HomeSecurityFirstBank customers targeted by Phishing campaign

FirstBank customers targeted by phishing campaign

FirstBank customers are being targeted by cybercriminals, who are sending fraudulent messages attempting to collect log-in information for the online banking service.

FirstBank Phishing Campaign

An email from a bank informing about potential fraudulent activity detected in someone's bank account prompts the user to take hasty action. This is exactly what cybercriminals rely on when sending phishing emails.

It is important to note that there are two financial institutions with the name FirstBank, one operating in the USA, in Arizona, Colorado and California, while the other operating in Africa (First Bank of Nigeria) and is one of the largest banks on the continent.

From a sample email, it is clear that the scammers are targeting the second bank, as evident from the malicious link provided, as well as the graphics inserted into the notification to make it appear legitimate.

On the other hand, if the message reaches US users , there is a risk that they will not pay attention to these details and cybercriminals will likely gather more evidence than they expected.

The subject line of the email is not suspicious, but the body of the message informs that irregular activities have been detected and that the beneficiary has not completed validation with the bank, as required by a recent security upgrade. Therefore, it states that protective measures should be taken to prevent access to the online account.

However, as stated in the email , should the beneficiary choose to complete the necessary information for identity verification and validation, the account will be unlocked. “Non-compliance will result in account deactivation,” the message informs.

The scammers want to make sure that these campaigns will not be blocked by spam filters and advise the potential victim to move the message to the inbox if it ended up in junk or spam.

The link leading to the fake form where victims are expected to enter their financial and personal information is hosted on a Russian domain. At the moment, the page is no longer available and it appears that the hosting domain is for adult content.

Although an English speaker may notice the poor grammar in the message, others may not be able to spot the errors. Anyone who has fallen for phishing is advised to change their password on their online account without delay.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS