All the latest UK technology news, reviews and analysis

UK bank hit by massive phishing attack

by Matt Chapman

13 Sep 2006

Comment: 1

  • Tweet this
Customers of Barclays Bank have been alerted to a range of phishing emails designed to steal online banking details
An antivirus company has identified 61 variants of spoofed emails targeting Barclays customers

Customers of Barclays Bank have been alerted to a range of phishing emails designed to steal online banking details. 

Antivirus company Panda Software has identified 61 variants of spoofed emails targeting Barclays customers. 

Panda said that 64 per cent of the phishing messages it has detected in the past few hours were aimed at the UK bank. 

The rush of spoof emails has pushed the number of overall phishing attacks up by 30 per cent.

"The false emails are designed to appear as if they have been sent from Barclays' customer services, with the subject field chosen at random from a list of options," said a statement from Panda Software.

"Some of these options include 'Barclays bank official update', 'Barclays bank Security update' and 'Please Read or Verify your data with Barclays bank'. "

The message text, imitating Barclays' corporate image, informs users that the bank is upgrading its software and that they should go to a link in order to confirm their bank details.

Users who click on the link will see a form similar to those used by the bank, requesting their account number, credit card number or Pin.

Panda warned that the 61 different variants of the email make it very likely that some will bypass anti-spam filters.

The attack also shows signs of being coordinated, since it was initiated in several places at the same time in order to spread rapidly.

It uses at least five false internet addresses based in Korea to hinder attempts to close all of the phishing sites quickly.

"This is a sophisticated attack in comparison with those that we usually see, " said Luis Corrons, director of Panda Labs.

"The use of several domains to host spoofed web pages makes it more difficult to disable them. The emails are also far more authentic looking than the usual, often error-strewn, messages."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

The workplace of the future poll - in association with IBM

What will be the biggest change to corporate technology in the future?

89%

6%

1%

3%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

PHP developer - CSS, HTML, Javascript, MySQL, Linux

PHP developer - CSS, HTML, Javascript, MySQL, Linux...

Senior BPM Developer

Senior BPM Developer (Java, J2EE, Agile, Spring, Struts...

Business Analyst

As a Business Analyst you will play a key role in understanding...

C#/ASP.NET Team Lead - Gloucester

C#/ASP.NET Team - Gloucester - My client has an urgent...

Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.

To send to more than one email address, simply separate each address with a comma.