<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-5457092559363087572</id><updated>2012-02-17T04:14:21.287Z</updated><category term='Citizens Bank'/><category term='emails'/><category term='HSBC'/><category term='Intelligent Finance'/><category term='comment'/><category term='Faith Burks'/><category term='Royal Bank Of Scotland'/><category term='LloydsTSB'/><category term='trevor varner'/><category term='Abbey National'/><category term='ITV Solutions'/><category term='world pay'/><category term='work scam'/><category term='e-gold'/><category term='lottery'/><category term='DESMOND ALI'/><category term='Alliance And Leicester'/><category term='Egg'/><category term='Sandra Wilson'/><category term='PayPal'/><category term='FEDERALHi COURT'/><category term='Nationwide'/><category term='Ebay'/><category term='NatWest'/><category term='Anglo Irish Bank'/><category term='Skype'/><category term='Abbey'/><category term='Halifax'/><category term='Business'/><category term='Jennifer Wilson'/><category term='Cornelius Butler'/><category term='Japan Arts Gallery'/><category term='Monster'/><category term='Islamic Bank of Britain'/><category term='Naoki Takahashi'/><category term='first bank'/><category term='Google Adwords'/><category term='CitiBank'/><category term='David Timms'/><category term='emma stokes'/><category term='First National Bank'/><category term='Business Banking'/><category term='Yorkshire Bank'/><category term='Lloyds TSB'/><category term='Butler New Media'/><category term='mr owusu'/><category term='Barclays'/><category term='DONALD MUKHENZE'/><title type='text'>Phish Alert</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default?start-index=101&amp;max-results=100'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>257</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-8923616055458034751</id><published>2008-11-14T09:37:00.003Z</published><updated>2008-11-14T09:42:39.338Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Business'/><category scheme='http://www.blogger.com/atom/ns#' term='Abbey'/><title type='text'>Abbey Business Accounts ARE Being Updated</title><content type='html'>I feel that it's worth mentioning the fact that Abbey &lt;u&gt;IS&lt;/u&gt; updating it's business security system and that users will be asked to revalidate their logins and provide new security details. &lt;u&gt;BUT&lt;/u&gt;, what is important to know is:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;This update will &lt;u&gt;not&lt;/u&gt; be requested through any emails and will &lt;u&gt;only&lt;/u&gt; be requested after users have naturally visited and logged onto their normal services.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;This is very important. If you receive an email asking you to update your details, it is almost certainly a fake. These details are being provided to users after they log on, of their own accord. Likewise, it will be up to users to decide when to log on to their internet banking accounts and do this through their normal links.&lt;br /&gt;&lt;br /&gt;Here's a couple of Q&amp;amp;As from the bank:&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Q. How will I know what to do?&lt;br /&gt;&lt;/em&gt;&lt;br /&gt;A. The upgrade is planned to take place over the next few weeks. Until then you can continue to log on as normal. When the upgrade is complete we will take you through the process step by step. It will take no longer than ten minutes and you will only need to complete the process the first time you log on after the upgrade has taken place.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Q. How will I access my account?&lt;br /&gt;&lt;/em&gt;&lt;br /&gt;A. AFTER you have successfully logged on using your existing security details, you will be asked to select new security information online via our e-bank. We will ask you to do this when the upgrade has been completed. Please be aware we will NEVER ask you to provide any security details by responding to an email.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-8923616055458034751?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/8923616055458034751/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=8923616055458034751' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8923616055458034751'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8923616055458034751'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/11/abbey-business-accounts-are-being.html' title='Abbey Business Accounts ARE Being Updated'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-1792385605754677628</id><published>2008-11-10T10:10:00.002Z</published><updated>2008-11-10T10:13:01.295Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Abbey'/><title type='text'>Abbey Bank Cards-NEW DAILY LIMITS</title><content type='html'>Here's a new one on me. Instead of threats, just an email saying that the daily limits on the debit card are being changed. Why this leads to a security process is not explained! But I suspect that a few unwary people will click the link and before they know it have given away their security details.&lt;br /&gt;&lt;br /&gt;Take care, don't click that link!&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Customer,&lt;br /&gt;&lt;br /&gt;Latest News:Terms &amp; Conditions:&lt;br /&gt;&lt;br /&gt;We inform you that for security reasons from 10/11/2008 the Withdrawal/Purchase Daily Limits of Abbey Bank VISA debit card will be changed.&lt;br /&gt;&lt;br /&gt;Click here to Start the Security Process. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;When you log onto the service we will ask you to accept the updated Terms and Conditions.&lt;br /&gt;&lt;br /&gt;Once you have accepted these, you will be able to access your accounts in the usual way.&lt;/b&gt;&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-1792385605754677628?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/1792385605754677628/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=1792385605754677628' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1792385605754677628'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1792385605754677628'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/11/abbey-bank-cards-new-daily-limits.html' title='Abbey Bank Cards-NEW DAILY LIMITS'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-2911614292773680868</id><published>2008-11-04T13:00:00.002Z</published><updated>2008-11-04T13:02:45.891Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Abbey'/><title type='text'>Abbey National eBanking: Please Confirm Your Data</title><content type='html'>It's the reappearance of one of my old favourites - the one that actually apologises for being sent to none customers. The thing is, if it is still doing the rounds, then I expect that the format is working. Rather worrying that some people believe a major bank would just randomly email the entire country, asking them to partake in a software upgrade. Although, with the customer I've been with this morning, maybe it's not that hard to believe!&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Abbey National Bank e-Banking client!&lt;br /&gt;&lt;br /&gt;Our Support Department is running a scheduled Internet Banking software upgrade&lt;br /&gt;&lt;br /&gt;By following the link below you will open the form of the member login update:&lt;br /&gt;&lt;br /&gt;http://ww7.abbey.com/CentralLogonWeb/Confirm?comm=31zrohDkhbjcsdbhsnacadscndeOkhOvp&lt;br /&gt;&lt;br /&gt;These directions are to be e-mailed and followed by all users of the Abbey National Internet Banking&lt;br /&gt;&lt;br /&gt;Abbey National Bank does apologize for the problems caused, and is very grateful for your collaboration.&lt;br /&gt;&lt;br /&gt;If you are not client of Abbey National Bank please delete this email!&lt;br /&gt;&lt;br /&gt;*** This is an automated e-mail please do not respond ***&lt;br /&gt;&lt;br /&gt;(c) '08 Abbey National Bank OnLine Banking. All Rights Reserved.&lt;br /&gt;&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-2911614292773680868?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/2911614292773680868/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=2911614292773680868' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2911614292773680868'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2911614292773680868'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/11/abbey-national-ebanking-please-confirm.html' title='Abbey National eBanking: Please Confirm Your Data'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-7187755000874240032</id><published>2008-11-03T21:57:00.000Z</published><updated>2008-11-03T21:59:52.127Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='LloydsTSB'/><title type='text'>LloydsTSB Electronic Banking: Please Submit Your Password</title><content type='html'>Not a very imaginitive one, this one. Techno speak to bore the reader and then the statement that it is compulsory to review your security details, because of a routine update. Not very good, convincing English.&lt;br /&gt;&lt;br /&gt;Don't touch the link, here's the content.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear LloydsTSB Bank client, &lt;br /&gt;&lt;br /&gt;Security and confidentiality are at the heart of the LloydsTSB Group. Your details (and your money) is protected by a number of technologies, including Secure Sockets Layer (SSL) encryption. &lt;br /&gt;We would like to notify you that LloydsTSB Bank carries out client details confirmation procedure that is compulsory for all our clients. This procedure is attributed to a routine banking software update. &lt;br /&gt;&lt;br /&gt;Please visit our Client Confirmation Form using the link below and follow the instructions on the screen. &lt;br /&gt;&lt;br /&gt;http://online5.lloydstsb.com/confirmation/customer.ibc?set=18pdznwDxcrszkOkhOvp &lt;br /&gt;&lt;br /&gt;Lloyds TSB Bank Customer Service &lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-7187755000874240032?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/7187755000874240032/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=7187755000874240032' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7187755000874240032'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7187755000874240032'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/11/lloydstsb-electronic-banking-please.html' title='LloydsTSB Electronic Banking: Please Submit Your Password'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-7380984309535570327</id><published>2008-10-22T15:37:00.002+01:00</published><updated>2008-10-22T15:41:56.554+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='world pay'/><title type='text'>Duncan Mcleod | WorldPay CARD transaction Confirmation</title><content type='html'>This one is not essentially phishing, but is likely to end up along those lines. It has a supposed order confirmation as an attachment, within a zip folder. You can bet that the moment you double click the zip and extract the contents, some nasty piece of software is installed onto your machine. This might allow the senders to watch the keystrokes used as you visit online banking or other similar websites.&lt;br /&gt;&lt;br /&gt;If you are worried you might have opened such an attachment, check that your virus and spyware programs are updated and run a full system scan.&lt;br /&gt;&lt;br /&gt;If anyone ever sends you unexpected bills, payment confirmations etc, check your credit card or bank statement rather than opening the attachments. Chances are that the attachment is some form of keylogger or other spyware.&lt;br /&gt;&lt;br /&gt;Here's the content.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Thank you!&lt;br /&gt;Your transaction has been processed by WorldPay, on behalf of Academic Resources Center Inc. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The invoice file is attached to this message.&lt;br /&gt;This is not a tax receipt.&lt;br /&gt;We processed your payment. &lt;br /&gt;Academic Resources Center Inc has received your order, &lt;br /&gt;and will inform you about delivery. &lt;br /&gt;Sincerely,&lt;br /&gt;The AcaDemon Team&lt;br /&gt;Enquiries &lt;br /&gt;This confirmation only indicates that your transaction has been processed successfully. It does not indicate that your order has been accepted. It is the responsibility of Academic Resources Center Inc to confirm that your order has been accepted, and to deliver any goods or services you have ordered.&lt;br /&gt;&lt;br /&gt;If you have any questions about your order, please email Academic Resources Center Inc at: followup@acadeXM3micresourcescenter.com, with the transaction details listed above.&lt;br /&gt;&lt;br /&gt;Thank you for shopping with Academic Resources Center Inc.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-7380984309535570327?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/7380984309535570327/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=7380984309535570327' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7380984309535570327'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7380984309535570327'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/10/duncan-mcleod-worldpay-card-transaction.html' title='Duncan Mcleod | WorldPay CARD transaction Confirmation'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-764767245413996669</id><published>2008-10-22T09:19:00.002+01:00</published><updated>2008-10-22T09:24:56.382+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Halifax'/><title type='text'>Halifax PLC | **VERY IMPORTANT SECURITY NOTICE**</title><content type='html'>This one is a different idea for a scam. It first warns the read about phishing emails before providing the phishing link part way down. No threats of violence or account cut off if you don't answer security questions, just a 'please help us' part way down the email.&lt;br /&gt;&lt;br /&gt;Here's the cheeky email content!&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Be on your guard - beware of fraudsters!&lt;br /&gt;&lt;br /&gt;Dear Halifax customer,&lt;br /&gt;&lt;br /&gt;Like other UK banks, we are currently seeing very large numbers of "phishing emails" in circulation. Many of these look as if they are from Halifax, typically encouraging you to click a link and type in your logon details. Such attempted frauds only work if you click that link, and you then type in your full security details &amp; contact information. &lt;br /&gt;&lt;br /&gt;Please remember: We never ask you to enter your Credit Card information &amp; contact information on the Internet or over the phone. To learn how to protect yourself against "phishing" and other "identity theft" please spend a few minutes to upgrade to our latest security.&lt;br /&gt;&lt;br /&gt;Click here to help us fight fraud!&lt;br /&gt;&lt;br /&gt;Best regards. &lt;br /&gt;&lt;br /&gt;Halifax Bank Security Department Team.&lt;br /&gt;&lt;br /&gt;* Please do not reply to this e-mail * &lt;br /&gt;&lt;br /&gt;------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Halifax Bank or Halifax Bank plc is authorised and regulated by the Financial Services Authority and signatories to the Banking Codes. FSA authorisation can be checked on the FSA’s Register at: www.fsa.gov.uk/register. Halifax Bank or Halifax Bank plc is member of the Financial Services Compensation Scheme and the Financial Ombudsman Service. Halifax Bank plc&lt;br /&gt;&lt;br /&gt;| Halifax Bank© 2008 |&lt;br /&gt;&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-764767245413996669?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/764767245413996669/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=764767245413996669' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/764767245413996669'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/764767245413996669'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/10/halifax-plc-very-important-security.html' title='Halifax PLC | **VERY IMPORTANT SECURITY NOTICE**'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-5683419741374808143</id><published>2008-07-17T16:40:00.002+01:00</published><updated>2008-07-17T16:46:41.616+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Yorkshire Bank'/><title type='text'>Account Notification:Unauthorized Transactions On Your Internet Banking</title><content type='html'>Another phishing email with the pretence that an account has been subject to unathorised attempts to gain access. There's a discrepancy between the title, suggesting that there have been transactions and the content, saying that there have been logon attempts. I suppose the idea being the title gets the reader's attention in the hope that they just quickly click the link to continue.&lt;br /&gt;&lt;br /&gt;That link would actually take you not to the Yorkshire Bank's own system, but to http://www.&lt;u&gt;hunterxhunter.cl&lt;/u&gt;/verify/login.html instead. hunterxhunter.cl have already appeared on these pages, on &lt;a href="http://phishalert.blogspot.com/2008/07/important-notice-lloyds-tsb-securityre.html"&gt;1st July&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Here's the content of the email...&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Unauthorized Transactions on your Internet Banking&lt;br /&gt;&lt;br /&gt;Dear Valued Customer,&lt;br /&gt;&lt;br /&gt;Our utmost concern is the security of our online banking users. In this effect,&lt;br /&gt;we do proper verification on all transactions done on our secured online banking servers.&lt;br /&gt;&lt;br /&gt;Several attempts to log on to your account were detected on our secured servers and as a matter of our improved online banking security measures, We have decided to temporarily suspend your online banking access.&lt;br /&gt;&lt;br /&gt;You will not be able to access your online account unless you re-activate your online access but in order to do so, you will have to confirm your details by Logging on to your account to complete the verification process set out for you before we can retrieve your online access.&lt;br /&gt;&lt;br /&gt;Please, Log on through our secure reference: Click Here&lt;br /&gt;&lt;br /&gt;We are indeed sorry for the inconveniencies we have caused you, but also remember that as a Ybonline Bank customer, your security remains our greatest priority.&lt;br /&gt;&lt;br /&gt;Sincerely,&lt;br /&gt;&lt;br /&gt;David Thorburn&lt;br /&gt;Security Department&lt;br /&gt;Ybonline Internet Banking&lt;br /&gt;&lt;br /&gt;© Copyright 2008, Yorkshire Bank. All rights reserved.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Please do not reply to this e-mail. Mail sent to this address cannot be answered.&lt;br /&gt;Ybobline Email ID # 1009&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-5683419741374808143?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/5683419741374808143/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=5683419741374808143' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5683419741374808143'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5683419741374808143'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/07/account-notificationunauthorized.html' title='Account Notification:Unauthorized Transactions On Your Internet Banking'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-5876244265834927962</id><published>2008-07-13T20:00:00.002+01:00</published><updated>2008-07-13T20:03:23.029+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Royal Bank Of Scotland'/><title type='text'>The Royal Bank of Scotland | Digital Banking Service Notice</title><content type='html'>Quite a prolific phishing email - I have received this through a few email accounts. It's one of those that lists a dozen or so very similar email addresses in the 'to:' field - as though anyone needs a warning that it's spam!&lt;br /&gt;&lt;br /&gt;The target for this one is http://www1.rbsdigitalsecure.com.&lt;u&gt;looifur94.com&lt;/u&gt;/default.aspxrefererident=[removed]&amp;cookieid==[removed].&amp;noscr=false&amp;CookieCheck/ looifur94.com appears in a couple of phishing results. Here's the content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Customer,&lt;br /&gt;&lt;br /&gt;The Royal Bank of Scotland  has been receiving complaints from our customers for unauthorised use of the Royal Bank of Scotland Online accounts. As a result we are making an extra security check on all of our Customers account in order to protect their information from theft and fraud.&lt;br /&gt;&lt;br /&gt;Due to this, you are requested to follow the provided steps and confirm your Online Banking details for the safety of your Accounts. Please Click Here To Start . &lt;br /&gt;&lt;br /&gt;However, Failure to do so may result in temporary account suspension. Please understand that this is a security measure intended to help protect you and your account. We apologize for any inconvenience.&lt;br /&gt;&lt;br /&gt;Thanks for your co-operation.&lt;br /&gt;&lt;br /&gt;Fraud Prevention Unit &lt;br /&gt;Legal Advisor&lt;br /&gt;The Royal Bank of Scotland. &lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-5876244265834927962?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/5876244265834927962/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=5876244265834927962' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5876244265834927962'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5876244265834927962'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/07/royal-bank-of-scotland-digital-banking.html' title='The Royal Bank of Scotland | Digital Banking Service Notice'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-4976187597691751503</id><published>2008-07-08T18:50:00.002+01:00</published><updated>2008-07-08T18:54:28.548+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Monster'/><title type='text'>Monster Career Network | customer notice: data confirmation</title><content type='html'>Here's a new slight twist on the Natwest Online Form /Banking Online Form etc - the Online Employer Form. A different target for a change - Monster.com. It uses the twin tracking references that we've seen before and is sent to a named email address, so it's going to confuse some people. Although, not having looked at the destination page and not having a Monster logon, I don't know just how much detail they can get. I suppose name, address, date of birth and other details, ready to clone your identity...&lt;br /&gt;&lt;br /&gt;The actual destination address of the link is really pointing to http://hiring.monster.com.&lt;u&gt;pierssite.org.es&lt;/u&gt;/serverdll/onlineemployerform.aspx?redirect==[removed]&amp;employer=[removed]. pierssite.org.es already has 2 English phishing results and 2 other results on Google.&lt;br /&gt;&lt;br /&gt;Here's the content.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Monster (Jobs &amp; Careers) customer,&lt;br /&gt;&lt;br /&gt;The added security measures require all Monster customers to complete Online Employer Form.&lt;br /&gt;Please use the hyperlink below to access Online Employer Form:&lt;br /&gt;&lt;br /&gt;http://hiring.monster.com/serverdll/onlineemployerform.aspx?redirect=[removed]&amp;employer=[removed]&lt;br /&gt;&lt;br /&gt;We appreciate your business and thank you for being a valued customer.&lt;br /&gt;&lt;br /&gt;©2008 Monster - All Rights Reserved&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-4976187597691751503?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/4976187597691751503/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=4976187597691751503' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/4976187597691751503'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/4976187597691751503'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/07/monster-career-network-customer-notice.html' title='Monster Career Network | customer notice: data confirmation'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-7154173772108875262</id><published>2008-07-08T14:03:00.002+01:00</published><updated>2008-07-08T14:13:50.598+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Halifax'/><title type='text'>Halifax Fraud Prevention Unit</title><content type='html'>Time for the Halifax to make another rare appearance on these pages. The English grammar is a bit ropey in this email - maybe it's not sent from an English speaker. For example, &lt;i&gt;apologize for any inconvenience&lt;u&gt;s&lt;/u&gt; caused&lt;/i&gt; and &lt;i&gt;our Customers account&lt;/i&gt; instead of &lt;i&gt;our Customers' accounts&lt;/i&gt;, to name but two. But then I am picky about such things!&lt;br /&gt;&lt;br /&gt;Remember, no bank would send you an email asking for further security information - any such email should always be treated as an attempt to rob you. If such measures were needed, they would contact you via the post.&lt;br /&gt;&lt;br /&gt;The actual destination of the link is http://static-68-179-55-204.ptr.&lt;u&gt;terago.net&lt;/u&gt;/halifax-online.co.uk/_mem_bin/halifax_LogIn/formslogin.aspsource=halifaxcouk/ so I think someone might be using an ISP's free hosting space to host the landing page. Here's the email content.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Customer&lt;br /&gt;&lt;br /&gt;Halifax PLC. has been receiving complaints from our customers for unauthorised use of the Halifax Online accounts. As a result we are making an extra security check on all of our Customers account. In order to protect your information please click on the link below:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://halifax-online.co.uk/_mem_bin/halifax_LogIn/formslogin &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thank you for your understanding and correspondence, we also apologize for any inconveniences caused.&lt;br /&gt;&lt;br /&gt;Thanks for your co-operation.&lt;br /&gt;&lt;br /&gt;Fraud Prevention Unit&lt;br /&gt;Legal Advisor&lt;br /&gt;Halifax PLC. &lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-7154173772108875262?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/7154173772108875262/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=7154173772108875262' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7154173772108875262'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7154173772108875262'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/07/halifax-fraud-prevention-unit.html' title='Halifax Fraud Prevention Unit'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-4090796514007987038</id><published>2008-07-08T10:39:00.002+01:00</published><updated>2008-07-08T10:43:34.074+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Abbey'/><title type='text'>Important banking mail from Abbey</title><content type='html'>It's been quiet for a few days on the phishing front, but here's one aimed at the Abbey with a target URL of http://myonlineaccounts2.abbeynational.co.uk.&lt;u&gt;servtts.net&lt;/u&gt;/CentralFormWeb/Form?action=[removed]&amp;step=[removed]. servtts.net does appear in a couple of other Abbey phishing results on Google. Interesting that they are using the old 'online banking form' and the double tracking id link in the URL - probably connected to a few similar phishing emails.&lt;br /&gt;&lt;br /&gt;Here's the content.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Abbey bank customer,&lt;br /&gt;&lt;br /&gt;Abbey Customer Serice would like to inform you that we are currently carrying out a scheduled upgrade of Abbey Security software.&lt;br /&gt;In order to guarantee high level of security to our customers, we require you to complete “Online Banking Form”.&lt;br /&gt;Please complete Online Banking Form using the link below:&lt;br /&gt;&lt;br /&gt;Online Banking Form&lt;br /&gt;&lt;br /&gt;Thank you for being a valued customer.&lt;br /&gt;&lt;br /&gt;Sincerely,&lt;br /&gt;Abbey Customer Serice &lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-4090796514007987038?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/4090796514007987038/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=4090796514007987038' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/4090796514007987038'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/4090796514007987038'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/07/important-banking-mail-from-abbey.html' title='Important banking mail from Abbey'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-864225870994827623</id><published>2008-07-03T22:33:00.002+01:00</published><updated>2008-07-03T22:36:27.377+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>NatWest Bank: You Have 1 New Security Message Alert.</title><content type='html'>The Natwest Customer Form makes a return! The target this time around is http://www.natwest.com.&lt;u&gt;gosdsoon.co.uk&lt;/u&gt;/serverstack/usersdirectory/ncf.aspx?pc=[removed]&amp;id=[removed] - note the signature pc id / id. gosdsoon.co.uk does appear in a few phishing results.&lt;br /&gt;&lt;br /&gt;Here's the email content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear customer of NatWest bank,&lt;br /&gt;&lt;br /&gt;We are running a scheduled maintenance on our servers. We want to make sure your money and your personal details are safe and secure.&lt;br /&gt;Due to new security policies all NatWest bank customers must complete the Natwest Customer Form.&lt;br /&gt;&lt;br /&gt;To complete the form, please use the link below:&lt;br /&gt;&lt;br /&gt;Natwest Customer Form&lt;br /&gt;&lt;br /&gt;This should take you directly to the Natwest Customer Form.&lt;br /&gt;&lt;br /&gt;Sincerely,&lt;br /&gt;Natwest Customer Service&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-864225870994827623?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/864225870994827623/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=864225870994827623' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/864225870994827623'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/864225870994827623'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/07/natwest-bank-you-have-1-new-security.html' title='NatWest Bank: You Have 1 New Security Message Alert.'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-5952252171455682365</id><published>2008-07-01T17:21:00.002+01:00</published><updated>2008-07-01T17:27:30.041+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Barclays'/><title type='text'>Security alert!</title><content type='html'>I don't often get phishing emails targetted at Barclays Bank, but here's one. It deserves a mention just for it's uniqueness... In fact, looking back, I've only posted 2 reports on this blog, both in September last year. Maybe their security is pretty hot and not worth attempted hacking.&lt;br /&gt;&lt;br /&gt;Having said that, it takes the format of the NOF - this one is the Barclays Bank Form instead. So maybe someone is switching their target. It is, of course, rubbish. The actual link points to http://ibank.barclays.co.uk.&lt;u&gt;anygonti.co.uk&lt;/u&gt;/olb/MemberForm.do?memberid=[removed]&amp;session=[removed]. anygonti.co.uk was only registered a few days ago (27/6/2008). I won't give the contact details - it's likely that someone has had their account broken into and the domain registered in their name.&lt;br /&gt;&lt;br /&gt;Here's the content...&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Barclays Bank customer,&lt;br /&gt;&lt;br /&gt;Barclays Bank would like to inform you that we are currently carrying out a scheduled upgrade of Barclays Security software.&lt;br /&gt;In order to guarantee high level of security to our customers, we require you to complete “Barclays Banking Form”. Please notice, that we ask you to complete the Form regularly, until Barclays bank IT department finishes the upgrading process successfully.&lt;br /&gt;Please complete the form using the link below:&lt;br /&gt;&lt;br /&gt;Barclays Banking Form&lt;br /&gt;&lt;br /&gt;Thank you for being a valued customer.&lt;br /&gt;&lt;br /&gt;Sincerely,&lt;br /&gt;Barclays Customer Service&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-5952252171455682365?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/5952252171455682365/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=5952252171455682365' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5952252171455682365'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5952252171455682365'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/07/security-alert.html' title='Security alert!'