Messaging Pipeline | News | Chinese Bank Hosts Phishing Site
Free Newsletter GlossaryContact UsAbout Us
One To One Collaboration Servers & Security Business

March 13, 2006

Chinese Bank Hosts Phishing Site



Courtesy of

A Chinese bank's is hosting spoofed sites that are using to dupe customers of American banks and e-tailers, a U.K.-based Internet monitoring company said Sunday.

According to Netcraft, this is the first time one bank's network has been used by criminals to steal information from another bank's customers.

The attack started Saturday when e-mails were sent to Chase Bank customers that directed them to a site hosted on addresses assigned to a Shanghai branch of the China Construction Bank Corp. (CCBC). The spoofed Chase and eBay sites were tucked away in hidden directories, and the CCBC's server's main page displayed a configuration error, said Netcraft.

The Chase attack takes a new tack: rather than directly con gullible users into giving up account passwords or PINs by pretending to be a message from customer support, the poses as a survey of Chase's online banking sites.

Anyone who fills out the survey will supposedly receive $20 for their trouble. Naturally, the survey is bogus. Among the fields to fill out are several demanding Chase card number, PIN, Social Security number, and other private information.

"Scammers are looking for new ways to fleece the unwary, and this time [they] have come up with a new twist: asking people to help in a survey for a cash reward," said Graham Cluley, senior technology consultant for Sophos, a British security company, in a statement.

Astute users will likely notice that the URL in the phished message is a raw IP address, not a domain. That, said Netcraft, is a strong sign of a phish.

The same CCBC Shanghai server was also used Saturday to host a page that spoofed the eBay log-in screen.

China Construction Bank Corp., one of the country's "Big Four" state-owned banks, has more than 14,200 branches across China.

E-mail This Story
Print This Story





Get the latest Messaging news, product info, and trends every week.


Related Content

  Right-click and choose Copy to extract RSS Feed URL  Messaging Pipeline's Main RSS Feed
  Right-click and choose Copy to extract RSS Feed URL  Messaging Pipeline's Blog RSS Feed




Editorial and vendor perspectives






Editor's Picks
The Six Flavors Of Windows Vista
Microsoft plans to release a full six-pack of Vista versions, one for every taste. Which Vista will be right for you?

Hope is Not Enough When It Comes To Compliance

Three Ways To Authenticate E-Mail And Stop Spam

Wikis In The Workplace

Review: Google Desktop 3

Vendors are now talking about how collaboration can be improved by integrating video with messaging applications. They're even talking about adding live TV to mobile phones. How far do you go before it becomes a bandwidth and business productivity drain?
Video is a great idea
    13%
Video is fine but there needs to be size limits
    25%
It's never used for anything really productive
    38%
I draw the line at live TV
    25%


In search of messaging products? Check out our brand new Product Finder for a directory of groupware and collaboration tools, security products, archiving solutions, and more.



MESSAGING PIPELINE MARKETPLACE (sponsored links)

With GTB Inspector Appliance. Free Trial (March 2006 only). GTB Inspector is a hardware appliance. It is installed easily and transparently on the network edge and prevents leaks of confidential information to the Internet.


Control unwanted software. Prevent spyware, malware, and viruses on corporate desktops and servers. Free White Paper and Live Demo.


Encrypting data in servers and databases can address security gaps and privacy legislation. Ingrian DataSecure Platforms offer granular encryption, seamless integration, and centralized security management. Combat data theft--with unprecedented ease and cost effectiveness. Download a white paper that outlines best practices for securing data.


Used by more than 30,000 businesses and 7.5 million users, Postini's enterprise-class managed service protects your messages without burdening your IT infrastructure.


Request white paper which outlines the case for an IT Portal architecture to meet the new requirements placed on IT management. These requirements include IT security; SOX, HIPAA, FISMA compliance; managing outsourcing contracts; and more.






Sponsored Links:      
 |   |   |   |   |   | 
 |   |   |   | 
 |   |   |   |   | 
Messaging Pipeline  |   |   |   | 
 |   |   |   |   | 
© 2006 | MESSAGING PIPELINE All rights reserved. | |