Beware - Bank Fraud!
Author
Discussion

Kentish

Original Poster:

15,169 posts

263 months

Tuesday 12th July 2005
quotequote all
Had this e-mail the other day, from someone with the e-mail address of "Lauren" <RYXX_MJ@parker.com> claiming to be part of HSBC, interestingly it says "if you do not have an online banking account with HSBC® then this message does not apply to you and you may ignore this message" which I don't: -


Dear valued HSBC® member,

Due to concerns, for the safety and integrity of the online banking community we have issued the following warning message.

It has come to our attention that your HSBC® account information needs to be updated as part of our continuing commitment to protect your account and to reduce the instance of fraud on our website. If you could please take 5-10 minutes out of your online experience and renew your records you will not run into any future problems with the online service. However, failure to confirm your records may result in your account suspension.

Once you have confirmed your account records your internet banking service will not be interrupted and will continue as normal.

To confirm your bank account records please http://hsbc.serti016.com/index.html" target="_blank">click here.

Note:

This e-mail was sent on behalf of the online banking community, if you do not have an online banking account with HSBC® then this message does not apply to you and you may ignore this message.


--------------------------------------------------------------------------------

Thank you for your time,


HSBC® Billing Department.

alexkp

16,484 posts

273 months

Tuesday 12th July 2005
quotequote all
These crop up at the rate of several a week. Your email address has obviously just popped up on the scammer's radar.

You will probably get plagued by them now, as I do.

ProPlus

3,810 posts

269 months

Tuesday 12th July 2005
quotequote all
Kentish said:
Had this e-mail the other day, from someone with the e-mail address of "Lauren" <RYXX_MJ@parker.com> claiming to be part of HSBC, interestingly it says "if you do not have an online banking account with HSBC® then this message does not apply to you and you may ignore this message" which I don't: -


Dear valued HSBC® member,

Due to concerns, for the safety and integrity of the online banking community we have issued the following warning message.

It has come to our attention that your HSBC® account information needs to be updated as part of our continuing commitment to protect your account and to reduce the instance of fraud on our website. If you could please take 5-10 minutes out of your online experience and renew your records you will not run into any future problems with the online service. However, failure to confirm your records may result in your account suspension.

Once you have confirmed your account records your internet banking service will not be interrupted and will continue as normal.

To confirm your bank account records please http://hsbc.serti016.com/index.html" target="_blank">click here.

Note:

This e-mail was sent on behalf of the online banking community, if you do not have an online banking account with HSBC® then this message does not apply to you and you may ignore this message.


--------------------------------------------------------------------------------

Thank you for your time,


HSBC® Billing Department.

Cheers for that.

Have passed it on to our security department, I suspect someone is going to get shut down and traced pretty damn quick.

Si

MilnerR

8,273 posts

287 months

Tuesday 12th July 2005
quotequote all
Have a look on the 419eater forums. They have a forum that deals with fake bank sites used for 419 scams and phishing scams. The way they are dealt with is usually a stiff letter to the provider or it gets added to ladvampire and is killed that way:

www.aa419.org/vampire/ladvampire.html

If you have any computers running with spare bandwidth then load this page up; what it does is constantly reloads the images on fake bank sites which will cost the guy who set the site up a fortune and hopefully get it taken down when the bandwidth limit is reached. Its not illegal and its not a denial of service attack, all it does is contantly relaod the fake bank web pages (like hitting the refresh button repeatedly)
These internet scamers are the scum of the earth, there are already scam emails doing the rounds using the tragic events in London to extract money from well meaning people

philthy

4,697 posts

269 months

Tuesday 12th July 2005
quotequote all
www.aa419.org/vampire/ladvampire.html

That is brilliant !!!
1Mb connection, no download limits for me, I'm certainly going to use some bandwidth for them.


Phil

Kentish

Original Poster:

15,169 posts

263 months

Tuesday 12th July 2005
quotequote all
MilnerR said:
These internet scamers are the scum of the earth, there are already scam emails doing the rounds using the tragic events in London to extract money from well meaning people


Bastads!

branflakes

2,039 posts

267 months

Tuesday 12th July 2005
quotequote all
MilnerR said:
If you have any computers running with spare bandwidth then load this page up; what it does is constantly reloads the images on fake bank sites which will cost the guy who set the site up a fortune and hopefully get it taken down when the bandwidth limit is reached. Its not illegal and its not a denial of service attack, all it does is contantly relaod the fake bank web pages (like hitting the refresh button repeatedly)


Here is an prime example of why stupid people should not be allowed to use computers, and all others should recieve training before being allowed to use them. If you use this with the intention of overloading the target webserver, you are helping to perform a DoS attack and it is illegal. If successful, you don't just affect the site you are targetting but every other site hosted on that server. There may be no other sites hosted, there may be hundreds - you just don't know. There is also a good chance that the scammer has hacked his way into someone elses hosting account, in which case some innocent party is gonna end up paying for it.

anhamgrimmar

1,025 posts

260 months

Tuesday 12th July 2005
quotequote all
branflakes said:

MilnerR said:
snip...