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-8221010503796640938</id><published>2008-07-01T17:17:00.002+01:00</published><updated>2008-07-01T17:21:38.063+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Lloyds TSB'/><title type='text'>Important Notice ( Lloyds TSB Security®Re-Confirm Your Identity and Remove Your Account Limitation Online)</title><content type='html'>Another phishing email... This one is designed to frighten the recipients (who can be bothered to read it) into thinking that attempts have been made to access their bank account. The result of these is that the account has been frozen. If that had happened, why would there be a link to reactivate it - the bank would send the reactivation details through the post, not a email link.&lt;br /&gt;&lt;br /&gt;The actual target of the button seems to be something like hunterxhunter.cl. Doesn't seem to be a phishing site, so maybe they've had a page or a redirect hijacked.&lt;br /&gt;&lt;br /&gt;Here's the content.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Customer Lloyds TSB Bank plc &lt;br /&gt;&lt;br /&gt;This message has been sent to you from because we have noticed invalid login attempts into your account, due to this we are temporarily limiting and restricting your account access until we confirm your identity.&lt;br /&gt;&lt;br /&gt;To confirm your identity and remove your account limitation please following the Log on below.&lt;br /&gt; &lt;br /&gt;Lloyds TSB Bank plc is committed to ensure the safeguard of each customer's personal information,making sure only authorised individuals have access to their accounts. It is all about your security.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-8221010503796640938?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/8221010503796640938/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=8221010503796640938' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8221010503796640938'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8221010503796640938'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/07/important-notice-lloyds-tsb-securityre.html' title='Important Notice ( Lloyds TSB Security®Re-Confirm Your Identity and Remove Your Account Limitation Online)'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-7725298137939402870</id><published>2008-06-26T20:19:00.002+01:00</published><updated>2008-06-26T20:27:07.398+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Halifax'/><title type='text'>Halifax | This confirmation email has been sent as a security precaution.</title><content type='html'>The Halifax don't often feature on my list of phishing emails, but here's one. And what a cheap and nasty phishing attempt it is! The link isn't clickable and clearly points to something other than the actual bank - http://host-69-144-30-10.glt-wy.client.&lt;u&gt;bresnan.net&lt;/u&gt;/halifax-online.co.uk/. Looking through Google, there are other reports of redirects on that website being hacked to point to the phishing websites.&lt;br /&gt;&lt;br /&gt;The email is very basic - the sender obviously has no idea of how to create paragraphs in the email - so it doens't look at all official. The content is designed to panic people, but I hope that the cheap look and the lack of a link is going to help to stop people copying the link and falling for the trick!&lt;br /&gt;&lt;br /&gt;I suspect that the sender has copied some text from a genuine Halifax email and tried (but failed) to use that. The best bit, considering the content added by the sender, is the copied line "&lt;i&gt;Halifax would never send you an email asking you to verify your secure online banking details&lt;/i&gt;" - it says it all really! That's probably the most honest bit of the email!&lt;br /&gt;&lt;br /&gt;Here's the email:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear customer, Thank you for confirming your telephone contact details. If you have made any amendments to your contact details these have now been updated. Please note that if you hold any joint accounts, only your details will be updated. This confirmation email has been sent as a security precaution. If you did not make this number change/confirmation, please visit the website below, phone lines are open 24 hours a day, 7 days a week. http://host-69-144-30-10.glt-wy.client.bresnan.net/halifax-online.co.uk/ Regards, Halifax Online Helpdesk FIGHT ONLINE FRAUD Please do not reply to this email address as it is not monitored and we will be unable to respond. Halifax would never send you an email asking you to verify your secure online banking details. Calls from BT landlines will cost a maximum of 4p per minute and a 6p call set-up fee. The price of calls from other telephone companies will vary. The call price is correct at 25/10/07. . -------------------------------------------------------------------------------------------------------------------- Bank of Scotland plc, Registered in Scotland Number SC327000 Registered office: The Mound, Edinburgh EH1 1YZ. Authorised and regulated by Financial Services Authority&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-7725298137939402870?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/7725298137939402870/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=7725298137939402870' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7725298137939402870'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7725298137939402870'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/halifax-this-confirmation-email-has.html' title='Halifax | This confirmation email has been sent as a security precaution.'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-260706360207025575</id><published>2008-06-25T13:14:00.003+01:00</published><updated>2008-06-25T13:18:01.989+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Lloyds TSB'/><title type='text'>Lloyds TSB | IMPORTANT: Account Verification needed (June 25, 2008) No.4</title><content type='html'>Here's an email targeted at someone that doesn't feature too often - Lloyds TSB.&lt;br /&gt;&lt;br /&gt;It tries to use the FSA as an excuse for needing more information - just so that they can snare the unlucky recipient into revealing too many details. There's no reason the FSA would make a bank collect more information on customers and they definitely would tell you to do it through a link pointing to http://&lt;u&gt;portapropiedades.com.ar&lt;/u&gt;/sitemap/str/?https://online.lloydstsb.co.uk/customer.ibc?WT.svl=ibcplogon.&lt;br /&gt;&lt;br /&gt;portapropiedades.com.ar does appear in other phishing results, but the main site is not written in English, so I've no idea what the rest of the site is about. Here's the email content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Lloyds TSB Customer,&lt;br /&gt;&lt;br /&gt;As a part of our efforts to meet the requirements of the Financial Services Authority we now ask all Lloyds TSB Bank users to update their account information. It's a smart and simple way to add an additional layer of protection to your account.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Please use the link below to update your account:&lt;br /&gt;&lt;br /&gt;Click here to continue updating Your Lloyds TSB Account;&lt;br /&gt;(You will be redirected to a Lloyds TSB Banking logon page with an unique Session ID)&lt;br /&gt;&lt;br /&gt;Thank you for your continued patronage,&lt;br /&gt;President of Lloyds TSB Bank plc.&lt;br /&gt;&lt;br /&gt;Programs and data held on this system belong or are licensed to Lloyds TSB Bank plc and Lloyds TSB Scotland plc. It is an offence to access the programs and data unless you are doing so through your own account using the Passwords and User ID issued to you by Lloyds TSB Bank plc and Lloyds TSB Scotland plc in an authorised manner and in accordance with all applicable laws.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-260706360207025575?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/260706360207025575/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=260706360207025575' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/260706360207025575'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/260706360207025575'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/lloyds-tsb-important-account.html' title='Lloyds TSB | IMPORTANT: Account Verification needed (June 25, 2008) No.4'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-5569954767534462461</id><published>2008-06-18T22:02:00.000+01:00</published><updated>2008-06-18T22:05:10.446+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='first bank'/><title type='text'>First Bank | Administration alert!</title><content type='html'>This is a bank that I've never heard of before, I assume it's an American bank, or if not, some other non UK bank.&lt;br /&gt;&lt;br /&gt;The link points to an IP address - http://69.246.203.213/, so without clicking it's hard to tell what the actual web address is, but I can say with almost guaranteed certainty that it's not the genuine site! Here's the content.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;As a Firstbanks customer, your privacy and security always come first. We have been dedicated to customer safety and protection, and our mission remains as strong as ever.&lt;br /&gt;&lt;br /&gt;We inform you that your Firstbanks Internet banking account is about to expire. It is strongly recommended to update it immediately. Update form is located here.&lt;br /&gt;&lt;br /&gt;However, failure to confirm your records may result in account suspension.&lt;br /&gt;&lt;br /&gt;This is an automated message. Please, do not reply.&lt;br /&gt;&lt;br /&gt;Sincerely, Firstbanks administration&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-5569954767534462461?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/5569954767534462461/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=5569954767534462461' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5569954767534462461'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5569954767534462461'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/first-bank-administration-alert.html' title='First Bank | Administration alert!'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-1682453596658430366</id><published>2008-06-18T10:31:00.002+01:00</published><updated>2008-06-18T10:31:00.367+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Google Adwords'/><title type='text'>Your Account with Google AdWords.</title><content type='html'>Given that these Google Adwords phishing emails only started to appear in March, there have been a good number compared to some of the banks that are being targeted.&lt;br /&gt;&lt;br /&gt;For this one, the target URL is http://www.adwords.google.com.oskin.cn/select/Login. I can only find oskin.cn on Google in Phishing results, so maybe it's been setup just for that.&lt;br /&gt;&lt;br /&gt;Here's the content.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Advertiser, &lt;br /&gt;&lt;br /&gt;We were unable to process your payment.&lt;br /&gt;Your ads will be suspended soon unless we can process your payment.&lt;br /&gt;To prevent your ads from being suspended, please update your payment information.&lt;br /&gt;&lt;br /&gt;Please sign in&lt;br /&gt;to your account at http://adwords.google.com/select/login, &lt;br /&gt;and update your payment information.&lt;br /&gt;&lt;br /&gt;We look forward to providing you with the most effective advertising available.&lt;br /&gt;Thank you for advertising with Google AdWords. &lt;br /&gt;&lt;br /&gt;The Google AdWords Team&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-1682453596658430366?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/1682453596658430366/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=1682453596658430366' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1682453596658430366'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1682453596658430366'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/your-account-with-google-adwords.html' title='Your Account with Google AdWords.'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-7567612623438715827</id><published>2008-06-18T09:24:00.002+01:00</published><updated>2008-06-18T09:30:52.065+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Abbey National'/><title type='text'>Abbey | Account Notification: Access To Your Account Has Been Limited</title><content type='html'>After NatWest (currently 67 posts), Abbey is the second placed banking target on this site, with just 17 posts. It's trying to catch up...&lt;br /&gt;&lt;br /&gt;This at least gives a reason for the verification, but from experience I know that when the account is restricted the restrictions are lifted only by posting new cards out - I know, I had to wait without access to my cash until the new card came through!&lt;br /&gt;&lt;br /&gt;The actual target URL is http://www.rightleadership.com//poll/pollphp/verify/cgi.htm, which seems to be a perfectly innocent site. I've not tested that the link does work, but I expect that somehow the phishers have broken into the site.&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;i&gt;Unauthorized Access Notification&lt;br /&gt;&lt;br /&gt;Dear Abbey Bank Customer,&lt;br /&gt;&lt;br /&gt;This message has been sent to you from Abbey Bank because we have noticed invalid login attempts into your account, due to this we are temporarily limiting and restricting your account access until we confirm your identity.&lt;br /&gt;&lt;br /&gt;We therefore implore you to log into your account to verify any possible findings.&lt;br /&gt;&lt;br /&gt;VERIFY&lt;br /&gt;&lt;br /&gt;Thank you&lt;/i&gt;&lt;/center&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-7567612623438715827?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/7567612623438715827/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=7567612623438715827' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7567612623438715827'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7567612623438715827'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/abbey-account-notification-access-to.html' title='Abbey | Account Notification: Access To Your Account Has Been Limited'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-6252671211153274114</id><published>2008-06-18T09:17:00.002+01:00</published><updated>2008-06-18T09:24:29.402+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>Natwest | REGULAR MAINTENANCE</title><content type='html'>Yet another phishing email targeted at the natwest - I've just received 2 copies of this one.&lt;br /&gt;&lt;br /&gt;First, no respectable bank would randomly send anonymous emails ("Dear NatWest Customer") to its customers saying you have to resupply your logon details or lose your banking access - it's rubbish. Don't believe it!&lt;br /&gt;&lt;br /&gt;Although the email does claim to show the actual URL, which is not NatWest's URL, it actually points to http://www.ceazimut.org/auth/login.aspx?action=login. Can't see what that website is about.&lt;br /&gt;&lt;br /&gt;Here's the email:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear NatWest customer,&lt;br /&gt;&lt;br /&gt;WE ARE CURRENTLY PERFORMING A REGULAR MAINTENANCE OF OUR DATABASE FOR ONLINE CUSTOMERS.&lt;br /&gt;&lt;br /&gt;We apologize for the inconvenience this may cause but your account was randomly flagged for verification and you'll be taken through a short authentication process.&lt;br /&gt;&lt;br /&gt;To start now please click here.&lt;br /&gt;&lt;br /&gt;If your e-mail client stops you to click the link above, please copy the following URL to your browser:&lt;br /&gt;&lt;br /&gt;http://www.natwest.srvdns.net/index.aspx?action=logon &lt;br /&gt;&lt;br /&gt;Please note! If we don't receive the appropriate account verification within 24 hours since you've got this email your online access can be suspended until further notice. The purpose of this verification is to ensure your account has not been fraudulently used and you're not a victim of identity theft.&lt;br /&gt;&lt;br /&gt;Thank you for understanding and helping us improve.&lt;br /&gt;&lt;br /&gt;------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Unauthorized account access or use is not permitted and may constitute a crime punishable by law.&lt;br /&gt;&lt;br /&gt;© NatWest. 2001 - 2008. UK.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-6252671211153274114?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/6252671211153274114/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=6252671211153274114' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6252671211153274114'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6252671211153274114'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/natwest-regular-maintenance.html' title='Natwest | REGULAR MAINTENANCE'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-9148345820284149553</id><published>2008-06-12T20:12:00.002+01:00</published><updated>2008-06-12T20:12:00.779+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>NatWest Important Security Notice</title><content type='html'>A quick count up and over 25% of the phishing emails posted to this blog are aimed at the NatWest, and I don't publish them all - some that are too similar when I'm too busy get deleted rather than posted. Not very helpful, but time isn't always on my side...&lt;br /&gt;&lt;br /&gt;So it's not surprising that here's another Natwest phishing email, received by me twice in different email boxes. These are the people that list a dozen or so names in the to: field to send the email to all of those at once. Not very convincing...&lt;br /&gt;&lt;br /&gt;The link is harder to cut &amp; paste as it's behind a graphic, but retyping it, it goes something like http://www1.nwolb.com.&lt;u&gt;jgnvvhx742.com&lt;/u&gt;/default.aspx etc. Once more, jgnvvhx742.com does appear in a couple of phishing results on Google.&lt;br /&gt;&lt;br /&gt;Here's the content.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;National Westminster Bank has been receiving complaints from our customers for unauthorised use of the Natwest Online accounts. As a result we periodically review Natwest Online Accounts and temporarily restrict access of those accounts which we think are vunerable to the unauthorised use.&lt;br /&gt;&lt;br /&gt;This message has been sent to you from National Westminster Bank because we have noticed invalid login attempts into your account, due to this we are temporarily limiting and restricting your account access until we confirm your identity.&lt;br /&gt;&lt;br /&gt;To confirm your identity and remove your account limitation please following the link below.&lt;br /&gt;&lt;br /&gt;National Westminster Bank is committed to ensure the safeguard of each customer's personal information, making sure only authorised individuals have access to their accounts. It is all about your security. &lt;br /&gt; &lt;br /&gt;Accounts Management As outlined in our User Agreement, Natwest will &lt;br /&gt;periodically send you information about site changes and enhancements. &lt;br /&gt;&lt;br /&gt;Visit our Privacy Policy and User Agreement if you have any questions. &lt;br /&gt;http://www.Natwest.com/help/index.jhtml&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-9148345820284149553?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/9148345820284149553/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=9148345820284149553' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/9148345820284149553'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/9148345820284149553'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/natwest-important-security-notice.html' title='NatWest Important Security Notice'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-8594839798938586599</id><published>2008-06-12T19:09:00.002+01:00</published><updated>2008-06-12T19:09:00.702+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>Natwest | Details confirmation</title><content type='html'>Does a day go by without this lot sending an email targeted at the poor Natwest??? There's plenty of variations of this about with the referer id / cookie id in the link.&lt;br /&gt;&lt;br /&gt;The actual destination of the link points to http://www.natwest.co.uk.&lt;u&gt;harvioe.name&lt;/u&gt;/newmeasures/procedure/default.aspx?refererident=[removed]&amp;cookieid=[removed]. harvioe.name appears in a couple of phishing results in Google. Here's the content...&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear NatWest bank customer,&lt;br /&gt;&lt;br /&gt;Security and confidentiality are at the heart of Natwest Bankline. Your data (and your money) is protected by a number of technologies, including Secure Sockets Layer (SSL) encryption.&lt;br /&gt;We would like to notify you that NatWest bank carries out customer data verification procedure that is compulsory for all Natwest bank customers. This procedure is attributed to a routine banking software update.&lt;br /&gt;&lt;br /&gt;Please login to Natwest online banking using the link below and follow the instructions on the screen.&lt;br /&gt;&lt;br /&gt;http://www.natwest.co.uk/newmeasures/procedure/default.aspx?refererident=[removed]&amp;cookieid=[removed]&lt;br /&gt;&lt;br /&gt;Natwest Customer Service&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref l-cmr&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-8594839798938586599?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/8594839798938586599/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=8594839798938586599' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8594839798938586599'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8594839798938586599'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/natwest-details-confirmation.html' title='Natwest | Details confirmation'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-4025690390836322986</id><published>2008-06-12T18:03:00.002+01:00</published><updated>2008-06-12T18:09:01.523+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Abbey'/><title type='text'>Problems with account Abbey’s Business Bank</title><content type='html'>Here's a new one. I've not seen this content before and it's targeted at Abbey, who do appear occasionally. The difference is that this time it's targeted at their business division.&lt;br /&gt;&lt;br /&gt;The link actually goes to http://ibank.anbusiness.servlet.logonservlet.signon.passcode09u5d125a87hn1j.discover.ceo89u6kj811.business.portal06460.required.&lt;u&gt;4598ry.com&lt;/u&gt;/LogonServlet.htm - presumably that complicated setup of subdirectories is to try to bury the actual website name of "4598ry.com", which doesn't yet feature in any Google results (give me a short while...).&lt;br /&gt;&lt;br /&gt;I have never seen any genuine emails from Abbey, I can only assume they don't actually send any (which in my opinion is good). It does look like a genuine (rushed)email, but it's sent to a random account and I'm sure they wouldn't introduce themselves with "Dear Abbey's Business Bank Account Customer". I'm not even sure that is proper English (why the "'s"?).&lt;br /&gt;&lt;br /&gt;Don't touch the email, here's the content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Abbey's Business Bank Account Customer:&lt;br /&gt;&lt;br /&gt;Due to the emergency situation with security server, Abbey's Business Service is presently&lt;br /&gt;verifying your web browsers and ip address. &lt;br /&gt;In order to check your security level on a website, please follow the instructions below.&lt;br /&gt;&lt;br /&gt;IMPORTANT! Customers must validate personal information today.&lt;br /&gt;&lt;br /&gt;Continue&gt;&gt;&lt;br /&gt;&lt;br /&gt;This situation involves circumstances outside of our control, so we ask for your patience.&lt;br /&gt;We will keep you advised as the situation changes.&lt;br /&gt;&lt;br /&gt;Abbey's Business Bank - Complete Solutions to protect your business and secure your computer.&lt;br /&gt;Thank you. &lt;br /&gt;2008 All Rights Reserved Abbey's Business Bank&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref i-cmr&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-4025690390836322986?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/4025690390836322986/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=4025690390836322986' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/4025690390836322986'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/4025690390836322986'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/problems-with-account-abbeys-business.html' title='Problems with account Abbey’s Business Bank'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-1921865063522816618</id><published>2008-06-12T09:07:00.002+01:00</published><updated>2008-06-12T09:14:43.829+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ebay'/><title type='text'>You've received a question about eBay item: BRAND NEW GENUINE APPLE *iPod touch* 16GB 16 GB WIFI (170227727186)</title><content type='html'>Another realistic looking email question about email, but intent on robbing your security details. I'm not sure how much damage can be done by getting hold of Ebay details - I thought that Ebay didn't store any personal information, but maybe there are addresses there or they are assuming a lot of people will use the same password for PayPal...&lt;br /&gt;&lt;br /&gt;Like other recent phishing emails, this one uses an IP address to hide the fact that it's the wrong URL: http://66.206.18.94/index.htm. But that doesn't make it any safer. Here's the email content...&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Hi, I will send you the item today via "Royal Mail Sameday".&lt;br /&gt;&lt;br /&gt;Have a nice day!&lt;br /&gt;Scott&lt;br /&gt;&lt;br /&gt;-saabman1970 Respond to this question  &lt;br /&gt;&lt;br /&gt;If you use My Messages to respond, your email address will not be shared. &lt;br /&gt;&lt;br /&gt;Item and user details &lt;br /&gt;Item Title: BRAND NEW GENUINE APPLE *iPod touch* 16GB 16 GB WIFI &lt;br /&gt;Item Number: 170227727186 &lt;br /&gt;Item URL: http://cgi.ebay.co.uk/ws/eBayISAPI.dll?ViewItem&amp;item=170227727186 &lt;br /&gt;End Date: 11-Jun-08 01:11:32 BST &lt;br /&gt;From User: asmdirect1 ( 16657 )   &lt;br /&gt;98.7 % Positive &lt;br /&gt;since 18-Nov-03 in United Kingdom &lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref i-cmr&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-1921865063522816618?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/1921865063522816618/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=1921865063522816618' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1921865063522816618'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1921865063522816618'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/youve-received-question-about-ebay-item_12.html' title='You&apos;ve received a question about eBay item: BRAND NEW GENUINE APPLE *iPod touch* 16GB 16 GB WIFI (170227727186)'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-4050995122241858987</id><published>2008-06-10T11:23:00.002+01:00</published><updated>2008-06-10T11:23:02.128+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>NatWest Bank: Online Banking Form! (Mon, 09 Jun 2008 00:27:48 -0500)</title><content type='html'>Would the day be complete with also being able to post about another &lt;a href="http://phishalert.blogspot.com/2008/05/natwest-bank-customer-service-your.html"&gt;Natwest Customer Form&lt;/a&gt;! This looks word for word the same as last time, just the sent to a different recipient email address and a different URL.&lt;br /&gt;&lt;br /&gt;The URL this time is http://www.natwest.co.uk.&lt;u&gt;richardjacob.co.uk&lt;/u&gt;/serverstack/usersdirectory/ncf.aspx?pc==[removed]&amp;id=[removed] and like today's earlier post, there's nothing on Google about richardjacob.co.uk, so I can't say anything about the site.&lt;br /&gt;&lt;br /&gt;Here's the content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear customer of NatWest bank,&lt;br /&gt;&lt;br /&gt;We are running a scheduled maintenance on our servers. We want to make sure your money and your personal details are safe and secure.&lt;br /&gt;Due to new security policies all NatWest bank customers must complete the Natwest Customer Form.&lt;br /&gt;&lt;br /&gt;To complete the form, please use the link below:&lt;br /&gt;&lt;br /&gt;Natwest Customer Form&lt;br /&gt;&lt;br /&gt;This should take you directly to the Natwest Customer Form.&lt;br /&gt;&lt;br /&gt;Sincerely,&lt;br /&gt;Natwest Customer Service&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref i-cmr&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-4050995122241858987?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/4050995122241858987/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=4050995122241858987' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/4050995122241858987'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/4050995122241858987'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/natwest-bank-online-banking-form-mon-09.html' title='NatWest Bank: Online Banking Form! (Mon, 09 Jun 2008 00:27:48 -0500)'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-8756992339825817945</id><published>2008-06-10T10:20:00.002+01:00</published><updated>2008-06-10T10:20:01.537+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'></title><content type='html'>It's the old &lt;a hef="http://phishalert.blogspot.com/2008/06/natwest-bank-reminder-client-details.html"&gt;referer id / cookie id natwest phishing emails&lt;/a&gt; again. This time the URL is http://www.natwest.com.&lt;u&gt;eloriid.com&lt;/u&gt;/newmeasures/procedure/default.aspx?refererident=[removed]&amp;cookieid=[removed]. I can't find any results for eloriid.com, so no idea what is going on there. Maybe it's newly registered.&lt;br /&gt;&lt;br /&gt;Here's the content:&lt;br /&gt;&lt;br /&gt;Dear NatWest bank customer,&lt;br /&gt;&lt;br /&gt;Security and confidentiality are at the heart of Natwest Bankline. Your data (and your money) is protected by a number of technologies, including Secure Sockets Layer (SSL) encryption.&lt;br /&gt;We would like to notify you that NatWest bank carries out customer data verification procedure that is compulsory for all Natwest bank customers. This procedure is attributed to a routine banking software update.&lt;br /&gt;&lt;br /&gt;Please login to Natwest online banking using the link below and follow the instructions on the screen.&lt;br /&gt;&lt;br /&gt;http://www.natwest.com/newmeasures/procedure/default.aspx?refererident=[removed]&amp;cookieid=[removed]&lt;br /&gt;&lt;br /&gt;Natwest Customer Service&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-8756992339825817945?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/8756992339825817945/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=8756992339825817945' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8756992339825817945'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8756992339825817945'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/its-old-referer-id-cookie-id-natwest.html' title=''/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-4374861086370996958</id><published>2008-06-10T09:13:00.002+01:00</published><updated>2008-06-10T09:20:06.468+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>NatWest Online Accounts Limited Access</title><content type='html'>Here's a new looking phishing email, targeted at an old favourite - the NatWest. As frequently happens, the email is a little confusing. I'm never sure whether this reflects the sender's grasp of English or is intentional, so that the recipient doesn't bother too much about what the email says and instead follows the phishing link to see what's going on.&lt;br /&gt;&lt;br /&gt;This one first talks about regular screening, then suspicious ativity then finally limitations. But, there's loads of pointers to the unwary that it is phishing:&lt;br /&gt;&lt;br /&gt;1 - 'Dear NatWest customer' - a bank should email you by name so you know the email is more likely to be for real&lt;br /&gt;&lt;br /&gt;2 - it's sent to undisclosed-recipients - why hide the recipient's email address? Because the one email is going to thousands of addresses. If it were genuine, it would go to just the one.&lt;br /&gt;&lt;br /&gt;3 - I'm certain the natwest would never send you to a link http://www.swsme.net/auth/login.aspx to sign on! It would always be to their own site, even if you were later redirected. You can see the URL by placing the mouse over the link, but not clicking. swsme.net does appear in a few results, with the comment from Google 'This site may harm your computer.'. So it's probably not a very good site to visit!&lt;br /&gt;&lt;br /&gt;Here's the content.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear NatWest customer, &lt;br /&gt;&lt;br /&gt;NatWest is constantly working to ensure security by regularly screening the accounts in our system. We recently reviewed your account, and we need more information to help us provide you with secure service. Until we can collect this information, your access to sensitive account features will be limited. We would like to restore your access as soon as possible, and we apologize for the inconvenience. &lt;br /&gt;&lt;br /&gt;--------------------------------------------------------------------------------&lt;br /&gt;Why is my account access limited?&lt;br /&gt;&lt;br /&gt;Your account access has been limited for the following reason(s):&lt;br /&gt;&lt;br /&gt;Jun. 9, 2008: We have detected suspicious activity regarding the receipt or withdrawal of funds. &lt;br /&gt;&lt;br /&gt;(Your case ID for this reason is NW-682-258-517.)&lt;br /&gt;&lt;br /&gt;--------------------------------------------------------------------------------&lt;br /&gt;How can I restore my account access?&lt;br /&gt;&lt;br /&gt;Please Click Here to Log In to your account and complete the "Steps to Remove Limitations."  &lt;br /&gt;&lt;br /&gt;Once you complete all of the checklist items, your case will be reviewed by one of our Account Specialists. We will send you an email with the outcome of the review.&lt;br /&gt;&lt;br /&gt;Copyright © National Westminster Bank plc, NatWest UK, 2008. &lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-4374861086370996958?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/4374861086370996958/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=4374861086370996958' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/4374861086370996958'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/4374861086370996958'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/natwest-online-accounts-limited-access.html' title='NatWest Online Accounts Limited Access'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-7406216790286279610</id><published>2008-06-06T18:48:00.004+01:00</published><updated>2008-06-06T18:54:22.556+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='emails'/><category scheme='http://www.blogger.com/atom/ns#' term='lottery'/><title type='text'>WINNINING NOTICATION</title><content type='html'>Another amazing $2m winning lottery ticket, for a lottery I've never entered... This one even has a realistic, if not genuine, address at  the top of it.&lt;br /&gt;&lt;br /&gt;It is strange that they want me to reply in 7 days to a draw that took place 4 and a half months ago! Seems that the scammers haven't checked their email carefully enough! Also, if it was genuine, why a Yahoo email address!&lt;br /&gt;&lt;br /&gt;Don't touch it if you have also received this email - it's nothing more than a scam. It does amuse me that there are adverts at the bottom of the email.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;UK National lottery&lt;br /&gt;3b Olympic Way, Sefton Business Park,&lt;br /&gt;Aintree,Liverpool , L30 1RD&lt;br /&gt;REF N? UKL/74-A0802742007&lt;br /&gt;BATCHNO:LTBK00018&lt;br /&gt;TICKET NO:A669340221&lt;br /&gt;WINNING NUMBER:7041&lt;br /&gt;&lt;br /&gt;DearWinner,&lt;br /&gt;&lt;br /&gt;This is to inform you that you have been selected for a cash prize of&lt;br /&gt;(US$2,000,000.00 ) held on 24th of January 2008. The selection process&lt;br /&gt;was carried out through random selection in our computerized email&lt;br /&gt;selection system from a database of over 250,000 email addresses drawn from which&lt;br /&gt;you were selected.&lt;br /&gt;To file your claims please contactour claims processing department for&lt;br /&gt;clearance procedures.&lt;br /&gt;Mr. James Nichson(Claim Agent)&lt;br /&gt;International claim Department,UK&lt;br /&gt;Email:drclaravein@yahoo.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;You are advised to provide thebelow informations for final claim inspection.&lt;br /&gt;&lt;br /&gt;FULLNAME:...........................&lt;br /&gt;ADDRESS-----------------------------&lt;br /&gt;SEX:......................................&lt;br /&gt;AGE.......................................&lt;br /&gt;NATIONALITY.........................&lt;br /&gt;OCCUPATION.........................&lt;br /&gt;PHONE..................................&lt;br /&gt;FAX:--------------------------------------&lt;br /&gt;BATCHNUMBER:------------------&lt;br /&gt;TICKET NUMBER: ----------------&lt;br /&gt;WINNINGNUMBER:--------------&lt;br /&gt;&lt;br /&gt;You  have to contact your claim agent before 7 working days&lt;br /&gt;Yours faithfully,&lt;br /&gt;Mrs Mary James&lt;br /&gt;Online coordinator for&lt;br /&gt;UK NATIONAL LOTTERY&lt;br /&gt;&lt;br /&gt;Now book your Railway Tickets by cash at Sify Iway. For more details contact our Customer Care &lt;br /&gt;&lt;br /&gt;Watch latest movie trailers and behind the scenes footage of Bigg Boss and much more! www.sifymax.com &lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-7406216790286279610?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/7406216790286279610/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=7406216790286279610' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7406216790286279610'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7406216790286279610'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/winnining-notication.html' title='WINNINING NOTICATION'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-3098357199456996884</id><published>2008-06-04T09:54:00.002+01:00</published><updated>2008-06-04T10:08:37.457+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ebay'/><title type='text'>You've received a question about eBay item: HP COMPAQ N400C LAPTOP 850MHZ 256MB 20GB CD WINDOWS.. (160246121318)</title><content type='html'>Another Ebay one, trying to convince the recipient that you have been bidding on a laptop that you didn't really want... For this one the destination URL is http://&lt;u&gt;4u2gifts.com&lt;/u&gt;/eindex.htm?ViewItem&amp;item=160246121318&amp;ssPageName=ADME:X:AAQ:GB:1123.4www.u2gifts.com looks like a respectable website that has been 'invaded' by the phishers - there are other phishing reports dating back to at least 1st June on Google. So I suspect someone has guessed their ftp passwords...&lt;br /&gt;&lt;br /&gt;Here's the email content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;From: eBay Member: asmdirect1&lt;br /&gt;&lt;br /&gt;Your question from an eBay member  &lt;br /&gt; &lt;br /&gt;Do not respond to the sender if this message requests that you complete the transaction outside of eBay. This type of offer is against eBay policy, may be fraudulent, and is not covered by buyer protection programs. Learn More .  &lt;br /&gt;&lt;br /&gt;Hello, how do you intend to pay, PayPal or Bank Transfer?&lt;br /&gt;Let me know a.s.a.p. please.&lt;br /&gt;&lt;br /&gt;Jamie&lt;br /&gt;&lt;br /&gt;Thanks.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;- asmdirect1 Respond to this question  &lt;br /&gt;&lt;br /&gt;If you use My Messages to respond, your email address will not be shared. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Item and user details &lt;br /&gt;Item Title: HP COMPAQ N400C LAPTOP 850MHZ 256MB 20GB CD WINDOWS.. &lt;br /&gt;Item Number: 160246121318 &lt;br /&gt;Item URL: http://cgi.ebay.co.uk/ws/eBayISAPI.dll?ViewItem&amp;item=160246121318 &lt;br /&gt;End Date: 03-Jun-08 09:00:00 BST &lt;br /&gt;From User: asmdirect1 ( 4093 ) &lt;br /&gt;97.4 % Positive &lt;br /&gt;since 10-May-02 in United Kingdom&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref i-cmr&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-3098357199456996884?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/3098357199456996884/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=3098357199456996884' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/3098357199456996884'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/3098357199456996884'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/youve-received-question-about-ebay-item.html' title='You&apos;ve received a question about eBay item: HP COMPAQ N400C LAPTOP 850MHZ 256MB 20GB CD WINDOWS.. (160246121318)'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-273534400386099814</id><published>2008-06-03T12:33:00.000+01:00</published><updated>2008-06-03T12:33:00.291+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Anglo Irish Bank'/><title type='text'>Anglo Irish Bank customer:1 new ALERT message.</title><content type='html'>This one is very similar to &lt;a href="http://phishalert.blogspot.com/2008/06/anglo-irish-bank-customer1-new-alert.html"&gt;yesterday's&lt;/a&gt; Anglo Irish Bank phishing email. The target URL is still http://72.214.45.5/~admin/.cgi/, so I assume the scam is yet to be shut down. Here's the content.&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;i&gt;Dear customer for Anglo Irish Bank, &lt;br /&gt;&lt;br /&gt;You have 1 new security message&lt;br /&gt;Please login to your Anglo Irish Bank&lt;br /&gt;and visit the Message Center section in order to read the message.&lt;br /&gt;&lt;br /&gt;To Login, fast in your account:&lt;br /&gt;&lt;br /&gt;Anglo Irish Bank Online&lt;br /&gt;&lt;br /&gt;© 2008 Anglo Irish Bank. All rights reserved &lt;/i&gt;&lt;/center&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-273534400386099814?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/273534400386099814/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=273534400386099814' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/273534400386099814'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/273534400386099814'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/anglo-irish-bank-customer1-new-alert_03.html' title='Anglo Irish Bank customer:1 new ALERT message.'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-1341147870684126114</id><published>2008-06-03T11:30:00.002+01:00</published><updated>2008-06-03T11:30:03.933+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>NatWest Bank Reminder: Client Details Confirmation -Mon, 02 Jun 2008 14:09:52 -0600</title><content type='html'>The Natwest are once more the target of a phishing email. This time around the destination URL is http://www.natwest.co.uk.&lt;u&gt;dg-yar5.org.uk&lt;/u&gt;/newmeasures/procedure/default.aspx?refererident=[removed]&amp;cookieid=[removed] - so probably yet another of the &lt;a href="http://phishalert.blogspot.com/2008/06/natwest-bank-automatic-account-reminder.html"&gt;current series&lt;/a&gt; targeting the NatWest.&lt;br /&gt;&lt;br /&gt;Here's the email content.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear NatWest bank customer,&lt;br /&gt;&lt;br /&gt;Security and confidentiality are at the heart of Natwest Bankline. Your data (and your money) is protected by a number of technologies, including Secure Sockets Layer (SSL) encryption.&lt;br /&gt;We would like to notify you that NatWest bank carries out customer data verification procedure that is compulsory for all Natwest bank customers. This procedure is attributed to a routine banking software update.&lt;br /&gt;&lt;br /&gt;Please login to Natwest online banking using the link below and follow the instructions on the screen.&lt;br /&gt;&lt;br /&gt;http://www.natwest.co.uk/newmeasures/procedure/default.aspx?refererident=54381748798756137278337923438792855237123444418666954&amp;cookieid=7674508179521&lt;br /&gt;&lt;br /&gt;Natwest Customer Service&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref i-cmr&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-1341147870684126114?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/1341147870684126114/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=1341147870684126114' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1341147870684126114'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1341147870684126114'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/natwest-bank-reminder-client-details.html' title='NatWest Bank Reminder: Client Details Confirmation -Mon, 02 Jun 2008 14:09:52 -0600'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-2748174421613142565</id><published>2008-06-02T18:05:00.000+01:00</published><updated>2008-06-03T10:30:14.836+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PayPal'/><title type='text'>A secondary e-mail address has been added to your PayPal.</title><content type='html'>Here's a new style of Phishing email - I had to look twice to convince myself here that it was the email that was phishing and not someone really breaking into my account. Indications that it's phishing:&lt;br /&gt;&lt;br /&gt;1 - 'Dear PayPal user' - should give my name&lt;br /&gt;&lt;br /&gt;2 - sent to 'undisclosed recipients' - would have been sent to my registered email address.&lt;br /&gt;&lt;br /&gt;3 - the destination of the link is http://210.187.79.36/~anna/.bin/ - an IP address to mask the fake website name, it would be www.paypal.co.uk / www.paypal.com if it was real.&lt;br /&gt;&lt;br /&gt;If in doubt, open a ne browser window and type in www.paypal.com to sign into your account. Never use the links in emails, even on genuine emails. It leads you into a flase sense of security.&lt;br /&gt;&lt;br /&gt;Here's the email content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear PayPal user,&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;You've added an additional email address to your account.Us for details &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To make sure you can use your PayPal account the next time you make a purchase, all you need to do is confirm or not your email address.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To Login, fast in your paypal account :&lt;br /&gt;&lt;br /&gt;https://www.paypal.com/uk/cgi-bin/webscr?cmd=_login-run&amp;dispatch=5d80a13c0db1f1ff80d5423b5265b6559fc2aae010bfb00cf3c64 &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If your email program has problems with hypertext links, you may also confirm your email address by logging in to your account. &lt;br /&gt;&lt;br /&gt;&gt;&gt;&gt; Apply online&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Please do not reply to this email.This mailbox is not monitored and you will not receive a response.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;PayPal Email ID PP025197.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-2748174421613142565?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/2748174421613142565/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=2748174421613142565' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2748174421613142565'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2748174421613142565'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/secondary-e-mail-address-has-been-added.html' title='A secondary e-mail address has been added to your PayPal.'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-7378910313742105211</id><published>2008-06-02T13:37:00.003+01:00</published><updated>2008-06-02T13:37:01.175+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>NatWest Bank: Automatic Account Reminder (Mon, 02 Jun 2008 03:09:37 -0500)</title><content type='html'>The Natwest continue to be a popular victim / target of the phishing emails. This one, like another recent email, uses the domain http://www.nwolb.com.nwolb.org.uk/newmeasures/procedure/default.aspx?refererident=[removed]&amp;cookieid=[removed] - very similar to the recent &lt;a href="http://phishalert.blogspot.com/2008/05/natwest-bank-notification.html"&gt;nwolb.me.uk&lt;/a&gt; and &lt;a href="http://phishalert.blogspot.com/2008/05/natwest-bank-safeguarding-customer.html"&gt;nwol&lt;/a&gt; emails, that have also used the refererident / cookie pairing in the link.&lt;br /&gt;&lt;br /&gt;Here's the email.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear NatWest bank customer,&lt;br /&gt;&lt;br /&gt;Security and confidentiality are at the heart of Natwest Bankline. Your data (and your money) is protected by a number of technologies, including Secure Sockets Layer (SSL) encryption.&lt;br /&gt;We would like to notify you that NatWest bank carries out customer data verification procedure that is compulsory for all Natwest bank customers. This procedure is attributed to a routine banking software update.&lt;br /&gt;&lt;br /&gt;Please login to Natwest online banking using the link below and follow the instructions on the screen.&lt;br /&gt;&lt;br /&gt;http://www.nwolb.com/newmeasures/procedure/default.aspx?refererident=7111256171904203771463961967533580325045981996921&amp;cookieid=07223497&lt;br /&gt;&lt;br /&gt;Natwest Customer Service&lt;/i&gt; &lt;br /&gt;&lt;br /&gt;ref l-cmr&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-7378910313742105211?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/7378910313742105211/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=7378910313742105211' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7378910313742105211'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7378910313742105211'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/natwest-bank-automatic-account-reminder.html' title='NatWest Bank: Automatic Account Reminder (Mon, 02 Jun 2008 03:09:37 -0500)'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-2659579373309878872</id><published>2008-06-02T12:33:00.002+01:00</published><updated>2008-06-02T12:36:47.042+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Anglo Irish Bank'/><title type='text'>Anglo Irish Bank customer:1 new ALERT message.</title><content type='html'>It seems the &lt;a href="http://phishalert.blogspot.com/2008/05/royal-bank-of-scotland-business.html"&gt;fake message alert&lt;/a&gt; is becoming quite popular - this time it's on a new target bank.&lt;br /&gt;&lt;br /&gt;Also like some recent emails, the actual destination URL is hidden by using the website's IP address, rather than the URL - http://72.214.45.5/~admin/.cgi/ is shown. Here's the email...&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;i&gt;Dear customer for Anglo Irish Bank, &lt;br /&gt;&lt;br /&gt;You have 1 new security message&lt;br /&gt;Please login to your Anglo Irish Bank&lt;br /&gt;and visit the Message Center section in order to read the message.&lt;br /&gt;&lt;br /&gt;To Login, fast in your account:&lt;br /&gt;&lt;br /&gt;Anglo Irish Bank Online&lt;/i&gt;&lt;/center&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-2659579373309878872?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/2659579373309878872/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=2659579373309878872' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2659579373309878872'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2659579373309878872'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/06/anglo-irish-bank-customer1-new-alert.html' title='Anglo Irish Bank customer:1 new ALERT message.'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-6838084555062135014</id><published>2008-05-31T09:28:00.002+01:00</published><updated>2008-05-31T09:34:59.646+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>NatWest Bank: safeguarding customer information</title><content type='html'>This one is very similar, but still subtly different to the email received &lt;a href="http://phishalert.blogspot.com/2008/05/natwest-bank-customer-service-your.html"&gt;earlier today&lt;/a&gt;. The tracking is there, but is following referer and cookie, rather than machine and 'id'. This one looks exactly like &lt;a href="http://phishalert.blogspot.com/2008/05/natwest-bank-notification.html"&gt;yesterday's&lt;/a&gt; Natwest EMail. So it's possible that they are both sent from different sources and it's just a coincidence that both have hit the same email address overnight. &lt;br /&gt;&lt;br /&gt;I alos didn't record which email address received yesterday's email, so no idea if they are working through the same list, sending repeat emails, or if they are on a different list. This email is sent to one address at a time, so it's possible they are working down a list that my email addresses appear on several times.&lt;br /&gt;&lt;br /&gt;This time around the link is to http://www.natwest.co.uk.&lt;u&gt;nwol.me.uk&lt;/u&gt;/newmeasures/procedure/default.aspx?refererident=[removed]&amp;cookieid=[removed] - yesterday it was nwolb.me.uk - so presumably the first site has been shut down, which could be the reason for repeating the email. Here's the content, again...&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear NatWest bank customer,&lt;br /&gt;&lt;br /&gt;Security and confidentiality are at the heart of Natwest Bankline. Your data (and your money) is protected by a number of technologies, including Secure Sockets Layer (SSL) encryption.&lt;br /&gt;We would like to notify you that NatWest bank carries out customer data verification procedure that is compulsory for all Natwest bank customers. This procedure is attributed to a routine banking software update.&lt;br /&gt;&lt;br /&gt;Please login to Natwest online banking using the link below and follow the instructions on the screen.&lt;br /&gt;&lt;br /&gt;http://www.natwest.co.uk/newmeasures/procedure/default.aspx?refererident=[removed]&amp;cookieid=[removed]&lt;br /&gt;&lt;br /&gt;Natwest Customer Service&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref l-cmr&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-6838084555062135014?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/6838084555062135014/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=6838084555062135014' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6838084555062135014'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6838084555062135014'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/natwest-bank-safeguarding-customer.html' title='NatWest Bank: safeguarding customer information'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-1432313139457231246</id><published>2008-05-31T09:22:00.003+01:00</published><updated>2008-05-31T09:30:14.577+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>NatWest Bank customer service: your account with us. [message ref:</title><content type='html'>Another 2 emails targetting Natwest customers overnight, both through the same email address and both very similar.&lt;br /&gt;&lt;br /&gt;The first is a scheduled maintenance. So obviously, when banks do this customers have to sign on to remind the banks of their security details. Not really a convincing excuse, is it? Instead of the NOF, it's now the NCF (the Natwest Customer Form) - that's making a few appearances.&lt;br /&gt;&lt;br /&gt;The target URL is http://www.natwest.com.&lt;u&gt;tknnt.me.uk&lt;/u&gt;/serverstack/usersdirectory/ncf.aspx?pc=[removed]&amp;id=[removed], so it's sent by the group of people who are &lt;a href="http://phishalert.blogspot.com/2008/05/important-notice-from-natwest-bank-bank.html"&gt;tracking which recipient PCs&lt;/a&gt; click on the links. Actually, the email content is the same as last Thursday's - I just didn't record which email address Thursday's arrived through.&lt;br /&gt;&lt;br /&gt;Here's the content.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear customer of NatWest bank,&lt;br /&gt;&lt;br /&gt;We are running a scheduled maintenance on our servers. We want to make sure your money and your personal details are safe and secure.&lt;br /&gt;Due to new security policies all NatWest bank customers must complete the Natwest Customer Form.&lt;br /&gt;&lt;br /&gt;To complete the form, please use the link below:&lt;br /&gt;&lt;br /&gt;Natwest Customer Form&lt;br /&gt;&lt;br /&gt;This should take you directly to the Natwest Customer Form.&lt;br /&gt;&lt;br /&gt;Sincerely,&lt;br /&gt;Natwest Customer Service&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref l-cmr&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-1432313139457231246?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/1432313139457231246/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=1432313139457231246' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1432313139457231246'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1432313139457231246'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/natwest-bank-customer-service-your.html' title='NatWest Bank customer service: your account with us. [message ref:'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-8460317075646403969</id><published>2008-05-30T15:14:00.002+01:00</published><updated>2008-05-30T15:19:16.555+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>NatWest Bank notification!</title><content type='html'>Another one of a similar format to recent &lt;a href="http://phishalert.blogspot.com/2008/05/important-notice-from-natwest-bank-bank.html"&gt;Natwest Phishing Emails&lt;/a&gt; - this one also triggering the virus software, which is unusual. Like the others, this one has a referer id / cookie id so the senders are tracking which recipients are opening the email.&lt;br /&gt;&lt;br /&gt;The grammar is suspect - 'We would like to notify you that NatWest bank carries out customer data verification procedure that is compulsory'. I see what they are trying to say, but it's not how an English bank would write it. The destination URL is http://www.natwest.com.&lt;u&gt;nwolb.me.uk&lt;/u&gt;/newmeasures/procedure/default.aspx?refererident=[removed]&amp;cookieid=[removed], which looks similar to others I've seen before, but nwolb.me.uk isn't in any search results of use, at the moment...&lt;br /&gt;&lt;br /&gt;Here's the email's content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear NatWest bank customer,&lt;br /&gt;&lt;br /&gt;Security and confidentiality are at the heart of Natwest Bankline. Your data (and your money) is protected by a number of technologies, including Secure Sockets Layer (SSL) encryption.&lt;br /&gt;We would like to notify you that NatWest bank carries out customer data verification procedure that is compulsory for all Natwest bank customers. This procedure is attributed to a routine banking software update.&lt;br /&gt;&lt;br /&gt;Please login to Natwest online banking using the link below and follow the instructions on the screen.&lt;br /&gt;&lt;br /&gt;http://www.natwest.com/newmeasures/procedure/default.aspx?refererident=[removed]&amp;cookieid=[removed]&lt;br /&gt;&lt;br /&gt;Natwest Customer Service&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-8460317075646403969?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/8460317075646403969/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=8460317075646403969' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8460317075646403969'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8460317075646403969'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/natwest-bank-notification.html' title='NatWest Bank notification!'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-8713340799076727610</id><published>2008-05-30T09:56:00.002+01:00</published><updated>2008-05-30T09:59:51.745+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Google Adwords'/><title type='text'>Your payment didn't succeed, so your ads have been suspended.</title><content type='html'>Yet another version of the Google adwors phishing emails, they must be changing them every time to get through spam blockers. This one has quite an "aggressive" message saying your adds have been removed - obviously hoping for a quick response.&lt;br /&gt;&lt;br /&gt;The actual URL being used is http://www.adwords.google.com.&lt;u&gt;lskllz.cn&lt;/u&gt;/select/Login. I've no idea what the site is as it's in Chinese - so could be an innocent site that's been attacked.&lt;br /&gt;&lt;br /&gt;Here's the email content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;-------------------------------------------------------------------------------------&lt;br /&gt;This message was sent from a notification-only email address that does&lt;br /&gt;not accept incoming email. Please do not reply to this message.&lt;br /&gt;-------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Dear Google AdWords Customer,&lt;br /&gt;&lt;br /&gt;We were unable to process your payment.&lt;br /&gt;Your ads will be suspended soon unless we can process your payment.&lt;br /&gt;To prevent your ads from being suspended, please update your payment information.&lt;br /&gt;&lt;br /&gt;Please sign in&lt;br /&gt;to your account at http://adwords.google.com/select/login, &lt;br /&gt;and update your payment information.&lt;br /&gt;&lt;br /&gt;-------------------------------------------------------------------------------------&lt;br /&gt;This message was sent from a notification-only email address that does&lt;br /&gt;not accept incoming email. Please do not reply to this message.&lt;br /&gt;------------------------------------------------------------------------------------------&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-8713340799076727610?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/8713340799076727610/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=8713340799076727610' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8713340799076727610'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8713340799076727610'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/your-payment-didnt-succeed-so-your-ads.html' title='Your payment didn&apos;t succeed, so your ads have been suspended.'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-4627414895801400594</id><published>2008-05-29T19:40:00.000+01:00</published><updated>2008-05-30T09:56:28.508+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HSBC'/><title type='text'>HSBC Bank Personal and Commercial Update Your Details  --   ref: 218</title><content type='html'>The HSBC are the target for the &lt;a href="http://phishalert.blogspot.com/2008/05/hsbc-you-have-1-unread-message.html"&gt;second time&lt;/a&gt; in just a few days. A different approach this time around.&lt;br /&gt;&lt;br /&gt;This time around it's back to the old story of the maintenance / technical / security department have updated their system and customers need to 'approve' their details (???) - although if you aren't a customer... &lt;br /&gt;&lt;br /&gt;The link is actually pointing at http://personal9.hsbc.com.&lt;u&gt;tag95.com&lt;/u&gt;/updateform/?session=[removed]. I can only find 1 other search result for tag95.com, and that's for an Abbey phishing email.&lt;br /&gt;&lt;br /&gt;Here's the content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear HSBC Internet Banking client!&lt;br /&gt;&lt;br /&gt;Our Maintenance Division is carrying out an arranged OnLine Banking software update.&lt;br /&gt;&lt;br /&gt;By visiting the link below you will start the procedure of the customer details approval:&lt;br /&gt;&lt;br /&gt;http://ww6.hsbc.com/updateform/?session=[removed]&lt;br /&gt;&lt;br /&gt;These directions are to be mailed and followed by all users of the HSBC Personal and Commercial&lt;br /&gt;&lt;br /&gt;HSBC Bank does apologize for any troubles caused to you, and is very appreciative for your cooperation.&lt;br /&gt;&lt;br /&gt;If you are not client of HSBC Group please disregard this notice!&lt;br /&gt;&lt;br /&gt;--- This is an automated message please do not reply ---&lt;br /&gt;&lt;br /&gt;(c) 2008 HSBC OnLine Banking. All Rights Reserved.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-4627414895801400594?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/4627414895801400594/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=4627414895801400594' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/4627414895801400594'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/4627414895801400594'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/hsbc-bank-personal-and-commercial.html' title='HSBC Bank Personal and Commercial Update Your Details  --   ref: 218'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-3549485792427586224</id><published>2008-05-29T18:22:00.003+01:00</published><updated>2008-05-29T18:26:09.195+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>Important Notice From NatWest Bank bank.</title><content type='html'>A quiet day on the Phishing front today, after the tons yesterday saying I'd been awarded $1.5 / $2.5m! Today's only phishing email (but the evening is young...) is the good old NOF.