Fake NetBank Login Pages Copy CommBank’s New Design

A familiar login page can become less familiar overnight. When a bank updates its design, customers expect buttons, colors, and layouts to move, which creates a brief moment when almost anything new can feel plausible.

Phishing operators understand that gap. A text or email does not need to copy yesterday’s NetBank screen if it can claim that today’s unfamiliar screen is the official redesign.

This report looks at why the timing matters, what the copied page is built to collect, and how to verify the real service without trusting the message that brought you there.

Realistic reconstruction of a phishing text claiming that a new NetBank login must be verified

Overview

What CommBank is warning about

Commonwealth Bank began rolling out a refreshed NetBank experience in September 2026. The bank warned that scammers may copy the new look to make fake login pages more convincing.

The lure can arrive through an email or text message containing a link. The destination resembles NetBank and encourages the recipient to enter login or other sensitive information.

Why the redesign helps the phisher

People often spot phishing because something looks wrong. A redesign weakens that instinct temporarily. A different sign-in panel, unfamiliar wording, or moved security notice may seem like part of the bank’s update rather than evidence of a fake page.

The scammer does not need an exact copy. The victim may fill in the missing credibility by remembering that the bank announced a new experience.

The safe route to NetBank

CommBank’s advice is direct: do not use a link in an email or text to log in. Open the official app, type the bank’s address yourself, or use a trusted bookmark created from the genuine site.

  • A message link is not a safe NetBank shortcut.
  • The visible page design does not prove who controls the domain.
  • NetBank credentials, card details, and security codes should not be entered after an unsolicited message.
  • A copied redesign may still send information directly to a criminal.
  • If details were entered, contact CommBank through the app or official website immediately.

The Real Redesign Is Not an Invitation to Click

The bank’s update is genuine. The message that references it may not be. That distinction is the center of the scam.

Phishers frequently build their stories around real events because those events survive a quick search. A customer who searches “new NetBank design” will find authentic CommBank information, but that does not validate the link in the original text.

The official CommBank security alert says scammers may copy the new design and distribute fake login links through emails or text messages. The bank tells customers to navigate to the official website or netbank.com.au themselves.

A padlock icon is not enough. HTTPS only means the connection to that particular site is encrypted. It does not mean CommBank owns the site, reviewed the form, or will receive the information.

Search advertisements can add another problem. A sponsored result may appear above the genuine bank result. For account access, use a saved official app or a bookmark you created after independently verifying the address.

How the Fake NetBank Login Scam Works

Step 1: A message gives the redesign a reason

The email or text may say the customer must confirm a new login, migrate to the updated NetBank, review a security hold, accept new terms, or verify a recent transaction.

Each version creates a reason to sign in immediately. The redesign explains why the destination may not look exactly like the page the customer remembers.

Step 2: The link hides the real destination

The visible text can say CommBank or NetBank while the underlying address leads somewhere else. Shortened links, redirect services, compromised websites, and domains containing familiar words can make the route difficult to judge at a glance.

On a mobile screen, the complete address may be hidden. The page can also open inside an in-app browser that shows less of the normal browser interface.

Step 3: A copied page collects the first credentials

The fake page asks for a client number and password, or other identifying details. It may include professional spacing, help links, a security message, and a loading animation.

Pressing “Log on” sends the information to the operator. An error can then appear so the victim assumes the password was mistyped and enters it again.

Realistic reconstruction of a fake NetBank login page copying the layout of a newly redesigned banking portal

Step 4: The second screen asks for stronger proof

A phishing page may ask for a card number, PIN, security answer, NetCode, one-time code, or identity details. The exact request can change according to what the operator is trying to access.

A one-time code is especially valuable because it may expire quickly. That is why the page may show a timer or claim that verification is in progress.

Step 5: The victim is kept busy while access is attempted

The final page can display a spinner, maintenance message, or “verification complete” notice. That delay reduces the chance that the victim will immediately open the real app and notice unfamiliar activity.

Information captured from the page may be used to attempt account access, card transactions, identity fraud, or enrollment of another service. The outcome depends on what was entered and which protections the bank triggers.

Step 6: A follow-up call can continue the impersonation

If the operator also captured a phone number, a caller may pretend to be from the bank’s fraud team. The caller already knows that the victim saw a NetBank message and may repeat some of the details entered on the fake page.

The goal may be to obtain another security code, persuade the customer to approve an action, or move money. End the call and contact the bank independently.

The Domain Matters More Than the Design

A phishing kit can copy visible elements in minutes. It can reproduce headings, form labels, error messages, and security language. The browser address is harder to copy because the scammer does not control CommBank’s genuine domain.

Look at the registrable domain, not just a familiar word somewhere in a long address. A domain such as “netbank-secure-example.com” is controlled by whoever registered that domain, not by the owner of netbank.com.au.

Do not use a link checker as permission to log in. A new phishing page may not yet appear on blocklists. Independent navigation avoids the suspicious route entirely.

MalwareTips recently covered fake CommBank car giveaway ads that also sent people toward copied banking pages. The pretext changes, but the destination still depends on the customer trusting a login screen reached through an untrusted link.

A real interface change gives criminals a ready-made explanation for anything unfamiliar. A different color, a new button, or another verification screen no longer feels suspicious when customers already expect the service to look different.

