{"id":418135,"date":"2026-09-24T17:32:11","date_gmt":"2026-09-24T17:32:11","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=418135"},"modified":"2026-09-24T17:32:11","modified_gmt":"2026-09-24T17:32:11","slug":"fake-netbank-login-pages-copy-commbank-new-design","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/fake-netbank-login-pages-copy-commbank-new-design\/","title":{"rendered":"Fake NetBank Login Pages Copy CommBank&#8217;s New Design"},"content":{"rendered":"<p>A familiar login page can become less familiar overnight. When a bank updates its design, customers expect buttons, colors, and layouts to move, which creates a brief moment when almost anything new can feel plausible.<\/p><div id=\"mwtad1867637476\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Phishing operators understand that gap. A text or email does not need to copy yesterday\u2019s NetBank screen if it can claim that today\u2019s unfamiliar screen is the official redesign.<\/p>\n<p>This report looks at why the timing matters, what the copied page is built to collect, and how to verify the real service without trusting the message that brought you there.<\/p><div id=\"mwtad904580585\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<figure class=\"wp-block-image size-full\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-netbank-login-pages-copy-new-design-1.png\" class=\"wp-image-418136 skip-lazy\" loading=\"eager\" alt=\"Realistic reconstruction of a phishing text claiming that a new NetBank login must be verified\" width=\"1200\" height=\"675\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-netbank-login-pages-copy-new-design-1.png 1200w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-netbank-login-pages-copy-new-design-1-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-netbank-login-pages-copy-new-design-1-1024x576.png 1024w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><\/figure>\n<div id=\"mwtad1377848934\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>What CommBank is warning about<\/h3>\n<p>Commonwealth Bank began rolling out a refreshed NetBank experience in September 2026. The bank warned that scammers may copy the new look to make fake login pages more convincing.<\/p>\n<p>The lure can arrive through an email or text message containing a link. The destination resembles NetBank and encourages the recipient to enter login or other sensitive information.<\/p>\n<h3>Why the redesign helps the phisher<\/h3>\n<p>People often spot phishing because something looks wrong. A redesign weakens that instinct temporarily. A different sign-in panel, unfamiliar wording, or moved security notice may seem like part of the bank\u2019s update rather than evidence of a fake page.<\/p><div id=\"mwtad3296878365\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The scammer does not need an exact copy. The victim may fill in the missing credibility by remembering that the bank announced a new experience.<\/p>\n<h3>The safe route to NetBank<\/h3>\n<p>CommBank\u2019s advice is direct: do not use a link in an email or text to log in. Open the official app, type the bank\u2019s address yourself, or use a trusted bookmark created from the genuine site.<\/p>\n<ul>\n<li>A message link is not a safe NetBank shortcut.<\/li>\n<li>The visible page design does not prove who controls the domain.<\/li>\n<li>NetBank credentials, card details, and security codes should not be entered after an unsolicited message.<\/li>\n<li>A copied redesign may still send information directly to a criminal.<\/li>\n<li>If details were entered, contact CommBank through the app or official website immediately.<\/li>\n<\/ul>\n<div id=\"mwtad1766724012\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>The Real Redesign Is Not an Invitation to Click<\/h2>\n<p>The bank\u2019s update is genuine. The message that references it may not be. That distinction is the center of the scam.<\/p><div id=\"mwtad1657039247\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Phishers frequently build their stories around real events because those events survive a quick search. A customer who searches \u201cnew NetBank design\u201d will find authentic CommBank information, but that does not validate the link in the original text.<\/p>\n<p>The official <a href=\"https:\/\/www.commbank.com.au\/support\/security\/latest-scams-and-security-alerts.html\" rel=\"nofollow noopener\" target=\"_blank\">CommBank security alert<\/a> says scammers may copy the new design and distribute fake login links through emails or text messages. The bank tells customers to navigate to the official website or netbank.com.au themselves.<\/p>\n<div id=\"mwtad3805261226\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>A padlock icon is not enough. HTTPS only means the connection to that particular site is encrypted. It does not mean CommBank owns the site, reviewed the form, or will receive the information.