Royal Bank of Scotland 's online services have recently suffered several outages: one due to a distributed denial-of-service (DDoS) attack and the other due to technical issues. Shortly afterwards, the financial institution issued a warning to users about the possibility of phishing attacks in the aftermath.
As expected, cybercriminals have begun sending phishing emails designed to trick RBS customers and steal their personal information.
One such email, reported on millersmiles.co.uk, includes “Security Precaution” in the subject line.
"We notice that your card-related online services have been registered on a different ISP server, so access to your online service has been blocked. To reactivate your account, click on the 'ACTIVATE MY CARD' reference link and follow the required steps," the message states.
It then writes "Note: failure to do so will lead to permanent service suspension."
Of course, the email is not related to RBS. Users who click on the 'ACTIVATE MY CARD' link are taken to a compromised website owned by a company from Poland.
The website has been created to host a RBS . Here, victims are asked to enter credit card details, such as their name, PIN, internet password, email address and email address password.
Once this process is complete, the victim is taken to the genuine RBS website.
To ensure that you are on the legitimate website, check the URL in your browser's address bar. The login page on the legitimate site is protected by an SSL certificate (indicated by a green bar and a padlock icon).

