Investors Hangout Stock Message Boards Logo
  • Mailbox
  • Favorites
  • Boards
    • The Hangout
    • NASDAQ
    • NYSE
    • OTC Markets
    • All Boards
  • Whats Hot!
    • Recent Activity
    • Most Viewed Boards
    • Most Viewed Posts
    • Most Posted
    • Most Followed
    • Top Boards
    • Newest Boards
    • Newest Members
  • Blog
    • Recent Blog Posts
    • Recently Updated
    • News
    • Stocks
    • Crypto
    • Investing
    • Business
    • Markets
    • Economy
    • Real Estate
    • Personal Finance
  • Market Movers
  • Interactive Charts
  • Login - Join Now FREE!
  1. Home ›
  2. Stock Message Boards ›
  3. Stock Boards ›
  4. Zerify Inc (ZRFY) Message Board

Mobile Banking Users Targeted in SMS Phishing Camp

Message Board Public Reply | Private Reply | Keep | Replies (0)                   Post New Msg
Edit Msg () | Previous | Next


Post# of 82686
(Total Views: 491)
Posted On: 02/19/2020 11:34:14 AM
Avatar
Posted By: CyberC
Mobile Banking Users Targeted in SMS Phishing Campaign
Researchers Say Attackers Targeted American and Canadian Banking Customers


Ishita Chigilli Palli (Ishita_CP) • February 18, 2020

mobile-banking-users-targeted-in-sms-phishing-campaign-showcase_image-9-a-13735.jpg

Mobile Banking Users Targeted in SMS Phishing Campaign
Cybercriminals targeted mobile banking users by sending malicious SMS messages to their smartphones as part of a phishing campaign to steal account holders' information, including usernames and passwords, according to the cybersecurity firm Lookout.

See Also: The Changing Face of Online Banking and Financial Fraud

More than 3,900 mobile banking app users of several Canadian and American banks fell victim to the SMS phishing attacks, which started in June 2019 and apparently recently ended, researchers at Lookout say in their new report.

Those affected included customers of Scotiabank, CIBC Bank, RBC Royal Bank, UniBank, HSBC, Tangerine Bank, TD Bank, Meridian, Laurentian, Manulife, BNC National Bank and Chase, according to the report. The researchers notified the banks involved before publishing their report on Friday.

The attackers attempted to gain access to users' banking credentials, such as payment card numbers, usernames and passwords, as well as personal details, including dates of birth, according to Lookout.

Apurva Kumar, a staff security intelligence engineer at Lookout, tells Information Security Media Group that his firm does not have information on the specific accounts that were compromised or how the attackers may have tried to monetize the data that they collected.

But in other cases, hackers have attempted to sell stolen information on darknet marketplaces, such as Joker's Stash (see: Wawa's Stolen Payment Cards Are Now for Sale).

The Lookout researchers note in their report that smartphone users are more susceptible to phishing attacks because the features, functionality and screen size of these devices make it more difficult to discern if the message is fraudulent or a website link is fake, according to the report.

SMS as Malicious Tool
The phishing campaign that the Lookout researchers describe in their report used malicious SMS messages to lure victims into clicking on links that would take them to fake login pages of banks. These fake sites mirrored the real mobile banking sites of these firms, including using the same layout and sizing, according to the report.

Once a targeted victim reached the fake site, they were asked to input their username, password and other details, which were then collected by the attackers, the researchers say.

lookoutphishingbanks.jpg

Examples of fake mobile banks sites used in phishing campaign (Source: Lookout)
The attackers only targeted mobile users and spoofed the websites that were built specifically for smartphones, according to the report. With the increasing use of multifactor authentication, banks often send passwords to customers via SMS, which means customers are accustomed to receiving text messages from their banks, the report adds.

"Since mobile users are typically on the move and less likely to scrutinize the authenticity of an SMS message, text messages have become an attractive new attack vector," the researchers say.

The fake websites feigned legitimacy by taking the victims through a series of security questions, asking them to confirm their identity with the card's expiration date or double-checking the account number, according to the report. The pages also had links such as "Mobile Banking Security and Privacy" or "Activate Mobile Banking."

Campaign's Scope
Lookout said it identified over 3,900 unique IP addresses of victims who clicked on a malicious link over a seven-month period.

Some victims clicked on the link but did not provide any information; some provided only a few details; while others entered all the details requested by the cybercriminals, according to the report.

The researchers found more than 200 phishing pages that were part of the campaign. One of the phishing links that the researchers studied had over 800 unique clicks, according to the report.

The researchers also discovered an "automated SMS tool" linked to the campaign that the attackers may have used to create unique messages to victims victims.

About the Author

ishita-palli-largeImage-10-a-3127.jpg

Ishita Chigilli Palli
Senior Correspondent, Global News Desk
As senior correspondent for Information Security Media Group's global news desk, Ishita covers news worldwide. She previously worked at Thomson Reuters, where she specialized in reporting breaking news stories on a variety of topics.


(1)
(0)




Zerify Inc (ZRFY) Stock Research Links


  1.  
  2.  


  3.  
  4.  
  5.  


WORDS TO LIVE BY:

Never argue with stupid people, they will drag you down to their level and then beat you with experience.


Get .... PrivacyLok https://cyberidguard.com/

Try SafeVchat: https://cyberidguard.com/

My comments are only my opinion and are not to be used for investment advice.

Please conduct your own due diligence before choosing to buy or sell any stock.

xgqbj600g2g.jpg




Investors Hangout

Home

Mailbox

Message Boards

Favorites

Whats Hot

Blog

Settings

Privacy Policy

Terms and Conditions

Disclaimer

Contact Us

Whats Hot

Recent Activity

Most Viewed Boards

Most Viewed Posts

Most Posted Boards

Most Followed

Top Boards

Newest Boards

Newest Members

Investors Hangout Message Boards

Welcome To Investors Hangout

Stock Message Boards

American Stock Exchange (AMEX)

NASDAQ Stock Exchange (NASDAQ)

New York Stock Exchange (NYSE)

Penny Stocks - (OTC)

User Boards

The Hangout

Private

Global Markets

Australian Securities Exchange (ASX)

Euronext Amsterdam (AMS)

Euronext Brussels (BRU)

Euronext Lisbon (LIS)

Euronext Paris (PAR)

Foreign Exchange (FOREX)

Hong Kong Stock Exchange (HKEX)

London Stock Exchange (LSE)

Milan Stock Exchange (MLSE)

New Zealand Exchange (NZX)

Singapore Stock Exchange (SGX)

Toronto Stock Exchange (TSX)

Contact Investors Hangout

Email Us

Follow Investors Hangout

Twitter

YouTube

Facebook

Market Data powered by QuoteMedia. Copyright © 2025. Data delayed 15 minutes unless otherwise indicated (view delay times for all exchanges).
Analyst Ratings & Earnings by Zacks. RT=Real-Time, EOD=End of Day, PD=Previous Day. Terms of Use.

© 2025 Copyright Investors Hangout, LLC All Rights Reserved.

Privacy Policy |Do Not Sell My Information | Terms & Conditions | Disclaimer | Help | Contact Us