<\/p>\n<p>Search advertisements can add another problem. A sponsored result may appear above the genuine bank result. For account access, use a saved official app or a bookmark you created after independently verifying the address.<\/p>\n<div id=\"mwtad3126379866\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Fake NetBank Login Scam Works<\/h2>\n<h3>Step 1: A message gives the redesign a reason<\/h3>\n<p>The email or text may say the customer must confirm a new login, migrate to the updated NetBank, review a security hold, accept new terms, or verify a recent transaction.<\/p>\n<div id=\"mwtad1078495101\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>Each version creates a reason to sign in immediately. The redesign explains why the destination may not look exactly like the page the customer remembers.<\/p>\n<h3>Step 2: The link hides the real destination<\/h3>\n<p>The visible text can say CommBank or NetBank while the underlying address leads somewhere else. Shortened links, redirect services, compromised websites, and domains containing familiar words can make the route difficult to judge at a glance.<\/p>\n<p>On a mobile screen, the complete address may be hidden. The page can also open inside an in-app browser that shows less of the normal browser interface.<\/p>\n<h3>Step 3: A copied page collects the first credentials<\/h3>\n<div id=\"mwtad1058184762\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>The fake page asks for a client number and password, or other identifying details. It may include professional spacing, help links, a security message, and a loading animation.<\/p>\n<p>Pressing \u201cLog on\u201d sends the information to the operator. An error can then appear so the victim assumes the password was mistyped and enters it again.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-netbank-login-pages-copy-new-design-2.png\" class=\"wp-image-418137 skip-lazy\" loading=\"lazy\" alt=\"Realistic reconstruction of a fake NetBank login page copying the layout of a newly redesigned banking portal\" width=\"1200\" height=\"675\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-netbank-login-pages-copy-new-design-2.png 1200w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-netbank-login-pages-copy-new-design-2-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-netbank-login-pages-copy-new-design-2-1024x576.png 1024w\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" \/><\/figure>\n<h3>Step 4: The second screen asks for stronger proof<\/h3>\n<p>A phishing page may ask for a card number, PIN, security answer, NetCode, one-time code, or identity details. The exact request can change according to what the operator is trying to access.<\/p>\n<p>A one-time code is especially valuable because it may expire quickly. That is why the page may show a timer or claim that verification is in progress.<\/p>\n<h3>Step 5: The victim is kept busy while access is attempted<\/h3>\n<p>The final page can display a spinner, maintenance message, or \u201cverification complete\u201d notice. That delay reduces the chance that the victim will immediately open the real app and notice unfamiliar activity.<\/p>\n<p>Information captured from the page may be used to attempt account access, card transactions, identity fraud, or enrollment of another service. The outcome depends on what was entered and which protections the bank triggers.<\/p>\n<h3>Step 6: A follow-up call can continue the impersonation<\/h3>\n<p>If the operator also captured a phone number, a caller may pretend to be from the bank\u2019s fraud team. The caller already knows that the victim saw a NetBank message and may repeat some of the details entered on the fake page.<\/p>\n<p>The goal may be to obtain another security code, persuade the customer to approve an action, or move money. End the call and contact the bank independently.<\/p>\n<div id=\"mwtad3579644115\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>The Domain Matters More Than the Design<\/h2>\n<p>A phishing kit can copy visible elements in minutes. It can reproduce headings, form labels, error messages, and security language. The browser address is harder to copy because the scammer does not control CommBank\u2019s genuine domain.<\/p>\n<p>Look at the registrable domain, not just a familiar word somewhere in a long address. A domain such as \u201cnetbank-secure-example.com\u201d is controlled by whoever registered that domain, not by the owner of netbank.com.au.<\/p>\n<p>Do not use a link checker as permission to log in. A new phishing page may not yet appear on blocklists. Independent navigation avoids the suspicious route entirely.<\/p>\n<p>MalwareTips recently covered <a href=\"https:\/\/malwaretips.com\/blogs\/fake-commbank-car-giveaway-ads\/\">fake CommBank car giveaway ads<\/a> that also sent people toward copied banking pages. The pretext changes, but the destination still depends on the customer trusting a login screen reached through an untrusted link.<\/p>\n<p>A real interface change gives criminals a ready-made explanation for anything unfamiliar. A different color, a new button, or another verification screen no longer feels suspicious when customers already expect the service to look different.<\/p>\n<p>The scam message may arrive soon after genuine news about the redesign. That timing does not prove the sender has access to a customer list. Phishers can send the same message widely and wait for real CommBank customers to respond.<\/p>\n<p>They can also use public screenshots and marketing pages to copy visible details. A logo, font, or layout is not secret banking information. The copy may look convincing even when the criminal has never seen the victim&#8217;s account.<\/p>\n<p>The most useful check happens before the page opens. Did you reach NetBank through a bookmark or the official app, or did a text create urgency and choose the destination for you?<\/p>\n<p>Do not use the message as a shortcut, even if it says the account will be restricted. Open the app yourself and look for an alert there. If the issue is real, support can confirm it through a number you already trust.<\/p>\n<p>This habit removes the scammer&#8217;s strongest advantage. The criminal can copy a screen, but cannot make a link in an unsolicited message become the bank&#8217;s official domain.<\/p>\n<div id=\"mwtad1230881052\" class=\"gas_fallback-ad_381388-ad_309685-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Red Flags in a NetBank Login Message<\/h2>\n<p>A polished message can still be fraudulent. Pay attention to the action it demands and the route it wants you to use.<\/p>\n<ul>\n<li>The message arrives unexpectedly and contains a sign-in link.<\/li>\n<li>It says the new design requires immediate account verification.<\/li>\n<li>The sender creates urgency around a lock, transaction, refund, or security deadline.<\/li>\n<li>The link opens a domain other than CommBank\u2019s verified addresses.<\/li>\n<li>The page asks for a PIN, complete card details, or repeated one-time codes.<\/li>\n<li>The form displays an error regardless of what is entered.<\/li>\n<li>A caller follows up and asks the customer to read back a security code.<\/li>\n<li>The caller objects when the customer says they will use the official app instead.<\/li>\n<\/ul>\n<div id=\"mwtad551180166\" class=\"gas_fallback-ad_381392-ad_309685-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Company and Checkout Checks<\/h2>\n<h3>Confirm the domain independently<\/h3>\n<p>Do not compare the link with the message. Compare it with the address published by CommBank. Open the official app or type the known address yourself. Close the linked page rather than trying to prove it is genuine.<\/p>\n<h3>Check who sent the message<\/h3>\n<p>A display name can be forged, and scam messages may appear in an existing SMS thread. The sender name is not authentication. Treat every unexpected login link as untrusted even when the conversation looks familiar.<\/p>\n<h3>Separate bank support from the page<\/h3>\n<p>Use the phone number on the back of your card, the official app, or the contact page you reached independently. Do not call a number shown in the phishing message, pop-up, or fake login page.<\/p>\n<h3>Review what the form requested<\/h3>\n<p>Write down which credentials, card details, codes, and identity information were entered. This helps the bank protect the right services. Do not revisit the phishing page to collect that list if doing so may expose the device again.<\/p>\n<div id=\"mwtad574809546\" class=\"gas_fallback-ad_381392-ad_309685-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li><strong>Contact CommBank immediately.<\/strong> Use the official app, number on your card, or verified website. Tell the bank exactly what you entered and whether you approved any action.<\/li>\n<li><strong>Lock affected cards and accounts.<\/strong> Follow the bank\u2019s instructions for card replacement, password reset, digital-wallet review, and removal of unknown devices.<\/li>\n<li><strong>Change the NetBank password from a clean route.<\/strong> Do not use the message link again. Replace any password reused on email, shopping, or other financial accounts.<\/li>\n<li><strong>Review transactions and security notifications.<\/strong> Look for unfamiliar transfers, card charges, payees, wallet registrations, and changes to contact details.<\/li>\n<li><strong>Protect your email account.<\/strong> Change its password, enable multi-factor authentication, review forwarding rules, and sign out sessions you do not recognize.<\/li>\n<li><strong>Scan the device if anything was downloaded.<\/strong> A login form alone does not always install malware, but attachments and fake security apps can. Malwarebytes can help check for credential stealers and malicious browser extensions.<\/li>\n<li><strong>Preserve and report the message.<\/strong> Save a screenshot, sender details, full URL, and time. Report it to CommBank and the messaging or email provider.<\/li>\n<li><strong>Watch for follow-up impersonation.<\/strong> Criminals may call using the information already captured. Do not share a code or move money because a caller knows details about the incident.<\/li>\n<\/ol>\n<p>AdGuard can help block known phishing domains, malicious advertisements, and some redirect chains. It provides another layer, but the safest habit is never to reach online banking through an unsolicited link.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-netbank-login-pages-copy-new-design-3.png\" class=\"wp-image-418138 skip-lazy\" loading=\"lazy\" alt=\"Realistic reconstruction of a fake NetBank verification page requesting a one-time security code\" width=\"1200\" height=\"675\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-netbank-login-pages-copy-new-design-3.png 1200w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-netbank-login-pages-copy-new-design-3-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-netbank-login-pages-copy-new-design-3-1024x576.png 1024w\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" \/><\/figure>\n<h2>How to Use NetBank Without Trusting a Message<\/h2>\n<p>Open the official banking app from the icon you already use. If you prefer a browser, type the address yourself or use a bookmark created from a verified page.<\/p>\n<p>Once inside the real service, review alerts and recent activity there. If the message described a genuine issue, the bank\u2019s authenticated environment should provide a safe route to investigate it.<\/p>\n<p>Do not be embarrassed if the copied redesign looked convincing. The bank itself warned that scammers may exploit the new appearance. Speed matters more than blame after credentials have been entered.<\/p>\n<p>Finally, keep the device and browser updated. Security updates and phishing protection cannot identify every new page, but they reduce the number of ways a malicious link can turn a credential theft attempt into a wider device compromise.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Did CommBank really redesign NetBank?<\/h3>\n<p>Yes. CommBank began rolling out a refreshed NetBank experience in September 2026. That genuine change is why the bank warned about criminals copying the new design.<\/p>\n<h3>Can CommBank send legitimate messages?<\/h3>\n<p>Banks can send notifications, but an unexpected message should not be used as a login route. Open the official app or website independently to check the account.<\/p>\n<h3>Does HTTPS prove a NetBank page is real?<\/h3>\n<p>No. HTTPS encrypts the connection to the displayed domain. A phishing operator can also obtain HTTPS for a fraudulent domain.<\/p>\n<h3>What if I entered my password but no security code?<\/h3>\n<p>Contact CommBank and change the password immediately. Also change it anywhere else it was reused and review the account for unfamiliar activity.<\/p>\n<h3>What if the text appeared in a real CommBank thread?<\/h3>\n<p>Do not trust the thread placement alone. Sender IDs can be spoofed or messages can be grouped unexpectedly. Verify through the official app.<\/p>\n<h3>Should I call the number shown on the fake page?<\/h3>\n<p>No. Use the number on the back of your card or contact options in the official CommBank app or website.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The real NetBank redesign does not make a message link safe. It gives phishers a timely explanation for why their copied page may look unfamiliar.<\/p>\n<p>Skip the link, open NetBank through a route you control, and contact the bank immediately if credentials or codes were entered. The design can be copied. The verified domain and official app are the checks that matter.<\/p>\n<div id=\"mwtad1725481693\" class=\"gas_fallback-ad_176819-ad_309685-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A familiar login page can become less familiar overnight. When a bank updates its design, customers expect buttons, colors, and layouts to move, which creates a brief moment when almost anything new can feel plausible. &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Fake NetBank Login Pages Copy CommBank&#8217;s New Design\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/fake-netbank-login-pages-copy-commbank-new-design\/#more-418135\" aria-label=\"Read more about Fake NetBank Login Pages Copy CommBank&#8217;s New Design\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":418136,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-418135","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/418135","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=418135"}],"version-history":[{"count":2,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/418135\/revisions"}],"predecessor-version":[{"id":418496,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/418135\/revisions\/418496"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/418136"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=418135"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=418135"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=418135"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}