|
Date Reported: 2nd March 2008 |
Risk Level: MEDIUM |
|
|
|
|
|
Email Subject: |
Online form released. [message id: UJ5654067232671] |
|
Apparent Sender: |
Citibank |
|
Return Address: |
CitiBusiness < autoremailer.id608824- 02916575CBF@citi.com > |
|
Email Format: |
HTML |
|
URL of Web Content: |
http://citibusiness.citibank.com.losao9.es/ businessdir/cbof/start.do?ref= 223112789855877903735249642 266734770329784346296931060& session=66737411981 |
|
Location: |
Israel |
|
Scam number: |
aa-6628 |
|
Comments: |
-
Email asks you to confirm/update/verify your account data at Citibank by visiting the given link. You will be taken to a spoof website where your details will be captured for the phishers.
- Citibank never send their users emails requesting personal details in this way.
-
The REAL URL of the spoof website is disguised as "http://citibusiness.citibank.com/ businessdir/cbof/start.do?ref= 2231127898558779037352496422667 34770329784346296931060& session=66737411981".
-
The spoof website this email links to was not online at time of this report, but variations of the scam which link to working websites are bound to exist, so be wary! The website may have been taken down or disabled by the hosts, but quite often these websites are hosted on the personal computer of the phishers, so may only be online at certain times.
-
The REAL URL of the spoof website has been chosen to look very similar to the actual Citibank URL. Do not be fooled!
|
|
|
|
|
|
|
|
|
|
"CitiBusiness new Scheduled Maintenance Program protects your data from unauthorized access."
|
Dear CitiBusiness customer,
CitiBusiness new Scheduled Maintenance Program protects your data from unauthorized access. CitiBusiness Online Form is important addition to our scheduled maintenance program.
Please use the link below to access CitiBusiness Online Form:
http://citibusiness.citibank.com/ businessdir/cbof/start.do?ref= 2231127898558779037352496422667 34770329784346296931060&session= 66737411981
Please do not reply to this auto-generated email. Follow instructions above.
|
|
|
Website: |
|
|
|
Spoof website not online at time of report...
|
|