An ongoing large-scale phishing campaign is targeting Citibank customers, asking recipients to reveal sensitive personal information to lift alleged account freezes.
See also: Phishing method bypasses MFA with remote access software

The campaign uses emails that feature CitiBank logos, sender addresses that at first glance appear authentic, and content that does not contain typographical errors.
CitiBank customers targeted in these phishing attacks are informed that their account has been suspended due to a suspicious transaction or login attempt by someone else.
Because of this, the attackers claim that they should take urgent steps to verify their accounts to avoid permanent suspension.
If they click on the embedded button, victims are taken to a website that resembles a real Citibank portal, where they are asked to log in to their online account.
Of course, any ID and password pairs entered on this site go directly to the threat actors, who can then use the stolen credentials to hack into bank accounts and empty them.
See also: Phishing campaign targets users of the Monzo banking platform
Bitdefender was monitoring this campaign and shared the relevant report citing the following statistical findings:
- 81% of phishing emails in this campaign target American users
- 40% of these emails were sent from US IP addresses and 13% from Mexico
A parallel, less convincing effort
In addition to the tactic of creating urgency to force recipients to miss the obvious signs of fraud and take action, phishing actors also use lures that promise huge profits.
More specifically, Bitdefender detected another phishing campaign whose distribution peaked between February 11 and 15, 2022, providing recipients with the opportunity to claim financial compensation from the United Nations.
The trick used in this case is to identify the recipient as a victim of fraud and that they are one of 150 who were deemed eligible for $5,000,000 in compensation through Citibank.

In other cases, threat actors double the amount to $10,500,000 and try to include more details in the email to convince the victim of its validity.

However, in both cases, the fraud should be more than obvious, as that is not how compensation works.
See also: Lazarus: In its new phishing campaign it impersonates Lockheed Martin
Banks rarely notify users of important developments in their account via SMS or email, so whenever you receive such a message, call your bank and find out exactly what is happening.
Do not call the phone numbers provided in the email, but instead visit the bank's official website and check the contact details on the contact page.
Finally, never click on buttons embedded in the body of the email and always check the URL you are on when preparing to enter your credentials.
Information source: bleepingcomputer.com
