do NOT enter it. Close your browser and contact HSBC fraud dept 08456 100194.

Seems to be a very clever scam.

The address bar reads https://www.hsbc.co.uk

I was on the internet via a secure VPN link (work laptop) when I saw this last night.
I don't understand this thread. We have three business HSBC accounts, and it ALWAYS asks for the full number to be entered, which we do. That's the way it has always been, what's the problem?
Business log in might well be different to personal banking.

The fact is, for personal banking it is usually only the first field (some of your number but not all of them).

ETA: If you have a key ring passcode (as described in the post above) lcd display which changes every minute or so, then that is quite a bit more secure, I would imagine. You don't have this device for personal banking accounts.

I have the key ring device for my VPN log in to the work server. RSA SecureID thing.

Edited by texasjohn on Monday 25th January 20:12

JumboBeef

3,772 posts

183 months

Monday 25th January 2010
quotequote all
Right. Yes, business accounts have a 'thingy' which gives you a new number each time.

Scooby_snax

1,279 posts

260 months

Monday 25th January 2010
quotequote all
R60EST said:
I think the green is part of anti phishing stuff that comes with IE8 . It turns red when the site is suspect
You will have downloaded Trusteer Rapport from the RBS site which gives protection. Incidentally you can also use it on other payment sites once downloaded, somehow Trusteer identifies if the page is a spoof page