Personal Tech Pipeline | News | Chinese Bank Hosts Phishing Site

White Papers

Sponsor Resources

WebCasts
Free Newsletter GlossaryContact UsAbout Us
Players & CamsPhones & PDAsHome & AutoOnline

March 13, 2006

Chinese Bank Hosts Phishing Site



Courtesy of TechWeb News

A Chinese bank's server is hosting spoofed sites that phishers are using to dupe customers of American banks and e-tailers, a U.K.-based Internet monitoring company said Sunday.

According to Netcraft, this is the first time one bank's network has been used by criminals to steal information from another bank's customers.

The identity theft attack started Saturday when e-mails were sent to Chase Bank customers that directed them to a site hosted on IP addresses assigned to a Shanghai branch of the China Construction Bank Corp. (CCBC). The spoofed Chase and eBay sites were tucked away in hidden directories, and the CCBC's server's main page displayed a configuration error, said Netcraft.

The Chase attack takes a new phishing tack: rather than directly con gullible users into giving up account passwords or PINs by pretending to be a message from customer support, the e-mail poses as a survey of Chase's online banking sites.

Anyone who fills out the survey will supposedly receive $20 for their trouble. Naturally, the survey is bogus. Among the fields to fill out are several demanding Chase card number, PIN, Social Security number, and other private information.

"Scammers are looking for new ways to fleece the unwary, and this time [they] have come up with a new twist: asking people to help in a survey for a cash reward," said Graham Cluley, senior technology consultant for Sophos, a British security company, in a statement.

Astute users will likely notice that the URL in the phished message is a raw IP address, not a domain. That, said Netcraft, is a strong sign of a phish.

The same CCBC Shanghai server was also used Saturday to host a page that spoofed the eBay log-in screen.

China Construction Bank Corp., one of the country's "Big Four" state-owned banks, has more than 14,200 branches across China.

E-mail This Story
Print This Story
Reprint This Story




Get the latest Personal Tech news, product info, and trends every week.


Related Content

  Right-click and choose Copy to extract RSS Feed URL  Personal Tech Pipeline's Main RSS Feed
  Right-click and choose Copy to extract RSS Feed URL  Personal Tech Pipeline's Blog RSS Feed



Keeping Up To Date On Enterprise Server Tech?
Review our compilation of columns on server security, database software, and Linux issues.
How to Achieve High Performance Through IT
Learn to achieve high performance by aligning IT to
strategic objectives and solutions to unlock that value.
Using Current Performance to Shape
Future Results

Hear new strategies for improving business
performance and results.

Editor's Picks

Well, Microsoft has "unfolded" its "Origami" ultra-mobile PC platform Thursday. It turned out to be a full-featured PC smaller than a tablet but bigger than a PDA. Are you impressed?
Yes! I want one!
Sort of. We'll see.
No! It's too big for a pocket and too small for real computing. What's the point?


In search of personal tech products? See our new Product Finder, where you'll find personal computing devices, communications solutions, security products, and more.



PERSONAL TECH PIPELINE MARKETPLACE (sponsored links)
Trend Micro Enterprise Anti-Spyware Solutions
"Trend Micro is delivering what enterprise customers want." -The Forrester WAVE/Enterprise Anti-Spyware, Q1 2006/Forrester 2006. Download a FREE 30-day trial of Trend Micro Anti-Spyware Solutions for Enterprise Today.

Prevent Information Leaks from your Network
With GTB Inspector Appliance. Free Trial (March 2006 only). GTB Inspector is a hardware appliance. It is installed easily and transparently on the network edge and prevents leaks of confidential information to the Internet.

Cost-Effectively Secure Sensitive Data
Encrypting data in servers and databases can address security gaps and privacy legislation. Ingrian DataSecure Platforms offer granular encryption, seamless integration, and centralized security management. Combat data theft--with unprecedented ease and cost effectiveness. Download a white paper that outlines best practices for securing data.

Symantec Backup Solutions
Desktop to Data Center Protection. Explore the Official Symantec Site.

cost-effective Web server security
$200 discount coupon available now for the purchase of dotDefender, a website security solution that is available for a 30-day evaluation period. dotDefender supports Apache, IIS and iPlanet Web servers and all Linux Operating Systems.


Buy a Link Now


Top ten search terms from the TechWeb TechEncyclopedia
Stellent eSeminar "Approaches to Metadata Design" on March 23
Mobilized Solutions Guide: Find and compare solutions for your business
Top Requested White Paper Categories from TechWeb White paper Library
Top ten search terms from the TechWeb TechEncyclopedia