Here is an prime example of why stupid people should not be allowed to use computers, and all others should recieve training before being allowed to use them. If you use this with the intention of overloading the target webserver, you are helping to perform a DoS attack and it is illegal. If successful, you don't just affect the site you are targetting but every other site hosted on that server. There may be no other sites hosted, there may be hundreds - you just don't know. <i>There is also a good chance that the scammer has hacked his way into someone elses hosting account, in which case some innocent party is gonna end up paying for it.</i>



my italics
but surely, by youre quote, people should be trained so as to avoid this eventuality.

branflakes

2,039 posts

267 months

Tuesday 12th July 2005
quotequote all
anhamgrimmar said:

but surely, by youre quote, people should be trained so as to avoid this eventuality.


Okay, so perhaps the comment about stupid people and training for all was a biiit over the top (and apologies to MilnerR - didn't mean to imply you were stupid), but people really do need to consider learning how these things work before deciding on revenge. Servers I've had websites on in the past have been hacked and then used for scams like these, and it's bloody annoying to find your websites don't work thanks to the combined efforts of scammers and vigilantes without a clue.

philthy

4,697 posts

269 months

Tuesday 12th July 2005
quotequote all
branflakes said:


Here is an prime example of why stupid people should not be allowed to use computers, and all others should recieve training before being allowed to use them. If you use this with the intention of overloading the target webserver, you are helping to perform a DoS attack and it is illegal. If successful, you don't just affect the site you are targetting but every other site hosted on that server. There may be no other sites hosted, there may be hundreds - you just don't know. There is also a good chance that the scammer has hacked his way into someone elses hosting account, in which case some innocent party is gonna end up paying for it.


You're right, I'm so stupid, I apologise. Of course we should leave these sites running

If my site went down, because it was hosted on a server that the owners couldn't care what went on, I would take my business elsewhere. When something like this happens, they are forced to pay attention.

Phil

MilnerR

8,273 posts

287 months

Tuesday 12th July 2005
quotequote all
No offence taken

The majority of these scammers work out of internet cafes and set up fake websites to either actively phish for information to defraud or use them to back up their claims about being legit. They are not in the main sophisticated people and it is very very unlikely that they hijack webservers for these purposes. Instead, they open domains (with false details) and use them to steal from people. In the vast majority of cases the hosts are alerted to this and the offending domain is removed. That is the first course of action and usually works. However, scammers are finding that the only way to stop this happening is to use web servers further afield. Many of the domains are now hosted in china for example and the host doesn't seem too bothered as long as their bandwidth charges are paid every month. Hence sites like this were set up to cost the lads as much of their stolen money as possible and hopefully slow down their scams. As I say, these are not computer literate individuals e.g.

www.globaltrustsecurityfinance.com/

I doubt someone who produces such a ropey site has the nous to hijack many web servers

don't click on the link unless you wish to use the sites services, we wouldn't want to steal any more of his bandwidth

branflakes

2,039 posts

267 months

Tuesday 12th July 2005
quotequote all
philthy said:

You're right, I'm so stupid, I apologise. Of course we should leave these sites running


There are much better ways to deal with these things than joining in a potential DoS attack and bringing down innocent sites

philthy said:

If my site went down, because it was hosted on a server that the owners couldn't care what went on, I would take my business elsewhere.


Couldn't agree more - it's happened to me, and I changed hosts shortly afterwards.

But here's an alternative - contact the hosting company and the domain name registrar and tell them about the phishing site! It's very easy and far less likely to annoy innocent parties - just go to www.whois.sc/ and type in the domain name of the phishing site. It'll then tell you plenty of info about the person who registered the name (probably false), details about where the site is hosted (so you can contact their abuse department) and the registrar used to register the domain name (ditto). If the phishing email gives a numerical URL then you can still find out where the site is hosted, unless it's redirected somewhere else, in which case repeat the above procedure with the domain name you've been redirected to.


philthy

4,697 posts

269 months

Wednesday 13th July 2005
quotequote all
Oh, is that all there is to it?...........

Phil

cyberface

12,214 posts

286 months

Wednesday 13th July 2005
quotequote all
I get so many of these. It would be irritating, along with the sperm pills, 'local' bored housewives, pharmaceutical sales, hospital lists and remortgage offers, were it not for the fact that my Mac clears most of them out as junk mail.

Top tip for those not as internet-jaded as myself. Don't click on links in emails - simply copy them and paste them into a Text document (errr that'll be Notepad for Windows users, TextEdit for Mac OS X, and if you're using Linux and reading this then shame on you) and look at the URL before you use it in a browser.

If it's from your bank then you'd hope that the bank name is directly in front of the .com i.e. HSBC should end in hsbc.com - if you've got hsbc.hacker.com or anything else then you're looking at a phisher.

In general, you should never expect your bank to contact you via email, and never to expect you to pass over your details via an embedded link.

Remember that modern phishers are *very* good at formatting emails (including HTML) to make the mails look extremely authentic. The URL *ALWAYS* gives them away, cut and paste to expose the criminals.