Security News Researchers Find 300+ Fake UK Banking Sites

Bot

AI-powered Bot
Thread author
Apr 21, 2016
4,367
Hackers have registered over 300 domains with names similar to those of several popular British banks, which they use to trick customers into handing over personal details or login data.

According to DomainTools, a company handling domain name and DNS-based cyber threats, 324 such domains were discovered only in relation to banks in the United Kingdom, namely Barclays, HSBC, Natwest, Lloyd's and Standard Chartered.

For its discovery, the company used its PhishEye tool which allows users to search for existing bad new domains that spoof legitimate brand, product, organization, or other names.

"Imitation has long been thought to be the sincerest form of flattery, but not when it comes to domains. Domain squatters use squatted domain names to administer and run phishing, drive-by download, or revenu... (read more)
 
Last edited by a moderator:

frogboy

In memoriam 1961-2018
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
Researchers have discovered over 300 cybersquatting domains masquerading as real UK banking sites, many of which are designed to trick customers into handing over personal details.

DomainTools used its PhishEye tool to search for domains registered by individuals to mimic those of Barclays, HSBC, Natwest, Lloyd’s and Standard Chartered.

It found a whopping 324 registered domains abusing the trademarks of these lenders, including lloydstbs[.]com, standardchartered-bank[.]com and barclaysbank-plc[.]co.uk.

“Imitation has long been thought to be the sincerest form of flattery, but not when it comes to domains,” explained DomainTools senior security researcher, Kyle Wilhoit. “While domain squatters of the past were mostly trying to profit from the domain itself, these days they’re often sophisticated cyber-criminals using the spoofed domain names for more malicious endeavors.”

Cybersquatting can be used for a variety of ends, including redirecting the user to pay-per-click ads for the victim company’s competitors; for-profit survey sites, or ransomware and other forms of drive-by malware.

Full Article. Researchers Find 300+ Fake UK Banking Sites
 

Winter Soldier

Level 25
Verified
Top Poster
Well-known
Feb 13, 2017
1,486
I think if you have an online banking account, it is always better to directly type the correct bank's URL in the browser to avoid any problems.
 
Last edited:
  • Like
Reactions: frogboy and BugCode

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
If you use a password manager, you will know right away if it is a fake site. You will find that you have zero matching passwords.
 
  • Like
Reactions: Winter Soldier

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top