Sunday 30 March 2008

Halifax customer service: online banking notification!

First we had the NOF, now we've got the HOF. The HOF looks just like the NOF phishing email, just with the bank's name changed to 'Halifax'.

This time around the target URL is http://halifax.co.uk.sistemlog6.ms/_mem_bin/onlineform.asp?source=[removed] - sistemlog6.ms being a site that appears in a few Phishing results on Google.

The email is at least addresses on the to: section just to my email address and displayed the name part (before the URL) to try to make it more convincing. but 'Dear Halifax bank customer' is not how a bank would address a customer.

As always, no bank would send an email like this. It is purely an attempt to empty your account of funds and maybe even steal your identity. Don't click the link. If you are worried about accidentally clicking these links, use a phishing safe browser such as Firefox (free download from the button on the right).

Here's the content of the email.

Dear Halifax bank customer,

We have implemented security measures consistent with our internal information security practices to help us keep your information secure. These measures include technical and procedural steps to protect your data from misuse, access or disclosure, loss, alteration or destruction.

One of these security measures is HOF (Halifax Online Form) to help us to keep your personal and banking data up to date.

You should complete HOF on a regular basis.

Please complete HOF using the link below:

Halifax Online Form

Halifax Automated Mail Service. Please do not respond to this mail.


ref cmr

No comments: