Appriver Detects HMRC Phishing E-Mail

According to Security Company AppRiver, a newly launched phishing scam is dispatching e-mails supposedly from HMRC notifying of a tax refund.

Addressing the recipient i.e., the person paying taxes, the phishing message informs him that a tax re-imbursement of 3,997.32 GBP has been computed in his favor. Also, it informs that to process the tax refund, the Internet banking details of the recipient are required. Hence, he must answer back in 72 hours from the time of getting the e-mail. Moreover, the electronic message warns that in case of failure to provide the necessary information, HMRC will not initiate the tax refund amount that he's liable to get.

Subsequently, the e-mail asks the recipient to follow a given web-link. But on clicking it, the user is first led onto a preliminary landing page and from there he's instantly diverted onto the main phishing site which's an illegitimate copy of the HMRC's original website.

This phishing site exhibits 10 financial service firms' logos. These firms are Lloyds, Barclays, HSBC, Abbey, Halifax, RBS, TSB, NatWest and Alliance Leicester, egg and cahoot. The site directs the user to double-click on the logo which indicates his bank. But the logos are connected with phishing pages that are actually fake copies of the analogous financial service firms' Internet banking systems.

Note investigators at AppRiver that these web-pages appear trustworthy because their creators have lifted the images on them from the original websites of the institutions. Consequently, when users enter their passwords and other log-in credentials into the pages, the details end up into the hands of cyber-fraudsters instead of the bank. Softpedia.com reported this on July 28, 2010.

Highlight the researchers that it's not common to have a phishing scam that takes aim at so many financial institutions simultaneously and therefore requires greater effort for establishing the campaign compared to what typical phishers invest. This is as well why the scammers have utilized redirect codes prior to landing consumers on the ultimate spoofed website.

Thus the researchers advise recipients of the e-mail to avoid the web-link inside the uninvited message so as to remain protected from the scam.

Related article: AppRiver Reports Security Trends for November 2008

» SPAMfighter News - 09-08-2010

 

All SPAMfighter products offer a free trial!

SPAMfighter box shot

SPAMfighter is a free spam filter for Outlook, Outlook Express,Windows Mail, Windows Live Mail and Thunderbird.

SLOW-PCfighter

Optimize your Slow PC for better performance. Try FREE scan now

Full disk or slow disk?
Disk space recovery
and disk optimization. Try FULL-DISKfighter free


Spam Filter for Exchange Server

SPAMfighter Exchange Module is a Spam filter for Exchange server - Free 30 days trial.

Remove spyware

Remove Spyware with SPYWAREfighter - Free 30 days trial

Antivirus software

Antivirus software for your Windows PC - Free 30 days trial

<<<  >>> 

Compatible with Windows 7

Works with Windows Vista

SPAMfighter is

Microsoft Gold Certified Partner

Intel Software Partner