Monday 3 March 2008

NatWest | NatWest Bank: details confirmation

The NOF is back - it's been all of 4 days since we last saw this 'old friend'.

This time the target URL is http://online.natwest.co.uk.defelopour4.es/NOF/startupdate.aspx?refererident=[removed]&cookieid=[removed] - a simple attempt to convince the unweary that it's the real site by the use of subdomains under defelopour4.es. defelopour4.es appears in many phishing reports on Google, so it's not it's first time...

Here's the content of the email, it's been passed to the NatWest already.

Dear NatWest Bank customer,

We have implemented security measures consistent with our internal information security practices to help us keep your information secure. These measures include technical and procedural steps to protect your data from misuse, access or disclosure, loss, alteration or destruction.

One of these security measures is NOF (NatWest Online Form) to help us to keep your personal and banking data up to date.

You should complete NOF on a regular basis.

Please complete NOF using the link below:

NatWest Online Form

NatWest Automated Mail Service. Please do not respond to this mail.

No comments: