[62165] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: Citibank e-mail looks phishy

daemon@ATHENA.MIT.EDU (Peter Gutmann)
Mon Nov 13 13:27:56 2006

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
From: pgut001@cs.auckland.ac.nz (Peter Gutmann)
To: Carlos.Cid@rhul.ac.uk, cryptography@metzdowd.com
In-Reply-To: <0A738FE79EB90047A7923673A8083FA603C85BB8@exch15.rhul.ac.uk>
Date: Mon, 13 Nov 2006 19:39:44 +1300

"Cid Carlos" <Carlos.Cid@rhul.ac.uk> writes:

>Citibank e-mail looks phishy

I think "Citibank aims at foot and lets loose with both barrels, then reloads
and shoots a second time" would be a better title.  This is a really scary
example of what Perry once referred to as banks actively training users to
become future victims of phishing attacks.  What's even worse is that Citibank
uses such a profusion of marketing-driven vaguely bank-related domain names
(e.g. accountonline.com, although this now seems to have been shut down) that
the email could just as easily have directed users to <random bank-sounding
name>.com without raising too much suspicion.  Any half-awake phisher will
immediately send out an identical email sending people to some other vaguely
correct-looking URL and asking for the same information.

Peter.

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post