ANZ Bank customers in Australia and New Zealand were tricked into providing their online banking credentials by a fake notification claiming their accounts needed to be re-verified.
Following the standard pattern, malicious emails create a sense of urgency for the user, informing them that in less than 24 hours they must send their details to the bank.
For convenience, a link is provided in the message, which points to a malicious version of the bank's log-in page.
Users who fall into the trap are redirected to the original website after attempting to access their bank account through the fake page. Hoax-Slayer notes that this process deceives users into believing that the process is complete. This will prevent them from reporting the fraud, ensuring an increased lifespan for the malicious campaign.
However, by the time they fall into the trap, the credentials have already been sent to cybercriminals, who can then hack into the user's bank account if two-factor authentication (2FA) is not enabled via a Security Device offered by the bank.
It is highly recommended to use additional forms of authentication beyond username and password. 2FA is a supplementary form of authentication that is more difficult to breach, especially when a physical token is used, rather than a mobile device.

