PDA

View Full Version : Urgent Warning To Hsbc Customers


Hom3r
08-10-2005, 19:07
I Just got this emal from this address HSBC [security@online.hsbc.co.uk]

(phishing I Think)
http://asdasd1.coconia.net/image.jpg

Dear Customer,

Our Technical Service department has recently updated our online banking software, and due to this upgrade we kindly ask you to follow the reference given below to confirm your online account details. Failure to confirm the online banking details will suspend you from accessing your banking online.



http://hsbc.co.uk/1/2/personal/pib-home (phishing URL removed)



At HSBC, we use industry standard security technology and practices, focusing on three key areas – privacy, technology and identification to safeguard your account from any unauthorised access. The administration asks you to accept our apologies for the inconvience caused and expresses gratitude for cooperation. If you have any queries about this please call our Online Helpdesk on 0845 600 2290. Lines are open from 8am to 10pm every day.



Yours faithfully,



HSBC Internet Banking Technical Support

--

Please do not reply to this email address as it is not monitored and we will be unable to respond.
For assistance, log in to your HSBC Online Bank account and choose the "Help" link on any page.

© HSBC Bank plc 2005


I have firewalls and AV setup

Clicked the link ie went to this site

http://www.arlingtoon.com/www.hsbc.co.uk/1/2/personal/pib-home/

doesn't look good to me will print off and take to bank on monday









Admin edit (Stuart C): Disabled phishing link.

nffc
08-10-2005, 19:14
Yes it's a hoax. Spammed back :woot:

Florence
08-10-2005, 19:32
I have told HSBC that Iwill not respond to emails sent to me they use my mobile text message to send me offers or the online message that can only be read once you have logged in.

Martin
08-10-2005, 19:38
Yup very fishy!!!!

marky
08-10-2005, 19:39
Yup very fishy!!!! I agree its got to be a red herring.

kronas
08-10-2005, 19:41
its an obvious fake, if you hover over and click the link, it actually has a diffarent fake URL at the start.

Martin
08-10-2005, 19:44
its an obvious fake, if you hover over and click the link, it actually has a diffarent fake URL at the start.

Yeah they didn't go to a great deal of trouble to mask it's a fake!!

kronas
08-10-2005, 19:47
for those of you who want to be safe this toolbar will warn you of suspicious websites.

http://toolbar.netcraft.com/

Stuart
08-10-2005, 19:52
I have disabled the phishing link.


As a piece of advice to the members in general. In my experience, if banks need you to do anything to your account (for any reason), they will ask you to go to their main website (and you would be advised to TYPE this, not click on it), or go into your local branch.

ebay and paypal are the same, apart from the obvious fact they don't have any local branches to go to.

me283
08-10-2005, 20:10
ebay and paypal are the same, apart from the obvious fact they don't have any local branches to go to.

I can't tell you how many dodgy emails I've had from ebay or paypal asking for my login details. It gets really tiresome forwarding them on to the sites themselves. I wonder if they ever catch the spammers?

Roy MM
08-10-2005, 20:13
Yep had emails from every bank going, and i'm not even a customer. :shrug:

Chris W
08-10-2005, 20:30
I can't tell you how many dodgy emails I've had from ebay or paypal asking for my login details. It gets really tiresome forwarding them on to the sites themselves. I wonder if they ever catch the spammers?

Well the host being discussed in this thread has now had their hosting suspended... so i guess that's a start :)

Martin
08-10-2005, 20:48
Excellent!

Dave Stones
08-10-2005, 20:57
for all the paypal, ebay etc scams, fake banks etc there is always the lad-vampire and mugu-marauder if you don't mind wasting bandwidth... but that is mainly for 419 stuff ;)

makikomi
08-10-2005, 21:29
I have a surefire way of stopping these emails.

If you'd like to know, PM me your sort code, account number, PIN number and a scan of your signature.

:)

ScaredWebWarrior
08-10-2005, 22:07
I Just got this emal from this address HSBC [security@online.hsbc.co.uk]
Admin edit (Stuart C): Disabled phishing link.
Now that's where a good email client comes in VERY handy.

I use Eudora, and apart from the fact that it simply ignores the most basic attempts at attack simply because they're Outlook exploits, it also highlights any 'links' which differ in their destination from the displayed info.

So, despite the fact that the email may indeed appear to be 'from' your bank, it is quite easy then to see it's a phishing attack.

Another way to look at it is like this; no reputable financial institution would send an email like that - i.e. (to my knowledge, so far) no bank/CC company etc. has EVER sent emails to their customers suggesting they should follow a link to divulge sensitive account details.

So, when I get them, I simply laugh and delete!

nffc
08-10-2005, 22:13
You should have left the link in, so people can fill it with cr*p.

Stuart
08-10-2005, 22:16
You should have left the link in, so people can fill it with cr*p.


The link I deleted is actually furthur down the post (but is clearly marked as a phising link), but the account has been disabled now.

nffc
08-10-2005, 22:17
You should have left the link in, so people can fill it with cr*p.


The link I deleted is actually furthur down the post (but is clearly marked as a phising link), but the account has been disabled now.
furry muff. ;)

Pia
08-10-2005, 23:02
furry muff. ;)


:rofl::D LOL!

I say that ALL the time i love it.

Martin
08-10-2005, 23:04
furry muff. ;)

Hmmmm that means something completely different to me, given the thread is about HSBC!! Hmmmmm

clarie
08-10-2005, 23:12
Can I just ask a really stupid question...


I clicked on the second link in the email (the one saying arlington or something) to see what it leads to. Then I just had a thought, was that a stupid thing to do? Have I compromised security or anything?:erm:

Martin
08-10-2005, 23:14
No not stupid at all Claire! I think everyone would have clicked to have a look! The only time you would comprise is if you put all your passwords/user id into the site.

nffc
08-10-2005, 23:15
Can I just ask a really stupid question...


I clicked on the second link in the email (the one saying arlington or something) to see what it leads to. Then I just had a thought, was that a stupid thing to do? Have I compromised security or anything?:erm:
No, I click them all the time but I do use ff.
__________________

furry muff. ;)


:rofl::D LOL!

I say that ALL the time i love it.
thought that was just a midlands thing :dozey:

clarie
08-10-2005, 23:15
Ok thanks, phew! Didn't know if they got IP addresses or something...

nffc
08-10-2005, 23:16
No not stupid at all Claire! I think everyone would have clicked to have a look! The only time you would comprise is if you put all your passwords/user id into the site.
as if, i just put a load of rubbish in. fill their records up with nonsense and they have to sift all the carp out from the genuine stuff making it more workload and potentially putting them off phishing. Well idealistically.

Martin
08-10-2005, 23:19
Ok thanks, phew! Didn't know if they got IP addresses or something...

They're just after bank details. Your IP isn't of great value to them folks!!
__________________

as if, i just put a load of rubbish in. fill their records up with nonsense and they have to sift all the carp out from the genuine stuff making it more workload and potentially putting them off phishing. Well idealistically.

LOL I have never thought of doing that, sound's like fun!! LMAO:tu:

nffc
08-10-2005, 23:19
Ok thanks, phew! Didn't know if they got IP addresses or something...
Yeah but an IP is totally useless if you have a firewall or on a proxy. ;)