Feeds

E-mail fraudsters target Barclays

Gone 'phishing'

  • alert
  • submit to reddit

Beginner's guide to SSL certificates

Scam emails which attempts to fool Barclays Bank customers into handing over sensitive account information has been sent to thousands of Web users this week.

The fake emails, which appear to have been spammed at users at random, purport to be part of a security check. Barclays customers receiving the emails are been encouraged to enter their details to fraudulent sites. As is common with such scams, the URL used in the emails is cleverly encoded to disguise the true location of the sites. The destination pages are designed to look like the genuine Barclays site. Only tell-tale signs, easily overlooked, like the title of the destination page "Barclays IBank" and the URLs of the fake sites give the game away.

Alex Shipp, of managed security services firm MessageLabs, told The Register that his firm alone has blocked the scam email hundreds of times.

"We are currently stopping hundreds of spams an hour directing Barclays Bank customers to fake login sites where you are invited to enter your username and password. The bad guys then log these, and clean out your account," Shipp said.

"The URL looks like it points to www.barclays.co.uk. However, it points to one of at least eight fake sites."

Checks suggest the fake sites are hosted by hosting firms Alabanza of Baltimore, Maryland and Affinity Internet, of El Segundo, California. We've notified both companies about the issue.

A Barclays spokeswoman confirmed it was aware of the scam. It advises users to avoid divulging account information in response to these emails. Users are advised to contact the bank directly if they have any questions or concerns.

The bank has informed the police and is looking to have the offending Web sites taken off the Net, she added.

The Barclays scam is similar to a scheme targeting Citibank customers that did the rounds last month (prompting a warning from Citibank), which is itself similar to numerous frauds targeting users of eBay, PayPal and other large ecommerce firms in the past. However, the prevalence of the Barclays scam emails is something slightly out of the ordinary. Its worth remembering that the scam doesn't rely on compromising a targeted organisation's systems.

We can expect similar scams in the future. Users should routinely ignore such emails or risk becoming the victim of identity theft, one of the fastest growing Net crimes. ®

The scam email:

Dear Valued Customer,

- Our new security system will help you to avoid
frequently fraud transactions and to keep your
investments in safety.

- Due to technical update we recommend you to
reactivate your account.

Click on the link below to login and begin using
your updated Barclays account.

To log into your account, please visit the NetBank
website at http://www.barclays.co.uk

If you have questions about your online statement,
please send us a Bank Mail or call us at
0846 600 2323 (outside the UK dial +44 247 686 2063).

We appreciate your business. It's truly our
pleasure to serve you.

Barclays Customer Care

This email is for notification only. To contact us,
please log into your account and send a Bank Mail.

Related Stories

Two-in-one ID theft, fee fraud scam debuts
You've got Scam! ID harvest scam targets AOL users
Email scammers target Nochex users
Email scam aims to swipe PayPal users' credit card details
ID theft hits 10m Americans a year
MS, eBay, Amazon et al join ID theft busters

Protecting users from Firesheep and other Sidejacking attacks with SSL

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Jihadi terrorists DIDN'T encrypt their comms 'cos of Snowden leaks
Intel bods' analysis concludes 'no significant change' after whistle was blown
Home Depot: 56 million bank cards pwned by malware in our tills
That's about 50 per cent bigger than the Target tills mega-hack
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
China hacked US Army transport orgs TWENTY TIMES in ONE YEAR
FBI et al knew of nine hacks - but didn't tell TRANSCOM
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.