Home Cybersecurity Aggressive Phishing Attack Targeting TSB Banking Customers Is Among Most Witty Way of Stealing Money

Aggressive Phishing Attack Targeting TSB Banking Customers Is Among Most Witty Way of Stealing Money

Posted: June 5, 2018

tsb bank phishing attackFollowing a potentially botched system just before an update, the UK-based TSB bank has succumbed to an aggressive phishing attack that has resulted in many customers having their accounts robbed for money.

The phishing attack is one that harkens back to the traditional model of sending out an aggressive phishing email that redirects users to a bogus TSB banking website. Where the cleverness of the phishing attack takes place is within the exceptional creativity of the hackers running the TSB banking phishing scam.

Those victimized through a spam or phishing email claiming to be from TSB bank leverages TSB's recent issue they had when updating their system recently. Many customers know of the update, and the phishing email will pretend to be a message notifying users that their "issues resolved." From there, the phishing email asks users to follow their secure page to complete account restoration. The interesting part of this step is that users are redirected to a secure site using the HTTPS (secure) protocol, which for most is enough for them to feel comfortable in entering their account login details.

The video below from Salted Hash takes us through the process in real-time revealing how the hackers can steal, or phish, login details along with a customer mobile number and their mothers maiden name. As you may know, having a mother's maiden name and mobile number will arm the hackers with enough information to not only log into the account online, but they could later call into the TSB bank and make transactions. In fact, many TSB banking customers have reported instances of their accounts being cleared out of their hard earned money due to this phishing attack.

Salted Hash video of TSB Bank phishing attack live demonstration

Have you ever encountered such a clever phishing attack? Do you check or verify that your banking website URL is the correct one? If not, you may want to start doing so before it's too late and you're the next victim of a phishing campaign similar to the TSB banking attack.

Loading...