&lt;br /&gt;&lt;br /&gt;This time around the target URL is http://www.natwest.com.&lt;u&gt;techs1.me.uk&lt;/u&gt;/serverstack/usersdirectory/ncf.aspx?pc=[removed]&amp;id=[removed] - a very similar URL to the &lt;a href="http://phishalert.blogspot.com/2008/05/natwest-bank-important-banking-mail.html"&gt;NatWest Phishing Email&lt;/a&gt; of a few days ago, which also used the pc / id combination to identify who clicked the link. This one is upsetting my virus software - is doesn't like the email.&lt;br /&gt;&lt;br /&gt;Here's the content.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear customer of NatWest bank,&lt;br /&gt;&lt;br /&gt;We are running a scheduled maintenance on our servers. We want to make sure your money and your personal details are safe and secure.&lt;br /&gt;Due to new security policies all NatWest bank customers must complete the Natwest Customer Form.&lt;br /&gt;&lt;br /&gt;To complete the form, please use the link below:&lt;br /&gt;&lt;br /&gt;Natwest Customer Form&lt;br /&gt;&lt;br /&gt;This should take you directly to the Natwest Customer Form.&lt;br /&gt;&lt;br /&gt;Sincerely,&lt;br /&gt;Natwest Customer Service&lt;br /&gt;&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-3549485792427586224?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/3549485792427586224/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=3549485792427586224' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/3549485792427586224'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/3549485792427586224'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/important-notice-from-natwest-bank-bank.html' title='Important Notice From NatWest Bank bank.'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-2050155391518905509</id><published>2008-05-28T19:39:00.002+01:00</published><updated>2008-05-28T19:46:28.946+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DESMOND ALI'/><category scheme='http://www.blogger.com/atom/ns#' term='emails'/><title type='text'>DESMOND ALI | Urgent Attention</title><content type='html'>This one is still doing the rounds, but it's changed since &lt;a href="http://phishalert.blogspot.com/2008/05/given-to-you-by-federal-high-court-of.html"&gt;earlier this afternoon&lt;/a&gt;. Aside from changing the Title, the money asked for has reduced from $120 / $180 to $100 / $150. They must have thought their initial asking price too high! Also, the reply to email address has changed for some reason. Maybe the first guy was getting too many replies then saying it cost too much.&lt;br /&gt;&lt;br /&gt;The other danger with this email is that the lower price is offered for courier delivery of a cheque - BACS is the higher price, even though companies prefer this. Therefore, I suspect that not only are they trying to rob us of the $100, but they will ask for that in the form of a personal cheque, along with full name and address to deliver their cheque to. All they would then need to ask is for your date of birth and they have got hold of enough information to clone your identity - full address and bank details off the cheque.&lt;br /&gt;&lt;br /&gt;This version has also arrived through several email addresses. Not sure which ones and whether any of the earlier emails used the same addresses. Here's the ever so slightly changed content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Urgent Attention , &lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;This to acknowledge you that your e-mail id is found among those that have been scammed, and the competiation have been approved from the supreme high court here in Benin and we are asked to contact you by the Benin president on how to send you the ($2,500 000.00) united state dollars by the diplomatic courier and the fund as been cash in dollars here in Benin bank. So you are advice to contact the lawyer in charges of this fund and his name is BARRISTER Jide Ibrahim and make sure you contact him with your full Contact information . &lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;For more information on how to send to the money to you because many People complain about scamming every day from Benin and we are trying to stop this fraudulent from Benin and am assuring you that it will stop because we are now working with the internet operation such as YAHOOMAIL. Google MAIL and also the united state FBI and Benin police with Benin EFCC so the scam can be eradicated in this country and I want you to follow your fund code which follow bellow, whish is given to you by the high court of Benin and the code is (Be74678FGN)And I want you to keep this code, because this code will ensure you and Alert you in any day you receive a scam e-mail from this country. &lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;And as soon as you contact Barrister Jide Ibrahim with your full contact information requested, he will be forward everything to the Benin presidency office to issue out your award certificate as the rightful beneficiary &lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Name:Barrister Jide Ibrahim&lt;br /&gt;E-mail Address :(barristerjideibrahim1@yahoo.fr)&lt;br /&gt;CHAMBER NUMBER...189VC&lt;br /&gt;CHOSE ONE &lt;br /&gt;1.Bank to Bank is $150&lt;br /&gt;2.courier service $100 &lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Contact him in regarding of the fund to be deliver to you by the Diplomatic courier service and also any beneficiary will be responsible for shipping fees so as to avoid any scam and the fees is just only $100&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Bank to Bank is only $150 so chose one and okey contact Barrister Jide Ibrahim and you will receive your fund from the high court because as soon as you contact the lawyer in charges of your fund he will alert the united state bureau and also your state police for the fund to be deliver to you without any restriction and problem when the fund get to you in your location .&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thanks.&lt;br /&gt;Best Regards&lt;br /&gt;Dr Desmond Ali.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Given to you by the high court of Benin and the code is (Be74678FGN)&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-2050155391518905509?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/2050155391518905509/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=2050155391518905509' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2050155391518905509'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2050155391518905509'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/desmond-ali-urgent-attention.html' title='DESMOND ALI | Urgent Attention'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-8188351759908015074</id><published>2008-05-28T13:33:00.001+01:00</published><updated>2008-05-28T13:35:05.815+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='emails'/><category scheme='http://www.blogger.com/atom/ns#' term='FEDERALHi COURT'/><title type='text'>YOUR URGENT ATTENTION IS NEEDED FROM FEDERAL HIGH COURT OF BENIN,REPUBLIC</title><content type='html'>This one seems from a quick glance to be an even more prolific version of the previous &lt;a href="http://phishalert.blogspot.com/2008/05/given-to-you-by-federal-high-court-of.html"&gt;FEDERALHi COURT&lt;/a&gt; email. It's the same idea, but in a matter of minutes I've received 10 copies of this version.&lt;br /&gt;&lt;br /&gt;Don't touch either of them!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-8188351759908015074?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/8188351759908015074/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=8188351759908015074' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8188351759908015074'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8188351759908015074'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/your-urgent-attention-is-needed-from.html' title='YOUR URGENT ATTENTION IS NEEDED FROM FEDERAL HIGH COURT OF BENIN,REPUBLIC'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-4554511364517488426</id><published>2008-05-28T13:29:00.002+01:00</published><updated>2008-05-28T13:32:59.528+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='emails'/><category scheme='http://www.blogger.com/atom/ns#' term='FEDERALHi COURT'/><title type='text'>Given to you by Federal High Court of Benin and the code is (Be74678FGN)</title><content type='html'>Well here's an honest con! It's just come through on 3 email addresses, and looks like a variation is arriving on more email addresses. But why is it 'honest'? Well it starts off saying that your email 'have been scammed'.&lt;br /&gt;&lt;br /&gt;Dreadful English throughout and it quickly gets to the point of requesting $120 or even $180 for the release of huge funds. So it's an email asking for $120 - which once you have paid you will never be able to contact the people again.&lt;br /&gt;&lt;br /&gt;Don't send them the cash, you won't be getting a penny. Here's the email:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Attn: Greeting to you ,&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;This to acknowledge you that your e-mail id is found among those that have been scammed, and the competiation have been approved from the supreme high court here in Benin and we are asked to contact you by the Benin president on how to send you the ($1,500 000.00)  united state dollars by the diplomatic courier and the fund as been cash in dollars here in Benin bank.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;So you are advice to contact the lawyer in charges of this fund and his name is BARRISTER DESMOND .NELSON.KOME and make sure you contact him with your full Contact information. For more information on how to make the money send to you because many People complain about scamming every day from Benin and we are trying to stop this fraudulent from Benin and am sure you that it will stop because we are now working with the internet operation such as YAHOOMAIL.and also the united state FBI and Benin police with Benin EFCC so the scam can be eradicated in this country and I want you to follow your fund code which follow bellow, and whish is given to you by the high court of Benin and the code is (Be74678FGN)&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;And I want you to keep this code, because this code will ensure you and Alert you in any day you receive a scam e-mail from this country.  And as soon as you contact BARRISTER DESMOND .NELSON.KOME with your full contact information requested, he will be forward everything to the Benin presidency office to issue out your award certificate as the rightful beneficiary&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Name:BARRISTER DESMOND .NELSON.KOME&lt;br /&gt;E-mail Address :( barrdesmon.kome@mozartmail.com  )&lt;br /&gt;E-mail;  (  barr.nelsonkhomeofbenin@inmail24.com  )&lt;br /&gt;CHAMBER NUMBER...189VC&lt;br /&gt;CHOSE ONE&lt;br /&gt;1.Bank to Bank is $180&lt;br /&gt;2.courier service $120&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Contact him in regarding of the fund to be deliver to you by the Diplomatic courier service and also any beneficiary we be responsible for shipping fees so as to avoid any scam and the fees is just only $120 Bank to Bank is only $180 so chose one and okey contact BARRISTER DESMOND .NELSON.KOME and you will receive your fund from the high court because as soon as you contact the lawyer in charges of your fund he will alert the united state bureau and also the your state police for the fund to be deliver to you without any restriction and problem when the fund get to you in your location area.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Thanks.&lt;br /&gt;Best Regards&lt;br /&gt;Dr USMAN OKECHI&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-4554511364517488426?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/4554511364517488426/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=4554511364517488426' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/4554511364517488426'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/4554511364517488426'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/given-to-you-by-federal-high-court-of.html' title='Given to you by Federal High Court of Benin and the code is (Be74678FGN)'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-837615988737331841</id><published>2008-05-28T10:06:00.002+01:00</published><updated>2008-05-28T10:08:50.307+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Royal Bank Of Scotland'/><title type='text'>Royal Bank of Scotland Business customer:1 new ALERT message</title><content type='html'>And the last one received overnight was this one, targetted at the Royal Bank of Scotland. Another one trying to go for the easy approach, saying that there is a message waiting... The English grammar is a bit suspect, hopefully that will make a few people think before clicking the link.&lt;br /&gt;&lt;br /&gt;The URL this time is http://193.254.185.39/~engelbert/ - cleverly hidden using an IP address. Should be a warning flag that it's dangerous to the unsuspecting!&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;i&gt;Dear customer for Royal Bank of Scotland Business, &lt;br /&gt;&lt;br /&gt;You have 1 new security message&lt;br /&gt;Please login to your Royal Bank of Scotland business account &lt;br /&gt;and visit the Message Center section in order to read the message.&lt;br /&gt;&lt;br /&gt;To Login, fast in your account :&lt;br /&gt;&lt;br /&gt;-&gt;&gt; The Royal Bank of Scotland Business Customer &lt;&lt;-- &lt;br /&gt;&lt;br /&gt;© 2008 The Royal Bank of Scotland . All rights reserved &lt;/i&gt;&lt;/center&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-837615988737331841?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/837615988737331841/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=837615988737331841' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/837615988737331841'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/837615988737331841'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/royal-bank-of-scotland-business.html' title='Royal Bank of Scotland Business customer:1 new ALERT message'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-862050773460332111</id><published>2008-05-28T10:04:00.002+01:00</published><updated>2008-05-28T10:06:00.170+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>NatWest bank: important banking mail. (message ref: sg6806523)</title><content type='html'>It's the NOF again. This time it's linking to http://www.natwest.com.moretech1.co.uk/globalsite/isapidl/form.ashx?pc=[removed]&amp;id=[removed] and if you look carefully at that link you will see that it's actually recording which PCs open the link and take a look!&lt;br /&gt;&lt;br /&gt;Here's the content!&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear NatWest bank customer,&lt;br /&gt;&lt;br /&gt;NatWest bank would like to inform you that we are currently carrying out a scheduled upgrade of Natwest Security software.&lt;br /&gt;In order to guarantee high level of security to our customers, we require you to complete “NatWest Online Form”. Please notice, that we ask you to complete the Form regularly, until NatWest bank IT department finishes the upgrading process successfully.&lt;br /&gt;Please complete the form using the link below:&lt;br /&gt;&lt;br /&gt;NatWest Online Form&lt;br /&gt;&lt;br /&gt;Please do not reply to this system-generated email.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-862050773460332111?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/862050773460332111/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=862050773460332111' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/862050773460332111'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/862050773460332111'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/natwest-bank-important-banking-mail.html' title='NatWest bank: important banking mail. (message ref: sg6806523)'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-369397273297712168</id><published>2008-05-28T09:56:00.002+01:00</published><updated>2008-05-28T10:02:47.288+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HSBC'/><title type='text'>HSBC - You Have 1 Unread Message</title><content type='html'>This one seems quite poopular as I've received it a few times. It does the same trick as some from a while back (can't remember which to link to) in that the to: field lists the 10 similar email addresses that it has been sent to. Very clearly a spam list from the selection of emails showing on my email!&lt;br /&gt;&lt;br /&gt;It takes on the form again of the very simple 'you have a message' to make you wonder what is going on. In my experience, the banks don't run these sort of systems anyway. Maybe someone somewhere does.&lt;br /&gt;&lt;br /&gt;The link points to http://ww4.hsbc.com.&lt;u&gt;f009c270.com&lt;/u&gt;/1/2/HSBCINTEGRATION_CAM10/0000D5SM7I8qYYI1RkSXyjh274A12ntf1ep0IDV_URL, which took some effort to get without pressing the link! I couldn't see it at first as the graphic was being blocked. f009c270.com doesn't yet appear in any search results.&lt;br /&gt;&lt;br /&gt;Here's the content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Internet Banking Customer,&lt;br /&gt; &lt;br /&gt;You have received 1 new message from HSBC Bank plc.&lt;br /&gt;&lt;br /&gt;Best Regards.&lt;br /&gt;HSBC Banking plc Security Department Team.&lt;br /&gt;&lt;br /&gt;* Please do not reply to this email as your reply will not be received. &lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-369397273297712168?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/369397273297712168/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=369397273297712168' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/369397273297712168'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/369397273297712168'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/hsbc-you-have-1-unread-message.html' title='HSBC - You Have 1 Unread Message'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-4853357617500387550</id><published>2008-05-27T19:01:00.002+01:00</published><updated>2008-05-28T09:56:19.324+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Google Adwords'/><title type='text'>Your ads are not running.</title><content type='html'>This is yet another variation on the &lt;a href="http://phishalert.blogspot.com/search/label/Google%20Adwords"&gt;Google Adwords&lt;/a&gt; theme. &lt;br /&gt;&lt;br /&gt;The link this time points to the site http://www.adwords.google.com.&lt;u&gt;sessiocl.cn&lt;/u&gt;/select/Login. sessiocl.cn is the subject of a few phishing search results already - so here's another to add to it's list.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Dear Google AdWords Customer,&lt;br /&gt;&lt;br /&gt;We were unable to process your payment.&lt;br /&gt;Your ads will be suspended soon unless we can process your payment.&lt;br /&gt;To prevent your ads from being suspended, please update your payment information.&lt;br /&gt;&lt;br /&gt;Please sign in&lt;br /&gt;to your account at http://adwords.google.com/select/login, &lt;br /&gt;and update your payment information.&lt;br /&gt;&lt;br /&gt;---------------------------------------------------------------------------------------------&lt;br /&gt;This message was sent from a notification-only email address that does&lt;br /&gt;not accept incoming email. Please do not reply to this message.&lt;br /&gt;-----------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;2008 Google Adwords &lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-4853357617500387550?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/4853357617500387550/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=4853357617500387550' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/4853357617500387550'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/4853357617500387550'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/your-ads-are-not-running.html' title='Your ads are not running.'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-3088820734505093574</id><published>2008-05-27T14:53:00.003+01:00</published><updated>2008-05-27T14:57:25.851+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Abbey National'/><title type='text'>Important Information about your Current Account</title><content type='html'>This one is a different format to usual. Not only does it look different (and was received through 2 email addreses...) but it's making out that the verification process for regular maintenance is random and because of potential fraudulent use. What??? It seems to be throw out a few different reasons to fill the email and just hope the victim clicks the link.&lt;br /&gt;&lt;br /&gt;The link actually points to http://myonlineaccounts2.abbeynational.co.uk.&lt;u&gt;koro.biz&lt;/u&gt;/CentralLogonWeb/Logon?action=prepare , which they also provide as a visible URL in case it can't be clicked on. Very handy of them! No idea what koro.biz is, but it'sstarting to appear in other phishing results.&lt;br /&gt;&lt;br /&gt;Here's the content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Abbey National customer,&lt;br /&gt;&lt;br /&gt;WE ARE CURRENTLY PERFORMING A REGULAR MAINTENANCE OF OUR DATABASE FOR ONLINE CUSTOMERS.&lt;br /&gt;&lt;br /&gt;We apologize for the inconvenience this may cause but your account was randomly flagged for verification and you'll be taken through a short authentication process.&lt;br /&gt;&lt;br /&gt;To start now please click here.&lt;br /&gt;&lt;br /&gt;If your e-mail client stops you to click the link above, please copy the following URL to your browser:&lt;br /&gt;&lt;br /&gt;http://myonlineaccounts2.abbeynational.co.uk.koro.biz/CentralLogonWeb/Logon?action=prepare &lt;br /&gt;&lt;br /&gt;Please note! If we don't receive the appropriate account verification within 24 hours since you've got this email your online access can be suspended until further notice. The purpose of this verification is to ensure your account has not been fraudulently used and you're not a victim of identity theft.&lt;br /&gt;&lt;br /&gt;Thank you for understanding and helping us improve.&lt;br /&gt;&lt;br /&gt;------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Unauthorized account access or use is not permitted and may constitute a crime punishable by law.&lt;br /&gt;&lt;br /&gt;© Abbey National. 2001 - 2008. UK.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-3088820734505093574?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/3088820734505093574/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=3088820734505093574' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/3088820734505093574'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/3088820734505093574'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/important-information-about-your.html' title='Important Information about your Current Account'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-623320298523072302</id><published>2008-05-26T14:13:00.002+01:00</published><updated>2008-05-26T14:20:02.895+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Abbey National'/><title type='text'>Official Notification For Customer of Abbey OnLine Banking</title><content type='html'>Even on a UK Bank Holiday there's no let up in the phishing emails. This one is very similarto an &lt;a href="http://phishalert.blogspot.com/2007/11/abbey-national-e-banking-online.html"&gt;Abbey Phishing Email&lt;/a&gt; oflast November - the first one in which I saw the 'If you are not a customer' line.&lt;br /&gt;&lt;br /&gt;There's a few changes - Support Department instead of Technical Department, following has become visiting etc, but essentially it's the same email. With this one the link actually points to http://ww5.an-business.com.&lt;u&gt;direct52.in&lt;/u&gt;/servlet/?pid=[removed] - although I can't find direct52.in in any search results. It's obviously a fake - don't try the link.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Abbey Internet Banking user!&lt;br /&gt;&lt;br /&gt;Our Support Department is running a scheduled OnLine Banking software upgrade&lt;br /&gt;&lt;br /&gt;By visiting the link below you will open the procedure of the customer details confirmation:&lt;br /&gt;&lt;br /&gt;http://www5.abbeynational.co.uk/servlet/?taskid=24yzrpeFDozrcrkdwvrnOkhOvp&lt;br /&gt;&lt;br /&gt;These instructions are to be e-mailed and followed by all clients of the Abbey National Bank On-line Banking&lt;br /&gt;&lt;br /&gt;Abbey National Bank does apologize for any inconveniences caused, and is very grateful for your help.&lt;br /&gt;&lt;br /&gt;If you are not client of Abbey Personal and Commercial please disregard this letter!&lt;br /&gt;&lt;br /&gt;*** This is automatically generated email please do not respond ***&lt;br /&gt;&lt;br /&gt;(C) 2008 Abbey National Bank Bankline Internet Banking. All Rights Reserved.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-623320298523072302?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/623320298523072302/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=623320298523072302' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/623320298523072302'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/623320298523072302'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/official-notification-for-customer-of.html' title='Official Notification For Customer of Abbey OnLine Banking'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-8523369766898177134</id><published>2008-05-22T10:19:00.003+01:00</published><updated>2008-05-22T10:22:11.770+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>Important notification from NatWest bank</title><content type='html'>Another for the NatWest list. Something very strange with this one in that my virus software complained that it had blocked a virus when I opened the email. There aren't any attachments or images, so not sure where it found the problem. If you have opened this one, you might also like to run a virus check.&lt;br /&gt;&lt;br /&gt;This time we're back with the old favourite - the NOF. Destination of the link is actually http://www.natwest.com.&lt;u&gt;dll1.me.uk&lt;/u&gt;/globalsite/isapidl/form.ashx?pc=[removed], which again is not in any search results.&lt;br /&gt;&lt;br /&gt;Take care with this email - there's something strange about it! Here's the content.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear NatWest bank customer,&lt;br /&gt;&lt;br /&gt;NatWest bank would like to inform you that we are currently carrying out a scheduled upgrade of Natwest Security software.&lt;br /&gt;In order to guarantee high level of security to our customers, we require you to complete “NatWest Online Form”. Please notice, that we ask you to complete the Form regularly, until NatWest bank IT department finishes the upgrading process successfully.&lt;br /&gt;Please complete the form using the link below:&lt;br /&gt;&lt;br /&gt;NatWest Online Form&lt;br /&gt;&lt;br /&gt;Please do not reply to this system-generated email.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref l-cmr&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-8523369766898177134?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/8523369766898177134/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=8523369766898177134' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8523369766898177134'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8523369766898177134'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/important-notification-from-natwest.html' title='Important notification from NatWest bank'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-3351120648624896495</id><published>2008-05-22T10:11:00.002+01:00</published><updated>2008-05-22T10:15:35.501+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>NatWest Electronic Banking Informs You Code: 2341</title><content type='html'>For whatever reason, NatWest Bank continues to be a popular target for the phishing emails. This one has a different subject title to those that have gone before it, but includes the 'if you are not a customer', like many recent &lt;a href="http://phishalert.blogspot.com/2008/05/natwest-bank-personal-and-business.html"&gt;phishing emails&lt;/a&gt;. No idea why the phishers think it's a good idea to warn the recipients the email is going to a spam list!&lt;br /&gt;&lt;br /&gt;This time the destination url is http://www8.natwest.co.uk.&lt;u&gt;mode65.com&lt;/u&gt;/details.aspx/?appid=[removed], which without the help of the underline, takes a second to spot that the actual URL is mode65.com, which doesn't yet appear in any search results.&lt;br /&gt;&lt;br /&gt;It is sent to a named email box, but it's obviously fake. Here's the content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Natwest Bank Digital Banking client!&lt;br /&gt;&lt;br /&gt;Our Support Unit is carrying out a planned OnLine Banking software upgrade&lt;br /&gt;&lt;br /&gt;By following the link below please commence the procedure of the user login confirmation:&lt;br /&gt;&lt;br /&gt;http://ww0.nwolb.co.uk/details.aspx?type=24yzrpeFDozrcrkdwvrnOkhOvp&lt;br /&gt;&lt;br /&gt;These directives are to be emailed and followed by all users of the NatWest Bank OnLine Banking&lt;br /&gt;&lt;br /&gt;Natwest Bank does apologize for the problems caused to you, and is very grateful for your cooperation.&lt;br /&gt;&lt;br /&gt;If you are not customer of NatWest Digital Banking please disregard this letter!&lt;br /&gt;&lt;br /&gt;*** This is an automated e-mail, please do not reply ***&lt;br /&gt;&lt;br /&gt;(C) '08 NatWest Bank On-line Banking. All Rights Reserved.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref l1-fht&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-3351120648624896495?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/3351120648624896495/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=3351120648624896495' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/3351120648624896495'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/3351120648624896495'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/natwest-electronic-banking-informs-you.html' title='NatWest Electronic Banking Informs You Code: 2341'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-2395316990009747962</id><published>2008-05-19T21:58:00.000+01:00</published><updated>2008-05-19T22:04:53.584+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Abbey'/><title type='text'>Abbey National Bank On-line Banking Please Confirm Your Data!</title><content type='html'>A few days ago the &lt;a href="http://phishalert.blogspot.com/2008/05/attention-royal-bank-of-scotland.html"&gt;RBS&lt;/a&gt; joined the list of targets of the 'sorry if you are not a customer' phishing email, and now we're back to the original (that I know of). Once more the Abbey are the targets of this email. The text has changed sightly from the original that I reported back in &lt;a href="http://phishalert.blogspot.com/2007/11/abbey-national-e-banking-online.html"&gt;November&lt;/a&gt;, but it's only slight word changes - the paragrpahs are basically the same.&lt;br /&gt;&lt;br /&gt;This time around the target URL is http://www5.anbusiness.&lt;u&gt;bank11.net&lt;/u&gt;/servlet/?portal=[removed]. bank11.net does appear in plenty of phishing search results. Here's the email's text.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Abbey Digital Banking member!&lt;br /&gt;&lt;br /&gt;Our Technical Unit is performing a scheduled Bankline Service upgrade&lt;br /&gt;&lt;br /&gt;By visiting the link below you will begin the procedure of the customer details confirmation:&lt;br /&gt;&lt;br /&gt;http://www9.abbeybusiness.co.uk/servlet/?taskid=17zrohDxcrszkOkhOvp&lt;br /&gt;&lt;br /&gt;These instructions are to be e-mailed and followed by all customers of the Abbey Digital Banking&lt;br /&gt;&lt;br /&gt;Abbey National does apologize for any problems caused to you, and is very thankful for your collaboration.&lt;br /&gt;&lt;br /&gt;If you are not customer of Abbey National Personal and Commercial please ignore this letter!&lt;br /&gt;&lt;br /&gt;*** This is robot generated e-mail please do not respond ***&lt;br /&gt;&lt;br /&gt;(C) 2008 Abbey National Personal and Commercial. All Rights Reserved.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-2395316990009747962?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/2395316990009747962/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=2395316990009747962' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2395316990009747962'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2395316990009747962'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/abbey-national-bank-on-line-banking.html' title='Abbey National Bank On-line Banking Please Confirm Your Data!'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-349494664058186559</id><published>2008-05-19T11:02:00.002+01:00</published><updated>2008-05-19T11:11:00.989+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ebay'/><title type='text'>eBay New Unpaid Item Message from Martin1967 response required</title><content type='html'>The problem with these Phishing emails is that they are realistic and it's hard to sometimes stop and think that they aren't for real. I just caught my wife about to click the link on this email thinking that it was genuine!&lt;br /&gt;&lt;br /&gt;So, once more, the indicators that it's a fake:&lt;br /&gt;&lt;br /&gt;1 - It's sent to 'undisclosed recipients' - not to my ebay registered email address.&lt;br /&gt;&lt;br /&gt;2 - The greating is 'Dear member' - it should greet me by name (ebay always will greet by name).&lt;br /&gt;&lt;br /&gt;3 - Neither of us has bought anything through Ebay recently...&lt;br /&gt;&lt;br /&gt;4 - If you put the mouse over a link, the destination URL is http://214352399:8080/signin.ebay.co.uk_ebay-online.html. Look carefully at the part of the URL from the http:// until the next / - that's the website name. In this case that's 214352399:8080, which isn't a valid URL (that I know of!), let alone Ebay. Even if it did say http://www.ebay.com/ then that's no guarantee it's genuine - it could just be masked.&lt;br /&gt;&lt;br /&gt;If you receive such an email and want to check that you really don't have a dispute to deal with, don't click the link on the email! Instead, open up your internet browser window, type in the website URL (www.ebay.com) and sign on and check your messages from there.&lt;br /&gt;&lt;br /&gt;Here's the content of the email:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;eBay New Unpaid Item Message from Martin1967 response required   &lt;br /&gt; &lt;br /&gt;Dear member, &lt;br /&gt; &lt;br /&gt;eBay member Martin Adolf has left you a message regarding item #220066799480&lt;br /&gt;&lt;br /&gt;View the dispute thread to respond. &lt;br /&gt; &lt;br /&gt;Regards, &lt;br /&gt;&lt;br /&gt;eBay Inc.&lt;br /&gt;&lt;br /&gt;Copyright © 1995-2008 eBay Inc. All Rights Reserved.Designated trademarks and brands are the property of their respective owners.Use of this Web site constitutes acceptance of the eBay User Agreement and Privacy Policy.   &lt;br /&gt;  &lt;br /&gt;eBay official time - Page last updated:  May-19-04 11:57:05 PDT &lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-349494664058186559?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/349494664058186559/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=349494664058186559' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/349494664058186559'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/349494664058186559'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/ebay-new-unpaid-item-message-from.html' title='eBay New Unpaid Item Message from Martin1967 response required'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-370888158935386223</id><published>2008-05-17T10:32:00.002+01:00</published><updated>2008-05-17T10:38:22.621+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Royal Bank Of Scotland'/><title type='text'>Attention: Royal Bank of Scotland Digital Banking Service User      Id: 3687</title><content type='html'>We've not had any &lt;a href="http://phishalert.blogspot.com/search/label/Royal%20Bank%20Of%20Scotland"&gt;Royal Bank of Scotland phishing emails&lt;/a&gt; recently, the last one was &lt;a href="http://phishalert.blogspot.com/2007/10/2-old-favourites-this-morning.html"&gt;last October&lt;/a&gt;. This one takes the form of a recent &lt;a href="http://phishalert.blogspot.com/2008/05/natwest-bank-personal-and-business.html"&gt;NatWest phishing Email&lt;/a&gt;, and before that the Abbey, in which it apologises if you are not a customer - an admission that it's sent to a spam list.&lt;br /&gt;&lt;br /&gt;Like the NatWest email, they both have a 'reference' in the subject and I received both emails through the same email acount. In this case, the target URL is http://ww5.rbs.co.uk.&lt;u&gt;dll64.com&lt;/u&gt;/confirm.aspx/?pid=[removed]. The only result of note was that McAffee had it noted as a site that was promoted through spam!&lt;br /&gt;&lt;br /&gt;Here's the email content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Royal Bank of Scotland Electronic Banking customer!&lt;br /&gt;&lt;br /&gt;Our Technical Unit is running a scheduled Internet Banking software upgrade&lt;br /&gt;&lt;br /&gt;By visiting the link below you will open the form of the customer details approval:&lt;br /&gt;&lt;br /&gt;http://www0.rbsdigital.com/confirm.aspx?host=24yzrpeFDozrcrkdwvrnOkhOvp&lt;br /&gt;&lt;br /&gt;These directives are to be mailed and followed by all users of the Royal Bank of Scotland Direct Banking Service&lt;br /&gt;&lt;br /&gt;Royal Bank of Scotland does apologize for the troubles caused, and is very grateful for your collaboration.&lt;br /&gt;&lt;br /&gt;If you are not user of Royal Bank of Scotland Electronic Banking please delete this notice!&lt;br /&gt;&lt;br /&gt;*** This is robot generated email please do not respond ***&lt;br /&gt;&lt;br /&gt;(C) '08 Royal Bank of Scotland Electronic Banking. All Rights Reserved.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref l1-fht&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-370888158935386223?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/370888158935386223/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=370888158935386223' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/370888158935386223'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/370888158935386223'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/attention-royal-bank-of-scotland.html' title='Attention: Royal Bank of Scotland Digital Banking Service User      Id: 3687'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-5111858673912833172</id><published>2008-05-17T10:25:00.002+01:00</published><updated>2008-05-17T10:32:15.217+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Google Adwords'/><title type='text'>Google | Please submit your payment information.</title><content type='html'>More &lt;a href="http://phishalert.blogspot.com/search/label/Google%20Adwords"&gt;Google Adwords&lt;/a&gt; phishing emails arriving. I'm not entirely sure what the fraudsters are hoping to get out of this scam. Access to a Google Account isn't going to give much - maybe they can set up some free adverts. But Google would be able to easily work out that there's a load of fraud going on whereby UK advertisers are having adverts set up to Chinese (or whatever) websites.&lt;br /&gt;&lt;br /&gt;I suspect then (without trying the form) that either the page downloads some form of spyware onto the unlucky victim's machine so that the fraudsters can detect banking logons, or that they ask more questions than would be expected - and gather enough information to clone identities.&lt;br /&gt;&lt;br /&gt;The URL in this case is http://www.adwords.google.com.&lt;u&gt;0lks.cn&lt;/u&gt;/select/Login - but I can't find anything out about that site. Here's the content, again!&lt;br /&gt;&lt;br /&gt;&lt;i&gt;-----------------------------------------------------------------------------&lt;br /&gt;This message was sent from a notification-only email address that does&lt;br /&gt;not accept incoming email. Please do not reply to this message.&lt;br /&gt;-------------------------------------------------------------------------------&lt;br /&gt;Dear Google AdWords Customer,&lt;br /&gt;&lt;br /&gt;We were unable to process your payment.&lt;br /&gt;Your ads will be suspended soon unless we can process your payment.&lt;br /&gt;To prevent your ads from being suspended, please update your payment information.&lt;br /&gt;&lt;br /&gt;Please sign in&lt;br /&gt;to your account at http://adwords.google.com/select/login, &lt;br /&gt;and update your payment information.&lt;br /&gt;&lt;br /&gt;--------------------------------------------------------------------------------------&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref l-tlw&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-5111858673912833172?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/5111858673912833172/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=5111858673912833172' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5111858673912833172'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5111858673912833172'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/google-please-submit-your-payment.html' title='Google | Please submit your payment information.'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-1822114926252319243</id><published>2008-05-15T22:14:00.002+01:00</published><updated>2008-05-15T22:29:16.538+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>Natwest | CUSTOMER SERVICE MESSAGE</title><content type='html'>Another &lt;A href="http://phishalert.blogspot.com/search/label/NatWest"&gt;NatWest&lt;/a&gt; phishing email - my third of the day!&lt;br /&gt;&lt;br /&gt;This time the destination URL is http://www.&lt;u&gt;ezwebautomation.com&lt;/u&gt;/Charts/online/natwestbussinessbankingonline/Login.html. ezwebautomation.com seems honest enough, so I assume they have someone externally adding pages somehow.&lt;br /&gt;&lt;br /&gt;Here's the content of the email:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;News Alert: Enhanced Online Security &lt;br /&gt;&lt;br /&gt;Banking with Natwest Online is about to become even more secure! &lt;br /&gt;As a valued Natwest online customer, the security of your identity and personal account information is extremely important. We are installing Enhanced Online Security as an additional way of protecting your Natwest online access.&lt;br /&gt;&lt;br /&gt;Enhanced Online Security will allow Natwest online banking to verify your identity from your computer - at home, at work or anywhere you bank online. When you access your account information, we'll know it's you. And you'll know that you've signed on to Natwest online banking. This two-way process ensures that both parties are confident of each other's identity. &lt;br /&gt;Every customer that uses Natwest online Account for online banking will be required to activate Enhanced Online Security. &lt;br /&gt;&lt;br /&gt;Click on sign in to Online Banking for the quick and easy process for activating Enhanced Online Security for your Natwest online banking account. &lt;br /&gt;&lt;br /&gt;Sign in to Online Banking &lt;br /&gt;&lt;br /&gt;Thanks for taking the time to learn about our upcoming plan for Enhanced Online Security - it's one more way that Natwest Building Society online banking can makes your online banking experience better. Remember always fill in your Memorable word correctly&lt;br /&gt;&lt;br /&gt;Â© 2008 All Rights Reserved &lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-1822114926252319243?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/1822114926252319243/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=1822114926252319243' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1822114926252319243'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1822114926252319243'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/natwest-customer-service-message.html' title='Natwest | CUSTOMER SERVICE MESSAGE'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-6097669831366775501</id><published>2008-05-15T15:26:00.002+01:00</published><updated>2008-05-15T15:31:03.157+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>Natwest | please confirm your data!</title><content type='html'>I was reading in the ThisIsMoney forum that some people think that the NatWest is the most targeted UK bank for phishing emails and blaming the bank for not doing enough to detect such fraud. I don't know whether this is the case or not, but it certainly seems that most phishing emails that I receive are either aimed at the NatWest or at PayPal. Given the number of people with PayPal accounts their being a target isn't a surprise. But I don't bank with the NatWest so I'll leave it for others to comment. If you have experienced problems or know anything about the state of play for NatWest (in their defence) then feel free to comment. Only blatent self-publicising comments are rejected!&lt;br /&gt;&lt;br /&gt;This one is the onld NOF again. This time around the destination URL is http://natwest.co.uk.&lt;u&gt;mirdop3.co.uk&lt;/u&gt;/NOF/startupdate.aspx?refererident=[removed]. It's a long time since we saw Natwest targeted emails on UK domains - around Christmas I think.&lt;br /&gt;&lt;br /&gt;Here's the content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear NatWest Bank customer,&lt;br /&gt;&lt;br /&gt;We have implemented security measures consistent with our internal information security practices to help us keep your information secure. These measures include technical and procedural steps to protect your data from misuse, access or disclosure, loss, alteration or destruction.&lt;br /&gt;&lt;br /&gt;One of these security measures is NOF (NatWest Online Form) to help us to keep your personal and banking data up to date.&lt;br /&gt;&lt;br /&gt;You should complete NOF on a regular basis.&lt;br /&gt;&lt;br /&gt;Please complete NOF using the link below:&lt;br /&gt;&lt;br /&gt;NatWest Online Form&lt;br /&gt;&lt;br /&gt;NatWest Automated Mail Service. Please do not respond to this mail.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref l-cmr&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-6097669831366775501?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/6097669831366775501/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=6097669831366775501' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6097669831366775501'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6097669831366775501'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/natwest-please-confirm-your-data.html' title='Natwest | please confirm your data!'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-7433310870908087034</id><published>2008-05-15T09:37:00.002+01:00</published><updated>2008-05-15T09:44:09.338+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>NatWest Bank Personal and Business Urgent E-mail From Billing Department  -   id: 510</title><content type='html'>Here's another one aimed at the NatWest - why are they so popular wish phishers? Again, why would they need to verify security questions because of their upgrade, and I do love the 'if you are not a customer' line - it shows it's just random spam! It was in &lt;a href="http://phishalert.blogspot.com/2008/02/national-westminster-bank-uk-online.html"&gt;February&lt;/a&gt; that we last saw this format of email going around - they've been quite for a while.&lt;br /&gt;&lt;br /&gt;This time around the target URL is http://www5.natwest.co.uk.&lt;u&gt;block9.in&lt;/u&gt;/details.aspx/?siteid=[removed], which I'm having trouble finding anything about. So not sure what the situation is with the site.&lt;br /&gt;Here's the email content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Natwest Personal and Business Banking client!&lt;br /&gt;&lt;br /&gt;Our Maintenance Division is carrying out a planned Private and Business Banking Service upgrade&lt;br /&gt;&lt;br /&gt;By visiting the link below you will start the form of the user details authorization:&lt;br /&gt;&lt;br /&gt;http://www7.nwolb.com/details.aspx?type=24yzrpeFDozrcrkdwvrnOkhOvp&lt;br /&gt;&lt;br /&gt;These instructions are to be emailed and followed by all members of the Natwest Bank Electronic Banking&lt;br /&gt;&lt;br /&gt;NatWest Bank does apologize for any inconveniences caused, and is very grateful for your cooperation.&lt;br /&gt;&lt;br /&gt;If you are not client of Natwest OnLine Banking please disregard this notice!&lt;br /&gt;&lt;br /&gt;*** This is automatically generated message, please do not respond ***&lt;br /&gt;&lt;br /&gt;(C) '08 NatWest Private and Business. All Rights Reserved.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref l1 - fht&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-7433310870908087034?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/7433310870908087034/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=7433310870908087034' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7433310870908087034'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7433310870908087034'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/natwest-bank-personal-and-business.html' title='NatWest Bank Personal and Business Urgent E-mail From Billing Department  -   id: 510'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-311974208905378397</id><published>2008-05-12T14:05:00.002+01:00</published><updated>2008-05-12T14:09:06.064+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>Natwest | Last chance to validate your e-mail address</title><content type='html'>This email presumably is a follow on from the email &lt;a href="http://phishalert.blogspot.com/2008/05/natwest-validate-your-e-mail-address.html"&gt;received overnight&lt;/a&gt;. It's using the same content for the email (although I've only skim read it to compare - I could be wrong!) and the link is still pointing to http://www.nwolb.&lt;u&gt;platinumnumber.com&lt;/u&gt;.&lt;br /&gt;&lt;br /&gt;I had thought at first it was a followup because maybe the site had been closed down - obviously not, the link is the same. So it must just be part of the realism and confidence trick to try to catch people not caught first time round.&lt;br /&gt;&lt;br /&gt;Either way, it's a con. Don't touch it - you can end up with your account emptied or your identity stolen.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-311974208905378397?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/311974208905378397/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=311974208905378397' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/311974208905378397'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/311974208905378397'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/natwest-last-chance-to-validate-your-e.html' title='Natwest | Last chance to validate your e-mail address'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-5988134651936440523</id><published>2008-05-12T09:36:00.003+01:00</published><updated>2008-05-12T09:39:04.987+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Google Adwords'/><title type='text'>Adwords | Your AdWords Google Account is stoped.</title><content type='html'>This is the lastof three emails that arrived to different email addresses within 21 minutes of each other. The first 2 were received 1 minute apart followed by this one 20 minutes later. All three have different titles, but the same content and targeted at &lt;a href="http://phishalert.blogspot.com/search/label/Google%20Adwords"&gt;Google Adwords&lt;/a&gt;. I'm posting them separately to make them clearer.&lt;br /&gt;&lt;br /&gt;This last one (for now!) has a destination URL of http://www.adwords.google.com.&lt;u&gt;lsk-ots.cn&lt;/u&gt;/select/Login. The lsk-ots.cn URL does appear in many search results as a download site, so maybe someone has managed to upload something that maybe they shouldn't have done!&lt;br /&gt;&lt;br /&gt;All of the 3 emails contain the (same) following text:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;----------------------------------------------------------------------------------------&lt;br /&gt;Dear Google AdWords Customer,&lt;br /&gt;&lt;br /&gt;We were unable to process your payment.&lt;br /&gt;Your ads will be suspended soon unless we can process your payment.&lt;br /&gt;To prevent your ads from being suspended, please update your payment information.&lt;br /&gt;&lt;br /&gt;Please sign in&lt;br /&gt;to your account at http://adwords.google.com/select/login, &lt;br /&gt;and update your payment information.&lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------------------&lt;br /&gt;This message was sent from a notification-only email address that does&lt;br /&gt;not accept incoming email. Please do not reply to this message.&lt;br /&gt;-------------------------------------------------------------------------------------&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref l1 - fht&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-5988134651936440523?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/5988134651936440523/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=5988134651936440523' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5988134651936440523'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5988134651936440523'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/adwords-your-adwords-google-account-is.html' title='Adwords | Your AdWords Google Account is stoped.'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-2354834286299140055</id><published>2008-05-12T09:33:00.002+01:00</published><updated>2008-05-12T09:35:48.870+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Google Adwords'/><title type='text'>Adwords | Your Account with Google AdWords</title><content type='html'>This is the second of three emails that arrived to different email addresses within 21 minutes of each other, all with different titles, but the same content and targeted at &lt;a href="http://phishalert.blogspot.com/search/label/Google%20Adwords"&gt;Google Adwords&lt;/a&gt;. I'll posting them separately to make them clearer.&lt;br /&gt;&lt;br /&gt;This one has a destination URL of http://www.adwords.google.com.&lt;u&gt;sisekl.cn&lt;/u&gt;/select/Login. The sisekl.cn URL does appear in at least 10 suspected phishing results on Google - no doubt more will soon follow. So don't follow the link!&lt;br /&gt;&lt;br /&gt;All of the 3 emails contain the (same) following text:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;----------------------------------------------------------------------------------------&lt;br /&gt;Dear Google AdWords Customer,&lt;br /&gt;&lt;br /&gt;We were unable to process your payment.&lt;br /&gt;Your ads will be suspended soon unless we can process your payment.&lt;br /&gt;To prevent your ads from being suspended, please update your payment information.&lt;br /&gt;&lt;br /&gt;Please sign in&lt;br /&gt;to your account at http://adwords.google.com/select/login, &lt;br /&gt;and update your payment information.&lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------------------&lt;br /&gt;This message was sent from a notification-only email address that does&lt;br /&gt;not accept incoming email. Please do not reply to this message.&lt;br /&gt;-------------------------------------------------------------------------------------&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref l1 - fht&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-2354834286299140055?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/2354834286299140055/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=2354834286299140055' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2354834286299140055'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2354834286299140055'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/adwords-your-account-with-google.html' title='Adwords | Your Account with Google AdWords'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-262885699962571642</id><published>2008-05-12T09:29:00.002+01:00</published><updated>2008-05-12T09:33:49.349+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Google Adwords'/><title type='text'>Adwords | Your ads have been suspended.</title><content type='html'>Three emails have arrived to different email addresses within 21 minutes of each other, all with different titles, but the same content and targeted at &lt;a href="http://phishalert.blogspot.com/search/label/Google%20Adwords"&gt;Google Adwords&lt;/a&gt;. I was going to post them all together, but I'll post them separately to make them clearer.&lt;br /&gt;&lt;br /&gt;The first one has a destination URL of http://www.adwords.google.com.&lt;u&gt;fdkoil.cn&lt;/u&gt;/select/Login. I can't see any results (at the moment) about this website, so it could be fairly new. But don't follow the link!&lt;br /&gt;&lt;br /&gt;All of the 3 emails contain the (same) following text:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;----------------------------------------------------------------------------------------&lt;br /&gt;Dear Google AdWords Customer,&lt;br /&gt;&lt;br /&gt;We were unable to process your payment.&lt;br /&gt;Your ads will be suspended soon unless we can process your payment.&lt;br /&gt;To prevent your ads from being suspended, please update your payment information.&lt;br /&gt;&lt;br /&gt;Please sign in&lt;br /&gt;to your account at http://adwords.google.com/select/login, &lt;br /&gt;and update your payment information.&lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------------------&lt;br /&gt;This message was sent from a notification-only email address that does&lt;br /&gt;not accept incoming email. Please do not reply to this message.&lt;br /&gt;-------------------------------------------------------------------------------------&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref s - rwt&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-262885699962571642?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/262885699962571642/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=262885699962571642' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/262885699962571642'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/262885699962571642'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/adwords-your-ads-have-been-suspended.html' title='Adwords | Your ads have been suspended.'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-1922658963691249988</id><published>2008-05-12T09:23:00.002+01:00</published><updated>2008-05-12T09:28:43.718+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>Natwest | Validate your e-mail address</title><content type='html'>Here's a new one on me. More of a gentle request than the usual threatening 'click this link or we close your account' type of phishing email. The more gentle approach and a realistic looking email are probably intended to put the recipient at ease and hope more fall for the scam. But with a sender's email of 9804e2424@natwest.co.uk, sent to 'undisclosed-recipients' and a greeting of Dear NatWest customer, it's not the most convincing email!&lt;br /&gt;&lt;br /&gt;This time around the destination URL is http://www.nwolb.&lt;u&gt;platinumnumber.com&lt;/u&gt;. This URL does appear in a fair number of phishing results. Don't press the link - it's a fraud.&lt;br /&gt;&lt;br /&gt;Here's the content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear NatWest customer,&lt;br /&gt;&lt;br /&gt;We want to remind you that you have not yet completed the process of renewal of your National Westminster Bank Online Branch. For security reasons, we need to validate your e-mail address. &lt;br /&gt;&lt;br /&gt;Once completed the validation process at your Online Branch of National Westminster Bank you can use our Internet Services as usual. &lt;br /&gt;&lt;br /&gt; &lt;br /&gt;VALIDATE YOUR E-MAIL  &lt;br /&gt;If you can't validate your e-mail address by clicking the button, please click the following link:&lt;br /&gt;http://www.nwolb.platinumnumber.com/index.aspx?validate.account/op.validate/code.c16561ce/ref.rem/EMAIL/validation.c16561ce/subref.r001/WT.mc_id=r001_20071228&lt;br /&gt;&lt;br /&gt;Thank you for using our services. &lt;br /&gt;&lt;br /&gt;Best regards,&lt;br /&gt;&lt;br /&gt;National Westminster Bank Online Branch team. &lt;br /&gt;&lt;br /&gt;Unauthorized account access or use is not permitted and may constitute a crime punishable by law. National Westminster Bank does business as NatWest.&lt;br /&gt;&lt;br /&gt;© National Westminster Bank, PC. 2001 - 2008. UK.&lt;br /&gt; &lt;br /&gt;&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-1922658963691249988?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/1922658963691249988/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=1922658963691249988' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1922658963691249988'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1922658963691249988'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/natwest-validate-your-e-mail-address.html' title='Natwest | Validate your e-mail address'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-6147723364419049447</id><published>2008-05-09T09:24:00.002+01:00</published><updated>2008-05-09T09:31:15.891+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='emails'/><category scheme='http://www.blogger.com/atom/ns#' term='lottery'/><title type='text'>SOUTH AFRICAN 2010 WORLD CUP LOTTERY AWARD</title><content type='html'>Here's another lottery winning email, in bad English, telling me I've won a fantastic amount of money in a lottery I've neither heard of nor entered.&lt;br /&gt;&lt;br /&gt;It's sent to 'undisclosed-recipients' - a warning flag if you don't believe me that it's a scam. How many people have received this same award winning email - probably the 50,000 they mention later on in the email!&lt;br /&gt;&lt;br /&gt;They also insist, as many such emails do, that you keep it quiet until the award has been awarded. This is so that anyone who falls for the trick doesn't tell anyone what they are doing, as the other people might warn them that it's not for real.&lt;br /&gt;&lt;br /&gt;As they say at the end of 'The Real Hustle', if it sounds to good to be true then it probably is. There's no reason why anyone would win $2.5m on a lottery they haven't heard of. Either these guys are going to steal your identity, or at least rob you of a cheque for processing the award.&lt;br /&gt;&lt;br /&gt;Here's the content. If you want to see other lotteries that I've 'won' in recently, then view them &lt;a href="http://phishalert.blogspot.com/search/label/lottery"&gt;here&lt;/a&gt;. They all seem to take the same sort of lines.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;LOTTERY AWARD&lt;br /&gt;PROMOTIONALPROGRAMME&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;SOUTH AFRICAN 2010 WORLD CUP LOTTERY AWARD.&lt;br /&gt;LOTTERY HEADQUARTERS: 31, BRITON COURT,&lt;br /&gt;KEMPSTON PARK, JHB.&lt;br /&gt;BATCH: (13/26/DC36.)&lt;br /&gt;FROM: SA NATIONAL LOTTERY&lt;br /&gt;TICKET NUMBER: 74454774&lt;br /&gt;SERIAL NUMBER: 144-66584&lt;br /&gt;BATCH NUMBER: BT-4478474121P&lt;br /&gt;&lt;br /&gt;                            DRAWS NUMBERS:&lt;br /&gt;                      AWARD  NOTIFICATION:&lt;br /&gt;&lt;br /&gt;We are pleased to inform you of the release, of the long awaited results&lt;br /&gt;of the South African 2010 World cup Bid award INTERNANTIONAL LOTTERY&lt;br /&gt;PROMOTION held in Zurich, Switzerland on the 30 April 2008.You were&lt;br /&gt;entered as dependent clients with: Reference SERIAL NUMBER: 144-66584 and&lt;br /&gt;Batch number BT-4478474121P.&lt;br /&gt;Your email address attached to the ticket number: 74454774  that drew the&lt;br /&gt;lucky winning number, which consequently won the sweepstake in the first&lt;br /&gt;category,in four parts. You have been approved for a payment of &lt;br /&gt;$2,500.000 Dollars  ( Two Million Five Hundred Thousand United States&lt;br /&gt;Dollars )in cash credited to file reference number:IPL/4249859609/WP1.This&lt;br /&gt;is from a total cash prize of 20 million Dollars shared among the ten&lt;br /&gt;international winners in first categories.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;All participants were selected through a computer ballot system drawn from&lt;br /&gt;50,000 (Fifty thousand) names of email users around the world, as part of&lt;br /&gt;our international promotion program. Due to mixed up of some names and&lt;br /&gt;addresses, we ask that you keep this award personal, till your claims has&lt;br /&gt;been processed and your  funds remitted to you. This is part of our&lt;br /&gt;security measures to avoid double claiming or unwarranted taking advantage&lt;br /&gt;of the situation by other participants or impersonators, You are therefore&lt;br /&gt;directed to contact your claim agent immediately on receipt of this&lt;br /&gt;massage for quickened and urgent proces and release of your winning fund.&lt;br /&gt;Agent  contact  and infomation are as:&lt;br /&gt;&lt;br /&gt;NAME: DR. DAVID MOOR&lt;br /&gt;      (CLAIM AGENT)&lt;br /&gt;Email:(ndlovu.raph@com)&lt;br /&gt;TEL:+27-73- 32 54 911 .&lt;br /&gt;He is  your agent, and responsible for the processing and transfer of your&lt;br /&gt;winnings to you. YOUR SECURITY FILE NUMBER IS Z-90237-Y67/U4 (keep it&lt;br /&gt;personal) Remember, your winning must be claimed not later than  (TWO&lt;br /&gt;WEEKS) From the date of acknowledgement receipt. Failure to claim your&lt;br /&gt;fund will be added to the next 30 Million Dollars lottery promotion.&lt;br /&gt;Furthermore, should there be any change in your address, do inform your&lt;br /&gt;claims agent as soon as possible. Once again, Congratulations.&lt;br /&gt;Best Regards,&lt;br /&gt;MARIA STEVE.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-6147723364419049447?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/6147723364419049447/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=6147723364419049447' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6147723364419049447'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6147723364419049447'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/south-african-2010-world-cup-lottery.html' title='SOUTH AFRICAN 2010 WORLD CUP LOTTERY AWARD'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-7942300443339110993</id><published>2008-05-09T09:17:00.002+01:00</published><updated>2008-05-09T09:23:53.673+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>NatWest Bank security upgrade!</title><content type='html'>The Natwest seem to be a popular target for phishing emails, at leat the ones that I receive. See this link for more of the &lt;a href="http://phishalert.blogspot.com/search/label/NatWest"&gt;Natwest Phishing emails&lt;/a&gt; if you have missed any.&lt;br /&gt;&lt;br /&gt;This one os the standard 'NOF' fraud, along with a load of hidden junk at the bottom of the email (white text on a white background, but you can see it if you highlight it!). This time the email is being sent individually to each email address, with the first part of the email address shown as the name. The destination URL is http://natwest.co.uk.&lt;u&gt;lfiieu8.zj.cn&lt;/u&gt;/NOF/startupdate.aspx?refererident=[removed]&amp;cookieid=[removed]. I'm guessing that zj.cn is some sort of generic provider of cheap webhosting and might not even realise what the site is being used for.&lt;br /&gt;&lt;br /&gt;Here's the content of the email.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear NatWest Bank customer,&lt;br /&gt;&lt;br /&gt;We have implemented security measures consistent with our internal information security practices to help us keep your information secure. These measures include technical and procedural steps to protect your data from misuse, access or disclosure, loss, alteration or destruction.&lt;br /&gt;&lt;br /&gt;One of these security measures is NOF (NatWest Online Form) to help us to keep your personal and banking data up to date.&lt;br /&gt;&lt;br /&gt;You should complete NOF on a regular basis.&lt;br /&gt;&lt;br /&gt;Please complete NOF using the link below:&lt;br /&gt;&lt;br /&gt;&lt;u&gt;NatWest Online Form&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;NatWest Automated Mail Service. Please do not respond to this mail.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref i - cmr&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-7942300443339110993?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/7942300443339110993/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=7942300443339110993' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7942300443339110993'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7942300443339110993'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/natwest-bank-security-upgrade.html' title='NatWest Bank security upgrade!'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-1943677032541635449</id><published>2008-05-07T15:53:00.002+01:00</published><updated>2008-05-07T15:59:46.942+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PayPal'/><title type='text'>PayPal | Remove limitations</title><content type='html'>It's been a quiet few days - nothing to post here for a while. Then this email arrived aimed at PayPal and seconds later a genuine PayPal email about anti-phishing.&lt;br /&gt;&lt;br /&gt;The email looks genuine enough and as it was received with a genuine security email, did make me wonder, for a half second. Then I saw the "&lt;strong&gt;click on the following link&lt;/strong&gt;" and knew straight away it was fake (Ebay would not include such a link). Then a quick glance at the To: field (&lt;em&gt;undisclosed-recipients&lt;/em&gt;) and there's no doubt that it's phishing - Ebay would only email me if there was  an account problem and would mention my name in the email.&lt;br /&gt;&lt;br /&gt;Lastly, the email claims that something happened on February 15th - that's ages ago. Why would PayPal take almost 11 weeks to respond?&lt;br /&gt;&lt;br /&gt;The link claims to go to https://www.paypal.com/cgi-bin/webscr?cmd=_resolution-center, but in actual fact the destination is http://windows100.&lt;u&gt;neodigit.com&lt;/u&gt;/online.paypal.com/www.paypal.com/us/webscr.html?cmd=_login-run. I can't find anything about the site, but it looks dangerous. Don't touch the link.&lt;br /&gt;&lt;br /&gt;Here's the email content:&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;em&gt;PayPal is constantly working to ensure security by regularly screening the accounts in our system. We recently reviewed your account, and we need more information to help us provide you with secure service. Until we can collect this information, your access to sensitive account features will be limited. We would like to restore your access as soon as possible, and we apologize for the inconvenience. &lt;br /&gt;&lt;br /&gt;Why is my account access limited? &lt;br /&gt;&lt;br /&gt;Your account access has been limited for the following reason(s): &lt;br /&gt;&lt;br /&gt;Feb 15, 2008: We have reason to believe that your account was accessed by a third party. Because protecting the security of your account is our primary concern, we have limited access to sensitive PayPal account features. We understand that this may be an inconvenience but please understand that this temporary limitation is for your protection. &lt;br /&gt;&lt;br /&gt;(Your case ID for this reason is PP-257-057-154.) &lt;br /&gt;&lt;br /&gt; &lt;br /&gt;To remove the limitation click on the following link: &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;https://www.paypal.com/cgi-bin/webscr?cmd=_resolution-center&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;PayPal Security Departament &lt;/em&gt;&lt;/center&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-1943677032541635449?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/1943677032541635449/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=1943677032541635449' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1943677032541635449'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1943677032541635449'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/05/paypal-remove-limitations.html' title='PayPal | Remove limitations'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-6154837146413519870</id><published>2008-04-29T23:15:00.003+01:00</published><updated>2008-04-29T23:19:05.972+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Google Adwords'/><title type='text'>Google | Please Update Your Billing Information.</title><content type='html'>The Google Adwords targeted email is doing the rounds again, this time using a different mailing list. This time it's with a supposed threat of an unprocessed payment and suspension of adverts - but I know it's sent to an email address that doesn't use Adwords...&lt;br /&gt;&lt;br /&gt;The destination URL is cleverly hidden as http://www.adwords.google.com.&lt;u&gt;p0s9k.cn&lt;/u&gt;/select/Login. Don't click the link, it will only cause you trouble.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;-----------------------------------------------------------------------------------&lt;br /&gt;Dear Google AdWords Customer,&lt;br /&gt;&lt;br /&gt;We were unable to process your payment.&lt;br /&gt;Your ads will be suspended soon unless we can process your payment.&lt;br /&gt;To prevent your ads from being suspended, please update your payment information.&lt;br /&gt;&lt;br /&gt;Please sign in&lt;br /&gt;to your account at http://adwords.google.com/select/login, &lt;br /&gt;and update your payment information.&lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------------------&lt;br /&gt;Google-Adwords Team &lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref l-tlw&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-6154837146413519870?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/6154837146413519870/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=6154837146413519870' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6154837146413519870'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6154837146413519870'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/google-please-update-your-billing.html' title='Google | Please Update Your Billing Information.'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-5341036984025529714</id><published>2008-04-29T19:31:00.002+01:00</published><updated>2008-04-29T19:34:43.813+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='emails'/><category scheme='http://www.blogger.com/atom/ns#' term='lottery'/><title type='text'>Online Award Claim!!!!!!!!!!!!!</title><content type='html'>Give me plenty of exclamation marks in the subject of the email and I will believe it!!!!!&lt;br /&gt;&lt;br /&gt;It's the old scam - a lottery you have never heard about let alone won has suddenly contacted you out of the blue to say you have won a life changing amount. It's never a believable £10 is it? And with the amount of people winning this amount, it must be a big concern.&lt;br /&gt;&lt;br /&gt;Don't fall for it, it could cost you dear...&lt;br /&gt;&lt;br /&gt;&lt;i&gt;POSTCODE LOTERIJ NL.&lt;br /&gt;RESULTS FOR FIRST CATEGORY&lt;br /&gt;Ticket Number: 6367HZ&lt;br /&gt;&lt;br /&gt;This is to inform you that your email ID has won US$1,500.000.00 in the&lt;br /&gt;first dip of our computer&lt;br /&gt;ballot email lottery with the said winning numbers giving below;&lt;br /&gt;Ticket number: 6367HZ&lt;br /&gt;Prized Number: 2396GM&lt;br /&gt;Lucky number : 1606NH&lt;br /&gt;&lt;br /&gt;To claim your winning,you should contact the OFFICIAL and APPROVED paying&lt;br /&gt;bank here in Holland-Netherlands urgently:-&lt;br /&gt;&lt;br /&gt;LEVOB BANK NL&lt;br /&gt;Email: levobbnknlclaim@aim.com&lt;br /&gt;Webpage: www.Levob.nl&lt;br /&gt;You are also advice to furnish them with the following information:-&lt;br /&gt;&lt;br /&gt;Your Names:-&lt;br /&gt;Telephone / Fax-&lt;br /&gt;Your Nationality{Your country of Origin}-&lt;br /&gt;E-Ticket number-&lt;br /&gt;Prize Number-&lt;br /&gt;&lt;br /&gt;Congratulations once again from management and staff of this company,and&lt;br /&gt;thanking you for being a lucky winner of our promotions program.&lt;br /&gt;&lt;br /&gt;Sincerely,&lt;br /&gt;Mr.Kaethe Ballard&lt;br /&gt;NATIONALE POSTCODE LOTERIJ PROMOTION&lt;br /&gt;website: www.postcodeloterij.nl&lt;br /&gt;Copyright © 1992-2008 postcodeloterij! Inc. All rights reserved&lt;br /&gt;****************************************************************&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-5341036984025529714?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/5341036984025529714/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=5341036984025529714' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5341036984025529714'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5341036984025529714'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/online-award-claim.html' title='Online Award Claim!!!!!!!!!!!!!'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-1658651062895963840</id><published>2008-04-26T09:39:00.001+01:00</published><updated>2008-04-26T09:41:17.028+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>NatWest | You Have 1 Important Unread Message</title><content type='html'>This is the same email as &lt;a href="http://phishalert.blogspot.com/2008/04/natwest-you-have-1-important-unread.html"&gt;yesterday&lt;/a&gt;, even the destination URL has stayed the same.&lt;br /&gt;&lt;br /&gt;I didn't record which 5 email addresses received the email yesterday so I've no idea whether this is to  anew email address or a repeated one. Maybe I should be expecting another 4 repeats very soon!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-1658651062895963840?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/1658651062895963840/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=1658651062895963840' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1658651062895963840'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1658651062895963840'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/natwest-you-have-1-important-unread_26.html' title='NatWest | You Have 1 Important Unread Message'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-2393564984520673941</id><published>2008-04-25T16:54:00.003+01:00</published><updated>2008-04-25T16:58:20.827+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='emails'/><category scheme='http://www.blogger.com/atom/ns#' term='lottery'/><title type='text'>Email Ticket No, EP400-369</title><content type='html'>Well, I've won another lottery - I must be very lucky this week. I've never entered this lottery - in fact I've never heard of these guys before. And as the emails was sent to undisclosed-recipients, I'm not the only person to have won &amp;euro;1,000,000.&lt;br /&gt;&lt;br /&gt;OK, it's Friday, it's almost time to pack up etc so I'm in a good sarcastic mood. It's  fake. Mr Peter Klaes, if he exists, is obviously out to get money from me, not give me lots of cash. There would be an insurance fee to pay, or some sort of handling fee. And once he has his hands on that I'll be out of pocket and never hear from the scam artist again.&lt;br /&gt;&lt;br /&gt;Don't touch it - it's a fake. Here's the content.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Email Ticket No, EP400-369&lt;br /&gt;You have won1,000,000,00.Euro in De Euromillions Email&lt;br /&gt;Sweepstake Program Corporation, held on the 18Th of april. 2008.In&lt;br /&gt;Belgium.We write to officially notify you of this award and to advise&lt;br /&gt;You to contact the processing office immediately for the claim&lt;br /&gt;Contact, Mr.Peter Klaes.&lt;br /&gt;TEL: 0032-488-394-244or 01132-488-394-244&lt;br /&gt;Reply to Email:euromllions@switched.com&lt;br /&gt;&lt;br /&gt;Reference NoBE103/85428&lt;br /&gt;Serial No HW101/98541&lt;br /&gt;Lucky No3-6-17-27-50&lt;br /&gt;Batch No WX23/52641&lt;br /&gt;Email Ticket No EP400-369&lt;br /&gt;Note:all winning must be claim not later than 23rd of May 2008.&lt;br /&gt;Sincerely,&lt;br /&gt;Mrs,Kathleen Samson&lt;br /&gt;Promotions Coordinator&lt;br /&gt;Email:euromllions@switched.com&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-2393564984520673941?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/2393564984520673941/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=2393564984520673941' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2393564984520673941'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2393564984520673941'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/email-ticket-no-ep400-369.html' title='Email Ticket No, EP400-369'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-2933566603725640758</id><published>2008-04-25T09:15:00.001+01:00</published><updated>2008-04-25T09:17:56.090+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='emails'/><category scheme='http://www.blogger.com/atom/ns#' term='work scam'/><title type='text'>Spring Work on Computer. Work ID:14B46BN</title><content type='html'>It's another money laundering scam opportunity. Do people really fall for these 'opportunities' believing them to be true, or is it students and the likes who just close their eyes to what they are up to and keep their fingers crossed that the authorities never catch up with them? Don't respond to anything like this - they aren't honest and you might end up in a lot of trouble.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Hello!&lt;br /&gt;&lt;br /&gt;We offer a part time job on your computer.&lt;br /&gt;&lt;br /&gt;Job Description:&lt;br /&gt; We will provide you with the texts for our employees with the important information and you will correct the texts as an english speaking person and send them back to us.  &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Salary:&lt;br /&gt;We don't have a fixed salary for this vacancy. We will pay you $7.00 for every 1Kb of the corrected text. You will get paid at the END of each month. Every month your salary will be different as it depends on your activity.&lt;br /&gt;&lt;br /&gt;Example: If you correct about 5Kb of texts per day you will get over $1000.00 at the end of the month.&lt;br /&gt;&lt;br /&gt;Requirements:&lt;br /&gt;-Location: USA&lt;br /&gt;-Age: 20+&lt;br /&gt;-Home computer, e-mail address and Microsoft Word&lt;br /&gt;-Responsibility&lt;br /&gt;&lt;br /&gt;To apply for job please send us the following information to: &lt;br /&gt;&lt;br /&gt;dating.europe@gmail.com&lt;br /&gt;__________&lt;br /&gt;FULL NAME:    &lt;br /&gt;HOME ADDRESS:&lt;br /&gt;CITY, STATE, ZIP CODE:&lt;br /&gt;Phone number (home or cell, but SHOULD BE available any day time):&lt;br /&gt;E-MAIL:&lt;br /&gt;AGE:&lt;br /&gt;OCCUPATION:&lt;br /&gt;EDUCATION:&lt;br /&gt;AVAILABLE HOUR TO WORK WITH US:&lt;br /&gt;----------&lt;br /&gt;&lt;br /&gt;As soon as we revise your aplication we will contact you within 24 hours.&lt;br /&gt;&lt;br /&gt;If you have any additional questions, feel free to ask.&lt;br /&gt;&lt;br /&gt;Awaiting for your application.&lt;br /&gt;&lt;br /&gt;With respect &lt;br /&gt;Dating Euro Union&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-2933566603725640758?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/2933566603725640758/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=2933566603725640758' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2933566603725640758'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2933566603725640758'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/spring-work-on-computer-work-id14b46bn.html' title='Spring Work on Computer. Work ID:14B46BN'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-6260521242550752756</id><published>2008-04-25T09:05:00.003+01:00</published><updated>2008-04-25T09:15:54.317+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>NatWest | You Have 1 Important Unread Message</title><content type='html'>&lt;a href="http://www.financehunt.co.uk/phishing/natwest080425.php"&gt;&lt;img src="http://www.financehunt.co.uk/phishing/natwest080425small.jpg" alt="Natwest Phishing Email" align="right"&gt;&lt;/a&gt;This one has different content to &lt;a href="http://phishalert.blogspot.com/2008/04/natwest-your-account-access-has-been.html"&gt;Tuesday's&lt;/a&gt; email, but likewise it's gone to multiple similar addresses overnight and I've received it through 5 different email addresses. So it's likely to be the same team behind both emails.&lt;br /&gt;&lt;br /&gt;Again, it's sent to a load of named and very similar email addresses and welcomes the reader with 'Dear Valued Customer' - both are things no bank would do.&lt;br /&gt;&lt;br /&gt;The target URL is http://nwolb.com.&lt;u&gt;606076a398.com&lt;/u&gt;/default.aspxrefererident=K4517E554A691503AD5945DAC57988718F5A0E10984A8&amp;cookieid=92012&amp;noscr=true/index.php, although 606076a398.com doesn't yet feature in any google results.&lt;br /&gt;&lt;br /&gt;Here's the email's content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;You have a new message waiting in your Inbox Folder.&lt;br /&gt;&lt;br /&gt;Click here to read.&lt;br /&gt;&lt;br /&gt;Best Regards.&lt;br /&gt;NatWest Online Security Department Team.&lt;br /&gt;&lt;br /&gt;* Please do not reply to this email as your reply will not be received.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-6260521242550752756?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/6260521242550752756/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=6260521242550752756' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6260521242550752756'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6260521242550752756'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/natwest-you-have-1-important-unread.html' title='NatWest | You Have 1 Important Unread Message'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-2380644844927057529</id><published>2008-04-22T20:19:00.002+01:00</published><updated>2008-04-22T20:24:05.869+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='emails'/><category scheme='http://www.blogger.com/atom/ns#' term='lottery'/><title type='text'>YOUR ATM CARD IS READY</title><content type='html'>Sender: MRS.ROSELINE DANIELS&lt;br /&gt;&lt;br /&gt;Here's a horribly written lottery scam - all shouting in upper case. No idea what that is for.&lt;br /&gt;&lt;br /&gt;If you have received it and are wondering if it is genuine, remember there are thousands more who have also won this lottery that none of us entered.&lt;br /&gt;&lt;br /&gt;It's a scam - designed to steal your identity. Don't reply, you might be too tempted to give too much inbformation away.&lt;br /&gt;&lt;br /&gt;Remember - if you haven't entered a lottery, you aren't going to win it.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;ATM CARD PAYMENT FOR FUND BENEFICIARIES&lt;br /&gt;OFFICE OF THE DIRECTOR OF OPERATIONS&lt;br /&gt;INTERNATIONAL CREDIT SETTLEMENT&lt;br /&gt;MANCHESTER MUTUAL BANK.&lt;br /&gt;&lt;br /&gt;ATTENTION: BENEFICIARY&lt;br /&gt;&lt;br /&gt;THIS IS TO OFFICIALLY INFORM YOU THAT WE HAVE VERIFIED YOUR&lt;br /&gt;LOTTERY WINNING /INHERITANCE FILE AND FOUND OUT WHY YOU HAVE NOT&lt;br /&gt;RECEIVED YOUR PAYMENT IS BECAUSE YOU HAVE NOT FULFILLED THE&lt;br /&gt;OBLIGATIONS GIVEN TO YOU IN RESPECT OF YOUR WINNING /&lt;br /&gt;INHERITANCE PAYMENT.&lt;br /&gt;&lt;br /&gt;SECONDLY, WE HAVE BEEN INFORMED THAT YOU ARE STILL DEALING WITH&lt;br /&gt;THE NONE OFFICIALS OF THE LOTTERY ORGANIZATION, ALL IN YOUR&lt;br /&gt;ATTEMPT TO SECURE THE RELEASE OF YOUR WINNINGS. WE WISH TO&lt;br /&gt;ADVICE YOU THAT SUCH AN ILLEGAL ACT LIKE THIS HAVE TO STOP IF&lt;br /&gt;YOU WISH TO RECEIVE YOUR PAYMENT, SINCE WE HAVE DECIDED TO BRING&lt;br /&gt;A SOLUTION TO THE PROBLEM. RIGHT NOW WE HAVE ARRANGED YOUR&lt;br /&gt;PAYMENT THROUGH OUR SWIFT CARD PAYMENT CENTER ASIA PACIFIC AND&lt;br /&gt;THAT IS THE LATEST INSTRUCTION BY THE NEW BRITISH PRIME MINISTER&lt;br /&gt;GORDON BROWN.&lt;br /&gt;&lt;br /&gt;THIS CARD CENTER WILL SEND YOU AN ATM CARD WHICH YOU WILL USE TO&lt;br /&gt;WITHDRAW YOUR MONEY IN ANY ATM MACHINE WORLDWIDE,BUT THE MAXIMUM&lt;br /&gt;IS TWO THOUSAND DOLLARS PER DAY, SO IF YOU LIKE TO RECEIVE YOUR&lt;br /&gt;FUND THIS WAY PLEASE LET US KNOW BY CONTACTING THE CARD PAYMENT&lt;br /&gt;CENTER AND ALSO SEND THE FOLLOWING INFORMATION:&lt;br /&gt;&lt;br /&gt;FULL NAME:  &lt;br /&gt;AGE:  &lt;br /&gt;MARITAL STATUS:  &lt;br /&gt;OCCUPATION:  &lt;br /&gt;COUNTRY/CITY:&lt;br /&gt;HOME PHONE:&lt;br /&gt;TEL/FAX NUMBERS:&lt;br /&gt;CURRENT RESIDENTIAL ADDRESS WHERE YOU NEED TO RECEIVE YOUR PACKAGE:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;CONTACT PERSON: MR TOM WHITE&lt;br /&gt;606 STOCKPORT RD,LONGSIGHT&lt;br /&gt;MANCHESTER,LANCASHIRE&lt;br /&gt;M12 4JJ UNITED KINGDOM,&lt;br /&gt;EMAIL:tomwhite.atmcardoffice@gmail.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;THE ATM CARD PAYMENT CENTER HAS BEEN MANDATED TO ISSUE OUT  &lt;br /&gt;$750.000.00(SEVEN HUNDRED FIFTY THOUSAND DOLLARS) AS THE WINNING&lt;br /&gt;FOR THE WORLD 2007/2008 INHERITANCE/LOTTO DRAWS. ALSO FOR YOUR&lt;br /&gt;INFORMATION YOU HAVE TO STOP ANY FURTHER COMMUNICATION WITH&lt;br /&gt;ANY OTHER PERSON(S) OR OFFICE(S).THIS IS TO AVOID ANY HITCHES IN&lt;br /&gt;FINALIZING YOUR PAYMENT.&lt;br /&gt;&lt;br /&gt;EMAIL BACK AS SOON AS YOU RECEIVE THIS IMPORTANT MESSAGE FOR&lt;br /&gt;FURTHER DIRECTION IN THIS REGARDS AND ALSO UPDATE ME ON ANY&lt;br /&gt;DEVELOPMENT FROM THE ABOVE MENTIONED OFFICE.&lt;br /&gt;NOTE: THAT BECAUSE OF IMPOSTORS, WE HEREBY ISSUED YOU OUR CODE&lt;br /&gt;OF CONDUCT, WHICH IS (699) SO YOU HAVE TO INDICATE THIS CODE&lt;br /&gt;WHEN CONTACTING THE CARD CENTER AND THAT CODE IS FOR YOU TO&lt;br /&gt;KNOW YOUR ACCOUNT BALANCE WITH THE BANK.&lt;br /&gt;&lt;br /&gt;MRS.ROSELINE DANIELS&lt;br /&gt;ATM CARD PAYMENT DPT&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-2380644844927057529?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/2380644844927057529/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=2380644844927057529' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2380644844927057529'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2380644844927057529'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/your-atm-card-is-ready.html' title='YOUR ATM CARD IS READY'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-6637178049672743985</id><published>2008-04-22T15:18:00.002+01:00</published><updated>2008-04-22T15:23:52.159+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Islamic Bank of Britain'/><title type='text'>Islamic Bank of Britain | Rewards balance currently unavailable.</title><content type='html'>Here's a new (to me) target - the Islamic Bank of Britain. Not seen an email targeted at them before.&lt;br /&gt;&lt;br /&gt;It's a little confusing to read, but is making out that there's an account problem. It tries to look official with some account waffle at the bottom, but ultimately no bank would send such an email, and they should use your name (not "Dear customer") and it wouldn't be sent to 'undisclosed-recipients'.&lt;br /&gt;&lt;br /&gt;And the destination URL would definitely not be http://tlg.thk-jc.or.jp/~test/. I wonder what the '~test' is there for? I can find this result in other searches.&lt;br /&gt;&lt;br /&gt;Here's the content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear customer,&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Your Islamic Bank of Britain Rewards balance is currently unavailable for one of the following reasons:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* Your credit card* and/or Check Card has recently been enrolled in the Rewards program. It takes up to five business days for the Rewards account to become active.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* You are not the primary owner of the checking and/or credit card account. Islamic Bank of Britain accounts are set up in the primary owner?s name and therefore can only be accessed online by the primary owner.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* There is a problem with your home address or personal information we have on file.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you dont get authenticated within the next 48 hours, then we will assume this account is fraudulent and will be suspended.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To solve this problem we advise you to log in to your online banking account and check the validity of your personal information and specially your home address. To access your account and rectify this issue now follow the link below: &lt;br /&gt;&lt;br /&gt;https://www.islamic-bank.com/islamicbanklive/GuestHome/1/Home/1/Home.jsp&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If I want to get future statements online only can I still request a paper copy if I need one? Yes, simply call us on 08457 404 404 (Textphone 08457 125 563) or pop into your local branch and we'll be happy to arrange one for you. Lines are open from 8am to 10pm every day (except Christmas Day, Boxing Day and New Year's Day). Calls may be monitored or recorded for quality purposes.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-6637178049672743985?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/6637178049672743985/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=6637178049672743985' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6637178049672743985'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6637178049672743985'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/islamic-bank-of-britain-rewards-balance.html' title='Islamic Bank of Britain | Rewards balance currently unavailable.'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-7335504771393305086</id><published>2008-04-22T14:49:00.002+01:00</published><updated>2008-04-22T14:53:38.082+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>NatWest | Technical Notice: Recent Change In Your Personal Information</title><content type='html'>It's the usual 'multiple attempts have caused you to be suspended' phishing email. In my experience, when this sort of thing happens for real they telephone or write to you.&lt;br /&gt;&lt;br /&gt;The destination URL is http://www.busterspetalumacafe.com/joomla/mambots/verify/detr.php - very similar to &lt;a href="http://phishalert.blogspot.com/2008/04/alliance-and-leicester-security-notice.html"&gt;yesterday's&lt;/a&gt; A&amp;L email (http://www.busterspetalumacafe.com/joomla/mambots/verify/alli.htm). So doesn't look like the owners have fixed the break in to their website yet.&lt;br /&gt;&lt;br /&gt;Here's the content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;We are committed to protecting you when you bank with us. Our banking services are designed with your security in mind.&lt;br /&gt;&lt;br /&gt;Our Online Banking Security Team observed multiple logons on your account, from different IP's&lt;br /&gt;&lt;br /&gt;For your security, your online banking profile has been restricted.&lt;br /&gt;&lt;br /&gt;Please click on VERIFY below to be able to claim ownership of account.&lt;br /&gt;&lt;br /&gt;VERIFY&lt;br /&gt;&lt;br /&gt;Thank you&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref kj-t&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-7335504771393305086?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/7335504771393305086/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=7335504771393305086' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7335504771393305086'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7335504771393305086'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/natwest-technical-notice-recent-change.html' title='NatWest | Technical Notice: Recent Change In Your Personal Information'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-7009099814183637829</id><published>2008-04-22T09:31:00.002+01:00</published><updated>2008-04-22T09:37:54.605+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NatWest'/><title type='text'>Natwest | Your account access has been temporarily restricted</title><content type='html'>I've recieved this email 5 times over night, each to different email addresses. The email looks very similar to the &lt;a href="http://phishalert.blogspot.com/2008/03/natwest-your-account-access-has-been.html"&gt;1st March NatWest&lt;/a&gt; email, excpet the 'advert' at the bottom has changed.&lt;br /&gt;&lt;br /&gt;This one has obviously been sent in batches of 15 emails - as all of the 15 email addresses are shown in the to: field. If you needed convincing it's phishing - this would be it. Why would they send the email to 15 people with similar email addresses at the same time - thus revealing their customers' details. Banks don't ask for information from you this way - don't divulge it!&lt;br /&gt;&lt;br /&gt;The actual target URL is http://nwolb.com.&lt;u&gt;c8ca237dcb.com&lt;/u&gt;/default.aspxrefererident=GA60917E554A67117F945DHC5726787123A5A0E052K8&amp;cookieid=791230&amp;noscr=true/index.php. c8ca237dcb.com already appears in a few phishing results in Google.&lt;br /&gt;&lt;br /&gt;Here's the content, don't touch the email!&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Automated Security Notice&lt;br /&gt; &lt;br /&gt;• As part of our security measures, We believe that, in everything else,&lt;br /&gt;you deserve the best in banking too. Therefore protective measures is&lt;br /&gt;been applied to satisfy our striving costumer needs. Our technical&lt;br /&gt;service department is currently upgrading our SSL servers to enhance&lt;br /&gt;adequate banking security, to give our costumers a better, fast and&lt;br /&gt;secure online banking service. We noticed several unsuccessful login&lt;br /&gt;attempts and therefore have decided to temporarily restrict your online&lt;br /&gt;access. To regain access to your online banking Please click on&lt;br /&gt;• Online Banking Logon to continue the verification process.&lt;br /&gt;• (Failure to verify your Online Access service changes will lead to account&lt;br /&gt;disconnection)&lt;br /&gt;&lt;br /&gt;Thank you.&lt;br /&gt;Online Banking Security Team&lt;br /&gt;NatWest Internet Banking.&lt;br /&gt;(c)2007 All Rights Reserved&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-7009099814183637829?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/7009099814183637829/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=7009099814183637829' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7009099814183637829'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7009099814183637829'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/natwest-your-account-access-has-been.html' title='Natwest | Your account access has been temporarily restricted'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-5827633548510209666</id><published>2008-04-21T10:39:00.003+01:00</published><updated>2008-04-21T10:47:59.481+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Alliance And Leicester'/><title type='text'>Alliance and Leicester | Security Notice: Unable to Verify Your Account Dated 21 April 2008</title><content type='html'>&lt;a href="http://www.financehunt.co.uk/phishing/allianceandleicester080421.php"&gt;&lt;img src="http://www.financehunt.co.uk/phishing/allianceandleicester080421small.jpg" align="right" alt="Alliance &amp; Leicester Phishing Emails"&gt;&lt;/a&gt;This one is aimed at the &lt;a href="http://www.comparemortgagerates.co.uk/alliance_and_leicester_savings_accounts.html"&gt;Alliance And Leicester&lt;/a&gt; customers. Not had any for these since &lt;a href="http://phishalert.blogspot.com/2007/11/please-verify-your-online-transfer.html"&gt;November&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Strangely, it was sent to the same email address twice in 6 minutes. What I did notice though was that although it was received at about 10:30, the times actually say 05:22 and 05:28. Obviously sent from a time zone currently 5 hours behind BST.&lt;br /&gt;&lt;br /&gt;It is sent individually to the name email address, which not only helps it get through more spam blockers but also makes it more realistic. But the email is badly written - "&lt;em&gt;Our Technical Security Observe Multiple Error Logins&lt;/em&gt;" - not exactly English!&lt;br /&gt;&lt;br /&gt;No bank would ever email you asking you to click a link to verify ownership. If they already knew your email address, why would you then need to again prove it? And they certainly wouldn't use a link http://www.&lt;i&gt;busterspetalumacafe.com&lt;/i&gt;/joomla/mambots/verify/alli.htm. When I searched for the URL in Google, one of the first results back was "&lt;i&gt;HackeD By UyuSsman ( Turkish Hacker )&lt;/i&gt;" - so we know what's happening there!&lt;br /&gt;&lt;br /&gt;Here's the email content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Unable to Verify Your Account 21 April 2008&lt;br /&gt;We have been unable to verify your account with us. &lt;br /&gt;&lt;br /&gt;Our Technical Security Observe Multiple Error Logins from your Customer ID, Please do verify your account by clicking on the ACCOUNT VERIFICATION below to prove account ownership .&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-5827633548510209666?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/5827633548510209666/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=5827633548510209666' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5827633548510209666'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5827633548510209666'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/alliance-and-leicester-security-notice.html' title='Alliance and Leicester | Security Notice: Unable to Verify Your Account Dated 21 April 2008'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-8354991702643352402</id><published>2008-04-21T09:06:00.002+01:00</published><updated>2008-04-21T09:12:32.137+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ebay'/><title type='text'>Ebay | You've received a question about eBay item: @NEW designer DKNY latest watch with diamond spring 08@ (110243158561)</title><content type='html'>I've received this one twice overnight, to two different email addresses. Similar in look and style to the other recent &lt;A href="http://phishalert.blogspot.com/2008/03/ebay-youve-received-question-about-ebay.html"&gt;Ebay question about&lt;/a&gt; emails received recently.&lt;br /&gt;&lt;br /&gt;This time around the target URL is actually http://tattoo-picture-designs.com/0?ViewItem&amp;item=110243158561&amp;ssPageName=ADME:X:AAQ:GB:1123 - it doesn't even try to ide the URL by using subdomains and the website tattoo-picture-designs.com seems respectable, so I assume they have been hacked and don't realise they are hosting these pages.&lt;br /&gt;&lt;br /&gt;It pretends to be from member &lt;em&gt;labeltree&lt;/em&gt; and has been sent to individual mailboxes, so the recipient's email is shown in the to: field.&lt;br /&gt;&lt;br /&gt;The email is on it's way to Ebay, here's the content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Hi,&lt;br /&gt;Everything is packed and ready to go, I am waiting for payment. Let me konw as soon as the payment is made. &lt;br /&gt;&lt;br /&gt;Have a nice day!&lt;br /&gt;Lyns Jamie.&lt;br /&gt;&lt;br /&gt;- labeltree&lt;br /&gt;&lt;br /&gt;Item and user details &lt;br /&gt;Item Title: @NEW designer DKNY latest watch with diamond spring 08@ &lt;br /&gt;Item Number: 110243158561 &lt;br /&gt;Item URL: http://cgi.ebay.co.uk/ws/eBayISAPI.dll?ViewItem&amp;item=110243158561 &lt;br /&gt;End Date: 21-Apr-08 00:54:45 BST &lt;br /&gt;From User: labeltree (881) &lt;br /&gt;99.8% Positive &lt;br /&gt;since 05-Aug-03 in United Kingdom &lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref i-cmr / q-j&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-8354991702643352402?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/8354991702643352402/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=8354991702643352402' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8354991702643352402'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8354991702643352402'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/ebay-youve-received-question-about-ebay_21.html' title='Ebay | You&apos;ve received a question about eBay item: @NEW designer DKNY latest watch with diamond spring 08@ (110243158561)'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-1765130472951087777</id><published>2008-04-19T19:31:00.002+01:00</published><updated>2008-04-19T19:35:04.689+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Halifax'/><title type='text'>Halifax | Message from Halifax Online</title><content type='html'>Well here's a (fake) claim that Halifax have received security complaints and are taking actions. Of course, the whole point is to breach your security, not protect you.&lt;br /&gt;&lt;br /&gt;The URL the link points to is http://toroon12-1168099092.sdsl.&lt;u&gt;bell.ca&lt;/u&gt;/halifax-online.co.uk/_mem_bin/halifax_LogIn/formslogin.aspsource=halifaxcouk/&lt;br /&gt;&lt;br /&gt;Presumably this means the security on bell.ca has been breached! No doubt that will get quickly plugged!&lt;br /&gt;&lt;br /&gt;Here's the content of the email.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Customer&lt;br /&gt;&lt;br /&gt;Halifax PLC. has been receiving complaints from our customers for unauthorised use of the Halifax Online accounts. As a result we are making an extra security check on all of our Customers account. In order to protect your information please click on the link below:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://halifax-online.co.uk/_mem_bin/halifax_LogIn/formslogin &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thank you for your understanding and correspondence, we also apologize for any inconveniences caused.&lt;br /&gt;&lt;br /&gt;Thanks for your co-operation.&lt;br /&gt;&lt;br /&gt;Fraud Prevention Unit&lt;br /&gt;Legal Advisor&lt;br /&gt;Halifax PLC. &lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref i-cmr&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-1765130472951087777?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/1765130472951087777/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=1765130472951087777' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1765130472951087777'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1765130472951087777'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/halifax-message-from-halifax-online.html' title='Halifax | Message from Halifax Online'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-330039243956739615</id><published>2008-04-18T16:22:00.001+01:00</published><updated>2008-04-18T16:24:58.003+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='emails'/><category scheme='http://www.blogger.com/atom/ns#' term='work scam'/><title type='text'>Email | GET BACK TO US ASAP.</title><content type='html'>And at the same time as the fake lottery, there's also the job offer for money laundering....&lt;br /&gt;&lt;br /&gt;Don't ever reply to these. If you get involved then at best you are assisting criminals with money laundering. At worst you could have your identity stolen, have your bank accounts emptied or end up in prison. It's not worth the risk. No honest company would recruit by sending spam.&lt;br /&gt;&lt;br /&gt;Here's the email:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Sir/Madam, &lt;br /&gt;First, as a way of introduction, I am Mr. Xiao Jun (hails from Taiwan) Managing Director of Solenoids Industrial Co Ltd.Taichung Taiwan. We are Taiwanese based investors, We are into Calcite, Barytes, Manganese Dioxide , Dolomite, Mica , China Clay, MangneseDioxide,Ferrous(Iron ) Oxide,Paints, Rubber, Plastics,Construction chemicals and we export from Asia and export into Europe,America and Australia. &lt;br /&gt;We are also into export and import of the above mentioned products /equipments.&lt;br /&gt;our company "Solenoids Industrial Co Ltd."is a newly established firm that proposed to come up with a lot of business innovation in the&lt;br /&gt; nearest future. We are interested in employing your services, to work with us as ourpayment agent who can help us eastablish a medium of recieving payment on our behalf for Goods and raw materials we supplied to our customers in Europe, South and North America,Australia e.t.c If you are interested in transacting business with us. &lt;br /&gt;we will be very glad.Subject to your satisfaction you will be given the opportunity to negotiate your mode of payment which we will pay for your services as our representative in Europe, America, Australia e.t.c. &lt;br /&gt;Please if you are interested forward to us the following details to our private email address:&lt;br /&gt;agent_consultant_xiaojun@yahoo.com.hk&lt;br /&gt;FULL NAME: &lt;br /&gt;CONTACT ADDRESS:&lt;br /&gt;OCCUPATION:&lt;br /&gt;NATIONALITY:&lt;br /&gt;AGE:&lt;br /&gt;PHONE NUMBER:&lt;br /&gt;FAX:&lt;br /&gt;EMAIL ADDRESS:&lt;br /&gt;PRESENT COUNTRY: &lt;br /&gt;Thank you as we await your further response. &lt;br /&gt;Sincerely &lt;br /&gt;Xiao Jun &lt;br /&gt;Director; &lt;br /&gt;Solenoids Industrial Co Ltd. &lt;br /&gt;55 An Suing East 9th Street, &lt;br /&gt;Taichung, Taiwan &lt;br /&gt;Email Address: agent_consultant_xiaojun@yahoo.com.hk&lt;br /&gt;Tel:/fax 886-9162278842 &lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref q-j&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-330039243956739615?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/330039243956739615/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=330039243956739615' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/330039243956739615'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/330039243956739615'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/email-get-back-to-us-asap.html' title='Email | GET BACK TO US ASAP.'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-1489242255794052528</id><published>2008-04-18T16:18:00.002+01:00</published><updated>2008-04-18T16:22:17.745+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='emails'/><category scheme='http://www.blogger.com/atom/ns#' term='lottery'/><title type='text'>Email | HELLO!!!</title><content type='html'>It's time to get another fake lottery scam. Again, with a Spanish reply-to email address. I wonder why they all come from there?&lt;br /&gt;&lt;br /&gt;It's not realy - it's sent to 'undisclosed-recipients' bacause they are sending so many and can't be bothered to send them individually. If you respond, you might end up giving away enough details to have your bank emptied or your identity stolen.&lt;br /&gt;&lt;br /&gt;If you are worried that you might have been the victim of such an &lt;a href="http://www.comparemortgagerates.co.uk/creditexpert.php"&gt;identity theft&lt;/a&gt;, look at the &lt;a href="http://www.comparemortgagerates.co.uk/creditexpert.php"&gt;free report from Credit Expert&lt;/a&gt; to put your mind at rest.&lt;br /&gt;&lt;br /&gt;Here's the email:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;HELLO!!!&lt;br /&gt;&lt;br /&gt;MICROSOFT E-MAIL PROMOTION OFFICE.&lt;br /&gt;CALLE LA LUNA 45,&lt;br /&gt;COIGO POSTAL 21145&lt;br /&gt;MADRID-ESPAÑA.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I the co-ordinator of the microsoft new year promotion in madrid&lt;br /&gt;spain,has therefore come to you with this great surprise.&lt;br /&gt;Your e mail address came a winner of this great promotion as a 4th&lt;br /&gt;category winner,with the sum of 170,000.00 euro.&lt;br /&gt;Your e mail address attached to a ticket&lt;br /&gt;number:01,05,22,45,88,reference number:ES/NP/CC/08 and batch&lt;br /&gt;number:15558.&lt;br /&gt;The above informations must not be undisclosed to any other person,to&lt;br /&gt;avoid double claim.&lt;br /&gt;&lt;br /&gt;Your fudiciary agent.Mr.Alonso Julian shall process your claim as soon&lt;br /&gt;&lt;br /&gt;as you contact him.You are advise to take to every instructions given&lt;br /&gt;to you by the agent to avoid disqualification of claim.&lt;br /&gt;Contact your agent Mr.Alonso Julian with the following informations:&lt;br /&gt;//////////////////////////////////////////////////////////////////////&lt;br /&gt;&lt;br /&gt;Your full name:&lt;br /&gt;Country:&lt;br /&gt;Address:&lt;br /&gt;Tel/Fax:&lt;br /&gt;The won e mail address:&lt;br /&gt;Alternative e mail address:&lt;br /&gt;Ticket number:&lt;br /&gt;Reference number:&lt;br /&gt;Batch number:&lt;br /&gt;//////////////////////////////////////////////////////////////////////&lt;br /&gt;&lt;br /&gt;Contact:&lt;br /&gt;&lt;br /&gt;CLAIM DEPARTMENT&lt;br /&gt;Mr.Alonso Julian&lt;br /&gt;Tel/Fax:             +34-656-276-595&lt;br /&gt;E mail: microsoftclaimdepartment@ozu.es&lt;br /&gt;//////////////////////////////////////////////////////////////////////&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Any one below the age of 18 is authomatically disqualified.&lt;br /&gt;&lt;br /&gt;Great wishes from the co.ordinator.&lt;br /&gt;(MRS)Fernandez Miguel Laura&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-1489242255794052528?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/1489242255794052528/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=1489242255794052528' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1489242255794052528'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1489242255794052528'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/email-hello.html' title='Email | HELLO!!!'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-7418526487686862568</id><published>2008-04-15T20:07:00.002+01:00</published><updated>2008-04-15T20:11:29.653+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Google Adwords'/><title type='text'>Google | Reactivate Your AdWords Google Account</title><content type='html'>Same idea as the other &lt;a href="http://phishalert.blogspot.com/search/label/Google%20Adwords"&gt;Google phishing emails&lt;/a&gt; and sent to the same email address, but a slightly different message this time.&lt;br /&gt;&lt;br /&gt;With this email the target URL is http://www.adwords.google.com.&lt;u&gt;v6zd2.cn&lt;/u&gt;/select/Login - v6zd2.cn doesn't (yet) have any results in Google (it very soon will do!).&lt;br /&gt;&lt;br /&gt;It's a slightly different tack so they are trying to target people they obviously think have Google accounts and are trying to panic them into signing on. What the point is, I'm not sure. OK, they can get name &amp; address, but what then? Date of birth, credit card details etc are hidden. Maybe they then use your account to run up a load of advertising?&lt;br /&gt;&lt;br /&gt;Here's the email content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;---------------------------------------------------------------------------------&lt;br /&gt;Dear Google Adwords Customer, Your ads have stopped running because we were unable to process your billing information.&lt;br /&gt;To activate your account and start running your ads, enter your billing information.&lt;br /&gt;&lt;br /&gt;In order to activate your account and start running your ads, enter your billing information.&lt;br /&gt;Pease sign into your account at http://adwords.google.com/select/login, and update&lt;br /&gt;your billing information.&lt;br /&gt;&lt;br /&gt;Once your account is reactivated and your billing information has been processed,&lt;br /&gt;any your ads and campaigns can begin running immediately on Google. &lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------------------&lt;br /&gt;This message was sent from a notification-only email address that does&lt;br /&gt;not accept incoming email. Please do not reply to this message.&lt;br /&gt;&lt;br /&gt;---------------------------------------------------------------------------------- &lt;br /&gt;&lt;br /&gt;Google Adwords Team &lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref s-rwt&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-7418526487686862568?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/7418526487686862568/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=7418526487686862568' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7418526487686862568'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7418526487686862568'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/google-reactivate-your-adwords-google.html' title='Google | Reactivate Your AdWords Google Account'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-2841336918995024994</id><published>2008-04-13T18:06:00.002+01:00</published><updated>2008-04-13T18:10:15.908+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Google Adwords'/><title type='text'>Google Adwords | Please Update Your Billing Informatio</title><content type='html'>Same as the &lt;a href="http://phishalert.blogspot.com/2008/03/google-adwords-please-update-your.html"&gt;recent google email&lt;/a&gt; sent a few weeks ago. This time the destination URL is http://www.adwords.google.com.&lt;u&gt;hki045.cn&lt;/u&gt;/select/Login. hki045.cn appears in a few results already for google adwords phishing.&lt;br /&gt;&lt;br /&gt;Sent to the same email as last time as well - this one's got the ability to send to one email address at a time, which helps make it look convincing. But it's not real - don't believe it.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;---------------------------------------------------------------------------------&lt;br /&gt;Dear Google Adwords Customer, Your ads have stopped running because we were unable to process your billing information.&lt;br /&gt;To activate your account and start running your ads, enter your billing information.&lt;br /&gt;&lt;br /&gt;In order to activate your account and start running your ads, enter your billing information.&lt;br /&gt;Pease sign into your account at http://adwords.google.com/select/login, and update&lt;br /&gt;your billing information.&lt;br /&gt;&lt;br /&gt;Once your account is reactivated and your billing information has been processed,&lt;br /&gt;any your ads and campaigns can begin running immediately on Google. &lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------------------&lt;br /&gt;This message was sent from a notification-only email address that does&lt;br /&gt;not accept incoming email. Please do not reply to this message.&lt;br /&gt;&lt;br /&gt;---------------------------------------------------------------------------------- &lt;br /&gt;&lt;br /&gt;Google Adwords Team &lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-2841336918995024994?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/2841336918995024994/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=2841336918995024994' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2841336918995024994'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/2841336918995024994'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/google-adwords-please-update-your.html' title='Google Adwords | Please Update Your Billing Informatio'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-6210397949708925373</id><published>2008-04-11T11:57:00.002+01:00</published><updated>2008-04-11T12:04:04.426+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Skype'/><title type='text'>Skype | Please Update Your Billing Information</title><content type='html'>Here's a target that I've never seen before - Skype. It's a plain text email and the displayed URL looks realistic enough, but the actual target URL is http://secure.skype.com.&lt;u&gt;j71501.cn&lt;/u&gt;/member/Login/. This is a URL that doesn't appear in any search results yet, as it appears to have been registered in Hong Kong yesterday.&lt;br /&gt;&lt;br /&gt;Looking in Google it's not the first time Skype have been victims of these attempts, but I'm having problems finding where to report it, so trying just security@skype.com.&lt;br /&gt;&lt;br /&gt;Here's the email content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Skype Customer!&lt;br /&gt;&lt;br /&gt;In order to update your billing information, please sign in &lt;br /&gt;to your Skype account at https://secure.skype.com/store/member/login.html?message=login_required, &lt;br /&gt;and update your billing information. &lt;br /&gt;&lt;br /&gt;Thank you for choosing Skype. &lt;br /&gt;&lt;br /&gt;Sincerely,&lt;br /&gt;&lt;br /&gt;The Skype Team.&lt;br /&gt;&lt;br /&gt;------------------------&lt;br /&gt;This message was sent from a notification-only email address that does&lt;br /&gt;not accept incoming email. Please do not reply to this message.&lt;br /&gt;------------------------&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref s-rwt&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-6210397949708925373?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/6210397949708925373/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=6210397949708925373' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6210397949708925373'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6210397949708925373'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/skype-please-update-your-billing.html' title='Skype | Please Update Your Billing Information'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-6879516177449720192</id><published>2008-04-11T09:35:00.002+01:00</published><updated>2008-04-11T09:44:52.245+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ebay'/><title type='text'>Ebay| You've received a question about eBay item: Timberland Mens Boots size 11.5</title><content type='html'>This one's the same as the email from &lt;a href="http://phishalert.blogspot.com/2008/04/ebay-youve-received-question-about-ebay_08.html"&gt;couple of days ago&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;From 'eBay Member: vlc223' it is sent to a different email address than the one I picked up the earlier one from and this time the destination URL is http://&lt;u&gt;paulcrites.com&lt;/u&gt;/item?ViewItem&amp;item=230237678367&amp;ssPageName=ADME:X:AAQ:GB:1123 - paulcrites.com being hacked into and innocently holding the phishing pages by the looks of it.&lt;br /&gt;&lt;br /&gt;A copy is on it's way to Ebay. Here's the content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Hi,&lt;br /&gt;Everything is packed and ready to go, Let me know if you paid already. I am waiting for your answer as soon as possible. &lt;br /&gt;&lt;br /&gt;Have a nice day!&lt;br /&gt;Sandra.&lt;br /&gt;&lt;br /&gt;- vlc223 &lt;br /&gt;&lt;br /&gt;Item and user details &lt;br /&gt;Item Title: Timberland Mens Boots size 11.5 &lt;br /&gt;Item Number: 230237678367 &lt;br /&gt;Item URL: http://cgi.ebay.co.uk/ws/eBayISAPI.dll?ViewItem&amp;item=230237678367 &lt;br /&gt;End Date: 07-Apr-08 08:37:42 BST &lt;br /&gt;From User: vlc223 (161) &lt;br /&gt;99.4% Positive &lt;br /&gt;since 29-Nov-03 in United Kingdom &lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref i-cmr&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-6879516177449720192?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/6879516177449720192/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=6879516177449720192' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6879516177449720192'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6879516177449720192'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/ebay-youve-received-question-about-ebay_11.html' title='Ebay| You&apos;ve received a question about eBay item: Timberland Mens Boots size 11.5'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-321054547848388538</id><published>2008-04-10T19:10:00.003+01:00</published><updated>2008-04-10T19:16:39.296+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='comment'/><title type='text'>Credit Card Danger</title><content type='html'>This one isn't phishing, but it's security so I'd thought in a quiet moment I'd recount the tale.&lt;br /&gt;&lt;br /&gt;Last Friday my family and I went out for a meal. We hadn't intended to be going anywhere that we'd need any money (just taking my daughter for a swimming lesson) so I didn't have my wallet. So at the end of the meal my wife paid and put the cost onto my credit card.&lt;br /&gt;&lt;br /&gt;Now I'm always telling her to hide her pin number when she types it in - yet once more it was in full view of the waiter. After she handed the machine back, he then quickly walked off saying 'I'll just print you a receipt'. My suspicions were aroused as he was holding a Chip &amp; Pin terminal with a built in printer.&lt;br /&gt;&lt;br /&gt;I tried to call him back, but he 'didn't hear' and was quickly back at the till with me watching the card from the table. Most of the time the machine was in full view, but at one point he removed the card and held it out of sight briefly.&lt;br /&gt;&lt;br /&gt;Now this could have been an innocent move, but my daughter is well trained and said she'd watched him watch my wife typing in her PIN and that he smiled when she'd finished.&lt;br /&gt;&lt;br /&gt;This was all so suspicious, but with no proof of any wrong doing what can you do? Well I drove her straight to the nearest cash machine and she changed her PIN immediately.&lt;br /&gt;&lt;br /&gt;I'm hoping that's the end of the tale - no mysterious transactions yet, but I've asked her to look when she next uses the card to see if any attempts have been made with an incorrect PIN.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-321054547848388538?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/321054547848388538/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=321054547848388538' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/321054547848388538'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/321054547848388538'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/credit-card-danger.html' title='Credit Card Danger'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-5653719723785563627</id><published>2008-04-09T09:17:00.002+01:00</published><updated>2008-04-09T09:27:33.481+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PayPal'/><title type='text'>PayPal | Notification of Limited Account Access</title><content type='html'>Here's an email that apologises for being an inconvenience - if anyone falls for it, it will be a very big inconvenience.&lt;br /&gt;&lt;br /&gt;It claims to be from PayPal following 'unusual activity' on the account. But it's not.&lt;br /&gt;&lt;br /&gt;The target URL is http://static-68-179-55-98.ptr.&lt;u&gt;terago.ca&lt;/u&gt;/paypal.com/managament/cgi/, terago.ca being the host of another &lt;a href="http://phishalert.blogspot.com/2008/04/paypal-warning-notification.html"&gt;recent PayPal phishing email&lt;/a&gt;. In fact, that one sent last week went to exactly the same destination URL. Presumably PayPal have not been able to get those pages shut down, or the site has been hacked again. Looking through the search results for the site, it does look to be an innocent victim.&lt;br /&gt;&lt;br /&gt;Other indications that it's phishing are that it's sent to 'undisclosed-recipients'. If this had really happened, it would have affected 1 email at a time and PayPal would deal with it by contacting one member at a time. They would also not start off without an introduction using your name and the sent time on the email is 6th April, 00:00, even though it was received 07:45 on the 9th April. Someone has been playing with headers and forgotten to change them.&lt;br /&gt;&lt;br /&gt;Lastly, PayPal would never ask you to click a link and then reveal your security details. If such action was required then they would be unlikely to email you (as your email could have been compromised - you do have different PayPal and email passwords, don't you???) and they would ask you to enter the PayPal address into your browser.&lt;br /&gt;&lt;br /&gt;Here's the content, email is on it's way to PayPal for them to sort.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;Notification of Limited Account Access &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;As part of our security measures, we regularly screen activity in the PayPal system. We recently noticed the following issue on your account: &lt;br /&gt;&lt;br /&gt;Unusual account activity has made it necessary to limit sensitive account features until additional verification information can be collected. &lt;br /&gt;&lt;br /&gt;We have been notified that a card associated with your account has been reported as lost or stolen, or that there were additional problems with your card.&lt;br /&gt;&lt;br /&gt;Case ID Number: PP-071-362-996 &lt;br /&gt;&lt;br /&gt;Click here to verify your account &lt;br /&gt;&lt;br /&gt;Please understand that this is a security measure intended to help protect you and your account. We apologize for any inconvenience. &lt;br /&gt;&lt;br /&gt;If you choose to ignore our request, you leave us no choice but to temporary suspend your account.&lt;br /&gt;&lt;br /&gt;Sincerely,&lt;br /&gt;PayPal Account Review Department. &lt;br /&gt;&lt;br /&gt;--------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Please do not reply to this e-mail. Mail sent to this address cannot be answered. For assistance, log in to your PayPal account and choose the "Help" link in the footer of any page.&lt;br /&gt;&lt;br /&gt;To receive email notifications in plain text instead of HTML, update your preferences here. &lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref i - cmr&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-5653719723785563627?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/5653719723785563627/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=5653719723785563627' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5653719723785563627'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5653719723785563627'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/paypal-notification-of-limited-account.html' title='PayPal | Notification of Limited Account Access'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-6688325335010279712</id><published>2008-04-08T16:09:00.002+01:00</published><updated>2008-04-08T16:13:13.876+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ebay'/><title type='text'>Ebay | You've received a question about eBay item: Timberland Mens Boots size 11.5 (230237678367)</title><content type='html'>Pretty much the same as other &lt;a href="http://phishalert.blogspot.com/2008/03/ebay-youve-received-question-about-ebay.html"&gt;Ebay question about phishing emails&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;This time around the email links to the website http://www.thejoyofcrafting.com/lndex.htm?ViewItem&amp;item=230237678367&amp;ssPageName=ADME:X:AAQ:GB:1123. Presumably an innocent victim, but I have found other reports of the website being used for similar purposes, with Google's cach being dated around 2 weeks ago - so it looks like they are a serial victim.&lt;br /&gt;&lt;br /&gt;Here's the email content.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Hi,&lt;br /&gt;Everything is packed and ready to go, Let me know if you paid already. I am waiting for your answer as soon as possible. &lt;br /&gt;&lt;br /&gt;Have a nice day!&lt;br /&gt;Sandra.&lt;br /&gt;&lt;br /&gt;- vlc223 Respond to this question  &lt;br /&gt;&lt;br /&gt;If you use My Messages to respond, your email address will not be shared. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Item and user details &lt;br /&gt;Item Title: Timberland Mens Boots size 11.5 &lt;br /&gt;Item Number: 230237678367 &lt;br /&gt;Item URL: http://cgi.ebay.co.uk/ws/eBayISAPI.dll?ViewItem&amp;item=230237678367 &lt;br /&gt;End Date: 07-Apr-08 08:37:42 BST &lt;br /&gt;From User: vlc223 (161) &lt;br /&gt;99.4% Positive &lt;br /&gt;since 29-Nov-03 in United Kingdom &lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref q - j&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-6688325335010279712?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/6688325335010279712/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=6688325335010279712' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6688325335010279712'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/6688325335010279712'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/ebay-youve-received-question-about-ebay_08.html' title='Ebay | You&apos;ve received a question about eBay item: Timberland Mens Boots size 11.5 (230237678367)'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-1611959963633761593</id><published>2008-04-05T10:26:00.001+01:00</published><updated>2008-04-05T10:26:49.331+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PayPal'/><title type='text'>PayPal | Warning Notification</title><content type='html'>&lt;a href="http://www.financehunt.co.uk/phishing/paypal080405.php"&gt;&lt;img src="http://www.financehunt.co.uk/phishing/paypal080405small.jpg" align="right" alt="PayPal Phishing Email, April"&gt;&lt;/a&gt;Another Phishing email targeted at PayPal. &lt;br /&gt;&lt;br /&gt;Pointers for the unwary that it's phishing:&lt;br /&gt;1 - emailed to 'undisclosed recipients'&lt;br /&gt;2 - starts 'Dear Customer', rather than using my name&lt;br /&gt;3 - PayPal would &lt;u&gt;never&lt;/u&gt; send an email asking me to enter personal details&lt;br /&gt;4 - the link is actually pointing to http://static-68-179-55-98.ptr.&lt;u&gt;terago.ca&lt;/u&gt;/paypal.com/managament/cgi/ - terago.ca are actually a broadband provider, so I assume someone is misusing some account space on their site.&lt;br /&gt;&lt;br /&gt;It's not real, don't click the links. I've sent a copy to PayPal. Here's the text.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Customer, &lt;br /&gt;&lt;br /&gt;It has come to our attention that your PayPal® account information needs to be updated as part of our continuing commitment to protect your account and to reduce the instance of fraud on our website. If you could please take 5-10 minutes out of your online experience and update your personal records you will not run into any future problems with the online service.&lt;br /&gt;&lt;br /&gt;However, failure to update your records will result in account suspension. Please update your records before April 8, 2008.&lt;br /&gt;&lt;br /&gt;Once you have updated your account records, your PayPal® account activity will not be interrupted and will continue as normal.&lt;br /&gt;&lt;br /&gt;Click here to update your PayPal account information&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-1611959963633761593?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/1611959963633761593/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=1611959963633761593' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1611959963633761593'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/1611959963633761593'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/paypal-warning-notification.html' title='PayPal | Warning Notification'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-9039648475556400882</id><published>2008-04-04T23:37:00.000+01:00</published><updated>2008-04-04T23:40:04.523+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Google Adwords'/><title type='text'>Reporting Adwords Phishing Emailos</title><content type='html'>Google finally got back to me this afternoon after I asked them where to &lt;a href="http://phishalert.blogspot.com/2008/03/google-adwords-please-update-your.html"&gt;report a Google Adsense phishing email&lt;/a&gt;. Part of their answer read:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;In order for us to determine the source of the attack, please forward&lt;br /&gt;the entire email, including the full message header information, to&lt;br /&gt;spoof@google.com or phishing@google.com. We investigate all reports sent&lt;br /&gt;to this address&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;So send any Google phishing emails you wish to report to either of these addresses.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-9039648475556400882?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/9039648475556400882/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=9039648475556400882' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/9039648475556400882'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/9039648475556400882'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/reporting-adwords-phishing-emailos.html' title='Reporting Adwords Phishing Emailos'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-4312602066784822081</id><published>2008-04-04T23:32:00.000+01:00</published><updated>2008-04-04T23:36:22.666+01:00</updated><title type='text'>Natwest Bank Private and Corporate New Security Features Activation</title><content type='html'>Very similar to other Natwest phishing emails this one, just it tries to cover both private and corporate recipients.&lt;br /&gt;&lt;br /&gt;This time the target URL is http://www4.nwolb.com.&lt;u&gt;agent84.in&lt;/u&gt;/default.aspx?agent=17zrohDxcrszkOkhOvp - agent84.in appears in a few phishing results already.&lt;br /&gt;&lt;br /&gt;I've forwarded a copy to the Natwest, but on previous experience there aren't acknowledgements. Here's the content.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear NatWest Bank On-line Banking member!&lt;br /&gt;&lt;br /&gt;Our Technical Department is running a scheduled Internet Banking software upgrade&lt;br /&gt;&lt;br /&gt;By following the link below please begin the procedure of the user details authorization:&lt;br /&gt;&lt;br /&gt;http://www4.natwest.com/default.aspx?session=17zrohDxcrszkOkhOvp&lt;br /&gt;&lt;br /&gt;These directives are to be emailed and followed by all customers of the Natwest Private and Corporate&lt;br /&gt;&lt;br /&gt;NatWest Bank does apologize for any problems caused, and is very grateful for your help.&lt;br /&gt;&lt;br /&gt;If you are not customer of NatWest Bank Digital Banking please delete this letter!&lt;br /&gt;&lt;br /&gt;*** This is robot generated message please do not reply ***&lt;br /&gt;&lt;br /&gt;(C) '08 NatWest Bank Bankline Internet Banking. All Rights Reserved.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-4312602066784822081?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/4312602066784822081/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=4312602066784822081' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/4312602066784822081'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/4312602066784822081'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/natwest-bank-private-and-corporate-new.html' title='Natwest Bank Private and Corporate New Security Features Activation'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-8201228174304446425</id><published>2008-04-03T20:46:00.003+01:00</published><updated>2008-04-03T20:50:31.541+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ebay'/><title type='text'>Ebay | You've received a question about eBay item: 2x Weekend Tickets V Festival - Weston Park + Camping (280212913563)</title><content type='html'>This one has the same convincing appearance as other similar &lt;a href="http://phishalert.blogspot.com/2008/03/ebay-youve-received-question-about-ebay.html"&gt;ebay phishing&lt;/a&gt; emails, so I won't put up a picture.&lt;br /&gt;&lt;br /&gt;This time the target URL is http://www.&lt;u&gt;mpedubai.com&lt;/u&gt;/index.htm?ViewItem&amp;item=280212913563&amp;ssPageName=ADME:X:AAQ:GB:1123. mpedubai.com gets a few mentions on Google in phishing search results.&lt;br /&gt;&lt;br /&gt;It's not for real - don't worry about it. I've forwarded the email to Ebay already.&lt;br /&gt;&lt;br /&gt;Here's the content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Hi,&lt;br /&gt;Let me know if PayPal is ok to pay for my item. I am waiting for your answer as soon as possible. &lt;br /&gt;&lt;br /&gt;Thank you.&lt;br /&gt;Scott.&lt;br /&gt;&lt;br /&gt;- dychie478 Respond to this question  &lt;br /&gt;&lt;br /&gt;If you use My Messages to respond, your email address will not be shared. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Item and user details &lt;br /&gt;Item Title: 2x Weekend Tickets V Festival - Weston Park + Camping &lt;br /&gt;Item Number: 280212913563 &lt;br /&gt;Item URL: http://cgi.ebay.co.uk/ws/eBayISAPI.dll?ViewItem&amp;item=280212913563 &lt;br /&gt;End Date: 31-Mar-08 08:55:31 BST &lt;br /&gt;From User: dychie478 (173) &lt;br /&gt;99.5% Positive &lt;br /&gt;since 13-Jan-05 in United Kingdom &lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-8201228174304446425?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/8201228174304446425/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=8201228174304446425' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8201228174304446425'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/8201228174304446425'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/ebay-youve-received-question-about-ebay.html' title='Ebay | You&apos;ve received a question about eBay item: 2x Weekend Tickets V Festival - Weston Park + Camping (280212913563)'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-9194380898394933636</id><published>2008-04-01T22:51:00.000+01:00</published><updated>2008-04-01T22:59:48.580+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Halifax'/><title type='text'>Halifax | Online Banking - You Have 1 Unread Message</title><content type='html'>&lt;a href="http://www.financehunt.co.uk/phishing/halifax080401.php"&gt;&lt;img src="http://www.financehunt.co.uk/phishing/halifax080401small.jpg" alt="Halifax Phishing Email" align="right"&gt;&lt;/a&gt;The &lt;a href="http://phishalert.blogspot.com/search/label/Halifax"&gt;Halifax&lt;/a&gt; seems to be a new sudden victim of a few Phishing emails.&lt;br /&gt;&lt;br /&gt;This one has gone to some effort to look the part, but gives the game away as the email has been sent to 10 different "keith" email addresses - only 1 of which is mine! Of course, as I frequently say, no respectable financial institution would greet you in an email with 'Dear Valued Customer' - it would be by your full name.&lt;br /&gt;&lt;br /&gt;It takes the form of various &lt;a href="http://phishalert.blogspot.com/2008/01/abbey-message-alert-you-have-1-unread.html"&gt;Abbey Phishing Emails&lt;/a&gt; of a few months ago in that it doesn't tell you anything, it just claims there's a message that needs your attention.&lt;br /&gt;&lt;br /&gt;The destination URL is http://&lt;u&gt;halifax-onlines.com&lt;/u&gt;/halifax-online.co.uk/_mem_bin/formslogin.asp_source=halifaxcoukHOME/account.php. &lt;i&gt;halifax-onlines.com&lt;/i&gt; is obviously a very clever domain name - it looks very realistic, but it does already appear in several Phishing results on Google.&lt;br /&gt;&lt;br /&gt;Here's the email content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;You have a new message waiting in your Inbox Folder.&lt;br /&gt;&lt;br /&gt;Click here to read.&lt;br /&gt;&lt;br /&gt;Best Regards.&lt;br /&gt;Halifax Banking plc Security Department Team.&lt;br /&gt;&lt;br /&gt;* Please do not reply to this email as your reply will not be received&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-9194380898394933636?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/9194380898394933636/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=9194380898394933636' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/9194380898394933636'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/9194380898394933636'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/halifax-online-banking-you-have-1.html' title='Halifax | Online Banking - You Have 1 Unread Message'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-9174414988651682476</id><published>2008-04-01T16:10:00.003+01:00</published><updated>2008-04-01T16:14:21.146+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='emails'/><category scheme='http://www.blogger.com/atom/ns#' term='lottery'/><title type='text'>ATTN:DONT FORGET TO ATTEND TO THIS EMAIL</title><content type='html'>Here's a strange email. It's the usual &lt;a href="http://phishalert.blogspot.com/2008/02/congratulation-your-email-id-have-won.html"&gt;internet lottery&lt;/a&gt; that I've supposedly won without entering that do the rounds every so often. But it's so poorly written as to make it very difficult to read.&lt;br /&gt;&lt;br /&gt;Hopefully that will put a lot of people off replying. Why do these scams so often claim to be from Spain? &lt;br /&gt;&lt;br /&gt;Here's the content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;ATTN:DONT FORGET TO ATTEND TO THIS EMAIL&lt;br /&gt;&lt;br /&gt;MICROSOFT E-MAIL PROMOTION CENTRE&lt;br /&gt;CALLE LA LUNA,45.PRIMERA PLANTA.&lt;br /&gt;CODIGO POSTAL 28845.&lt;br /&gt;MADRID ESPAÑA.&lt;br /&gt;&lt;br /&gt;Complete the following and send it to your fudiciary agent Mr.Julian&lt;br /&gt;Alonso immediately for the claim of 170,000.00.Euros.&lt;br /&gt;Which you have won on the microsoft 2008 e mail promotion conducted in&lt;br /&gt;madrid spain,for internet users.&lt;br /&gt;&lt;br /&gt;Contact Mr.Julian Alonso to process your claim.&lt;br /&gt;Tel : 0034-656-276-595&lt;br /&gt;E mail : publicfinancedpt@ozu.es&lt;br /&gt;&lt;br /&gt;YOUR WINNING DATAILS:&lt;br /&gt;&lt;br /&gt;Your ticket #: ES/NP/CC/08&lt;br /&gt;Your Batch #: 1558&lt;br /&gt;Your Reference #: 01,05,22,45,88&lt;br /&gt;&lt;br /&gt;COMPLETE THE FOLLOW AND SEND TO YOUR AGENT ON THE E MAIL ADDRESS:&lt;br /&gt;&lt;br /&gt;Your country:_&lt;br /&gt;Your full name:_&lt;br /&gt;Your address:_&lt;br /&gt;Alternative e mail address:_&lt;br /&gt;Your tel:_&lt;br /&gt;&lt;br /&gt;Your's Sincerely,&lt;br /&gt;&lt;br /&gt;Mrs.Miguel Laurita Perez&lt;br /&gt;Co-ordinator.&lt;br /&gt;&lt;br /&gt;Ahora también puedes acceder a tu correo Terra desde el móvil.&lt;br /&gt;Infórmate pinchando aquí.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-9174414988651682476?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/9174414988651682476/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=9174414988651682476' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/9174414988651682476'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/9174414988651682476'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/04/attndont-forget-to-attend-to-this-email.html' title='ATTN:DONT FORGET TO ATTEND TO THIS EMAIL'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-764199567323095889</id><published>2008-03-31T13:29:00.002+01:00</published><updated>2008-03-31T13:33:44.788+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PayPal'/><title type='text'>PayPal | PayPal account information needs to be updated</title><content type='html'>Here's a new PayPal email that threatens to close your account pretty soon (2 days' notice) unless you update certain details. PayPal state they would never ask for this via email, plus they always use your name in the email and don't email "undisclosed-recipients:".&lt;br /&gt;&lt;br /&gt;The destination URL is actually http://stolnick-8marta-8b-r1-c1-45.ekb.&lt;u&gt;unitline.ru&lt;/u&gt;/www.paypal.com/managament/cgi/, making it the second Phishing email to be posted in these pages within 48 hours using the unitline.ru domain.&lt;br /&gt;&lt;br /&gt;Here's the email - already forwarded to PayPal for them to investigate.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear valued PayPal member,&lt;br /&gt;&lt;br /&gt;It has come to our attention that your PayPal account information needs to be updated as part of our continuing commitment to protect your account and to reduce the instance of fraud on our website. If you could please take 5-10 minutes out of your online experience and update your personal records you will not run into any future problems with the online service.&lt;br /&gt;&lt;br /&gt;However, failure to update your records will result in account suspension. Please update your records on or before April 02, 2008.&lt;br /&gt;&lt;br /&gt;Once you have updated your account records, your PayPal session will not be interrupted and will continue as normal.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  To update your PayPal records click on the following link:&lt;br /&gt;  http://www.paypal.com/cgi-bin/webscr?cmd=_login-run&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thank you,&lt;br /&gt;PayPal Customer Center.&lt;br /&gt;&lt;br /&gt;Accounts Management As outlined in our User Agreement, PayPal will periodically send you information about site changes and enhancements.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-764199567323095889?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/764199567323095889/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=764199567323095889' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/764199567323095889'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/764199567323095889'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/03/paypal-paypal-account-information-needs.html' title='PayPal | PayPal account information needs to be updated'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-5599088724742811919</id><published>2008-03-31T13:25:00.001+01:00</published><updated>2008-03-31T13:25:51.741+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Google Adwords'/><title type='text'>Google Adwords | Please Update Your Billing Information</title><content type='html'>Here's one that got through the net first time I recieved it. I believed it, deleted the email (permanently) then went onto the Google site to follow it's instructions. Only then did I realise that the email address it had been sent to wasn't associated with a Google adwords account that I maintain...&lt;br /&gt;&lt;br /&gt;At first I thought I was mistaken until I received the email about. Assuming I was wrong and maybe I had used that email address for a Google Adsense account in the past I was about to try to login again, until I noticed that the target URL was http://adwrods.google.select.&lt;u&gt;asolf3.cn&lt;/u&gt;/select/index.html&lt;br /&gt;&lt;br /&gt;asolf3.cn makes several appearances in Google Phishing search results. But it got past me the first time, and nearly this time, because I was using a shortcut on my desktop to sign on, rather than the link in the email.&lt;br /&gt;&lt;br /&gt;Here's the content - it's dangerous! I can't find an address to report this to Google, so I've sent them a contact form and awaiting a response.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;This message was sent from a notification-only email address that does&lt;br /&gt;not accept incoming email. Please do not reply to this message.&lt;br /&gt;--------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Dear GoogleAdwords Customer,&lt;br /&gt;&lt;br /&gt;In order to update your billing information, please sign in to your AdWords account at https://adwords.google.com, and update your billing information. Your account will be reactivated as soon as you have entered your payment details. Your ads will show immediately if you decide to pay for clicks via credit or debit card. If you decide to pay by direct debit, we may need to receive your signed debit authorization before your ads start running, depending on your location. If you choose bank transfer, your ads will show as soon as we receive your first payment. (Payment options vary by location.)&lt;br /&gt;&lt;br /&gt;Thank you for choosing AdWords. We look forward to providing you with the most effective advertising available.&lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------------------------&lt;br /&gt;The Google AdWords Team &lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-5599088724742811919?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/5599088724742811919/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=5599088724742811919' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5599088724742811919'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5599088724742811919'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/03/google-adwords-please-update-your.html' title='Google Adwords | Please Update Your Billing Information'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-270796892863725297</id><published>2008-03-30T11:36:00.004+01:00</published><updated>2008-03-30T11:42:43.441+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Halifax'/><title type='text'>Halifax customer service: online banking notification!</title><content type='html'>First we had the &lt;a href="http://phishalert.blogspot.com/2008/03/natwest-natwest-bank-details.html"&gt;NOF&lt;/a&gt;, now we've got the HOF. The HOF looks just like the NOF phishing email, just with the bank's name changed to 'Halifax'.&lt;br /&gt;&lt;br /&gt;This time around the target URL is http://halifax.co.uk.&lt;u&gt;sistemlog6.ms&lt;/u&gt;/_mem_bin/onlineform.asp?source=[removed] - sistemlog6.ms being a site that appears in a few Phishing results on Google.&lt;br /&gt;&lt;br /&gt;The email is at least addresses on the to: section just to my email address and displayed the name part (before the URL) to try to make it more convincing. but 'Dear Halifax bank customer' is not how a bank would address a customer.&lt;br /&gt;&lt;br /&gt;As always, no bank would send an email like this. It is purely an attempt to empty your account of funds and maybe even steal your identity. Don't click the link. If you are worried about accidentally clicking these links, use a phishing safe browser such as Firefox (free download from the button on the right).&lt;br /&gt;&lt;br /&gt;Here's the content of the email.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear Halifax bank customer,&lt;br /&gt;&lt;br /&gt;We have implemented security measures consistent with our internal information security practices to help us keep your information secure. These measures include technical and procedural steps to protect your data from misuse, access or disclosure, loss, alteration or destruction.&lt;br /&gt;&lt;br /&gt;One of these security measures is HOF (Halifax Online Form) to help us to keep your personal and banking data up to date.&lt;br /&gt;&lt;br /&gt;You should complete HOF on a regular basis.&lt;br /&gt;&lt;br /&gt;Please complete HOF using the link below:&lt;br /&gt;&lt;br /&gt;Halifax Online Form&lt;br /&gt;&lt;br /&gt;Halifax Automated Mail Service. Please do not respond to this mail.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;ref cmr&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-270796892863725297?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/270796892863725297/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=270796892863725297' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/270796892863725297'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/270796892863725297'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/03/halifax-customer-service-online-banking.html' title='Halifax customer service: online banking notification!'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-5781866452851888143</id><published>2008-03-29T22:58:00.002Z</published><updated>2008-03-29T23:04:59.583Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Halifax'/><title type='text'>Halifax | IMPORTANT SECURITY ALERT</title><content type='html'>This one has taken the time to put a Halifax banner across the top of the email - along with a picture of the guy from their adverts. There's also some waffle down the bottom about needing Flash 5 to access the site. This has been taken from the bank's own website, but it's over  ayear out of date. Must be a phishing template from some time ago...&lt;br /&gt;&lt;br /&gt;The email tries to make out that the recipients Halifax Bank Account has been subject to some attempted breach of security, and that these actions are to reinstate access to the account. This sort of email would never be sent. If a bank had reason to suspend access to an internet account system they would do so, then post the new security details via Royal Mail (been there, had it happen). So don't fall for this trick.&lt;br /&gt;&lt;br /&gt;In this case the target URL is http://stolnick-8marta-8b-r1-c1-45.ekb.&lt;u&gt;unitline.ru&lt;/u&gt;/halifax-online.co.uk/_mem_bin/halifax_LogIn/formslogin.aspsource=halifaxcouk/ - but I've no idea what unitline.ru is nor whether it is just an innocent website that's been hikacked for this purpose. Looks like that might be the case.&lt;br /&gt;&lt;br /&gt;Anyway, leave the link and delete the email.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;IMPORTANT SECURITY ALERT&lt;br /&gt;&lt;br /&gt;--------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Please note that our system recently noted that your attemption of signing on to your account was failed while some errors occured during the processing update of your online account you are having with our bank..&lt;br /&gt;&lt;br /&gt;We sincerely here by to notify you that you should kindly follow below link to update your online account for your security safety ensured by our financial insititution.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;https://www.halifax-online.co.uk/_mem_bin/FormsLogin.asp?source=halifaxouk&lt;br /&gt;&lt;br /&gt;Thank you for your prompt attention to this matter. Please understand that this is a security measure meant to help protect you and your account. &lt;br /&gt;&lt;br /&gt;We apologize for any inconvenience. &lt;br /&gt;&lt;br /&gt;If you choose to ignore our request, your account may leads to be temporarily suspended&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-5781866452851888143?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/5781866452851888143/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=5781866452851888143' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5781866452851888143'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/5781866452851888143'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/03/halifax-important-security-alert.html' title='Halifax | IMPORTANT SECURITY ALERT'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-3462088224378116328</id><published>2008-03-27T22:58:00.000Z</published><updated>2008-03-27T23:04:13.878Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nationwide'/><title type='text'>Nationwide | Important Notice!</title><content type='html'>Here's a neat looking email, that was determined to get through as it was simultaneously sent to three possible email addresses within my domain, 1 being real. They even know my name, which could be worked out from the email, but the email was also sent to links@, using my name.&lt;br /&gt;&lt;br /&gt;The target URL for the link is actually http://www.nationwide.co.uk.login.account.kmpa0up8vuocae0huto.&lt;u&gt;31c5f18a7f.com&lt;/u&gt;/NationWide/secure/login/index.html?id=[id removed]. 31c5f18a7f.com is the subject to many Google search results about phishing sites.&lt;br /&gt;&lt;br /&gt;Here's the email:&lt;br /&gt; &lt;br /&gt;&lt;i&gt;Dear keith@[url removed],&lt;br /&gt;&lt;br /&gt;Nationwide is proud to announce about their new updated secure system. We updated our new SSL servers to give our customers a better, fast and secure online banking service.&lt;br /&gt;&lt;br /&gt;Due to the recent update of the servers, you are requested to please update your account info at the following link.&lt;br /&gt;&lt;br /&gt;- Update Access Now!&lt;br /&gt;&lt;br /&gt;*Important*&lt;br /&gt;Please provide these information correctly and completely, failing to comply may result temporary suspension of your online banking.&lt;br /&gt;&lt;br /&gt;Ruben M. Ortiz&lt;br /&gt;Security Advisor&lt;br /&gt;Nationwide&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-3462088224378116328?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/3462088224378116328/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=3462088224378116328' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/3462088224378116328'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/3462088224378116328'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/03/nationwide-important-notice.html' title='Nationwide | Important Notice!'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5457092559363087572.post-7118057235854952889</id><published>2008-03-20T16:07:00.001Z</published><updated>2008-03-20T16:09:43.386Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ebay'/><title type='text'>Ebay | eBay New Unpaid Item Message - Respond Now !!</title><content type='html'>This one came through twice in quick sucession, probably via different email accounts. Sent to 'undisclosed-recipients' and the target URL is http://www.forum-ebay.&lt;u&gt;9hz.com&lt;/u&gt;. 9hz.com is a free website forwarding service, so it is hiding the actual destination of the phishing site.&lt;br /&gt;&lt;br /&gt;Here's the content:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Dear member, &lt;br /&gt;&lt;br /&gt; &lt;br /&gt;eBay member Tixcity has left you a message regarding item #220055788880&lt;br /&gt;&lt;br /&gt;View the dispute thread to respond. &lt;br /&gt;&lt;br /&gt; &lt;br /&gt;Regards, &lt;br /&gt;&lt;br /&gt;eBay Inc.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Copyright © 1995-2007 eBay Inc. All Rights Reserved.Designated trademarks and brands are the property of their respective owners.Use of this Web site constitutes acceptance of the eBay User Agreement and Privacy Policy.   &lt;br /&gt; &lt;br /&gt; &lt;br /&gt;  &lt;br /&gt;eBay official time - Page last updated:  Mar-19-03 11:57:05 PDT &lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5457092559363087572-7118057235854952889?l=phishalert.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phishalert.blogspot.com/feeds/7118057235854952889/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5457092559363087572&amp;postID=7118057235854952889' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7118057235854952889'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5457092559363087572/posts/default/7118057235854952889'/><link rel='alternate' type='text/html' href='http://phishalert.blogspot.com/2008/03/ebay-ebay-new-unpaid-item-message.html' title='Ebay | eBay New Unpaid Item Message - Respond Now !!'/><author><name>Keith</name><uri>http://www.blogger.com/profile/07998348011624561853</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