The scam message may arrive soon after genuine news about the redesign. That timing does not prove the sender has access to a customer list. Phishers can send the same message widely and wait for real CommBank customers to respond.

They can also use public screenshots and marketing pages to copy visible details. A logo, font, or layout is not secret banking information. The copy may look convincing even when the criminal has never seen the victim’s account.

The most useful check happens before the page opens. Did you reach NetBank through a bookmark or the official app, or did a text create urgency and choose the destination for you?

Do not use the message as a shortcut, even if it says the account will be restricted. Open the app yourself and look for an alert there. If the issue is real, support can confirm it through a number you already trust.

This habit removes the scammer’s strongest advantage. The criminal can copy a screen, but cannot make a link in an unsolicited message become the bank’s official domain.

Red Flags in a NetBank Login Message

A polished message can still be fraudulent. Pay attention to the action it demands and the route it wants you to use.

  • The message arrives unexpectedly and contains a sign-in link.
  • It says the new design requires immediate account verification.
  • The sender creates urgency around a lock, transaction, refund, or security deadline.
  • The link opens a domain other than CommBank’s verified addresses.
  • The page asks for a PIN, complete card details, or repeated one-time codes.
  • The form displays an error regardless of what is entered.
  • A caller follows up and asks the customer to read back a security code.
  • The caller objects when the customer says they will use the official app instead.

Company and Checkout Checks

Confirm the domain independently

Do not compare the link with the message. Compare it with the address published by CommBank. Open the official app or type the known address yourself. Close the linked page rather than trying to prove it is genuine.

Check who sent the message

A display name can be forged, and scam messages may appear in an existing SMS thread. The sender name is not authentication. Treat every unexpected login link as untrusted even when the conversation looks familiar.

Separate bank support from the page

Use the phone number on the back of your card, the official app, or the contact page you reached independently. Do not call a number shown in the phishing message, pop-up, or fake login page.

Review what the form requested

Write down which credentials, card details, codes, and identity information were entered. This helps the bank protect the right services. Do not revisit the phishing page to collect that list if doing so may expose the device again.

What to Do if You Have Fallen Victim to This Scam

  1. Contact CommBank immediately. Use the official app, number on your card, or verified website. Tell the bank exactly what you entered and whether you approved any action.
  2. Lock affected cards and accounts. Follow the bank’s instructions for card replacement, password reset, digital-wallet review, and removal of unknown devices.
  3. Change the NetBank password from a clean route. Do not use the message link again. Replace any password reused on email, shopping, or other financial accounts.
  4. Review transactions and security notifications. Look for unfamiliar transfers, card charges, payees, wallet registrations, and changes to contact details.
  5. Protect your email account. Change its password, enable multi-factor authentication, review forwarding rules, and sign out sessions you do not recognize.
  6. Scan the device if anything was downloaded. A login form alone does not always install malware, but attachments and fake security apps can. Malwarebytes can help check for credential stealers and malicious browser extensions.
  7. Preserve and report the message. Save a screenshot, sender details, full URL, and time. Report it to CommBank and the messaging or email provider.
  8. Watch for follow-up impersonation. Criminals may call using the information already captured. Do not share a code or move money because a caller knows details about the incident.

AdGuard can help block known phishing domains, malicious advertisements, and some redirect chains. It provides another layer, but the safest habit is never to reach online banking through an unsolicited link.

Realistic reconstruction of a fake NetBank verification page requesting a one-time security code

How to Use NetBank Without Trusting a Message

Open the official banking app from the icon you already use. If you prefer a browser, type the address yourself or use a bookmark created from a verified page.

Once inside the real service, review alerts and recent activity there. If the message described a genuine issue, the bank’s authenticated environment should provide a safe route to investigate it.

Do not be embarrassed if the copied redesign looked convincing. The bank itself warned that scammers may exploit the new appearance. Speed matters more than blame after credentials have been entered.

Finally, keep the device and browser updated. Security updates and phishing protection cannot identify every new page, but they reduce the number of ways a malicious link can turn a credential theft attempt into a wider device compromise.

Frequently Asked Questions

Did CommBank really redesign NetBank?

Yes. CommBank began rolling out a refreshed NetBank experience in September 2026. That genuine change is why the bank warned about criminals copying the new design.

Can CommBank send legitimate messages?

Banks can send notifications, but an unexpected message should not be used as a login route. Open the official app or website independently to check the account.

Does HTTPS prove a NetBank page is real?

No. HTTPS encrypts the connection to the displayed domain. A phishing operator can also obtain HTTPS for a fraudulent domain.

What if I entered my password but no security code?

Contact CommBank and change the password immediately. Also change it anywhere else it was reused and review the account for unfamiliar activity.

What if the text appeared in a real CommBank thread?

Do not trust the thread placement alone. Sender IDs can be spoofed or messages can be grouped unexpectedly. Verify through the official app.

Should I call the number shown on the fake page?

No. Use the number on the back of your card or contact options in the official CommBank app or website.

The Bottom Line

The real NetBank redesign does not make a message link safe. It gives phishers a timely explanation for why their copied page may look unfamiliar.

Skip the link, open NetBank through a route you control, and contact the bank immediately if credentials or codes were entered. The design can be copied. The verified domain and official app are the checks that matter.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Money Mule Job Offers Turn Applicants Into Accomplices

Next

Fake Tribal Tax Credits Put Buyers at IRS Risk