Home » Reference » Glossary - Computing » Phishing » Anti-Phishing Working Group » 

Phishing Attack: Citibank - īSafeguard your accountī

This phish uses some interesting and dangerous tricks.

The message itself is simple but effective in inciting urgency into the potential victim. The sender address is spoofed (it looks like it really comes from Citibank, while it does not), but the URL link is not hidden. This could raise suspicion, although the message does mention use of a separate server for the īcheckī:

citi e-mail

The phish site does look the way a Citibank page would look. It does not demand excessive amounts of information, and when you try to type in a bogus CC number, it rejects it. All this seems to point toward the conclusion that this is really a legitimate Citibank site:

phished citi

However, it is not. It does check the credit card number using a publicly available formula (Yes, even you can tell if a CC number a valid one, if you know the formula - click here for more information). Of course, the phisher can not check whether this is a real cardīs number, or (even less) whether itīs your CC number (this is why they phish you in the first place :) ).

But if a real username / password had been entered, the login would have proceeded with no problem. This way, the phish could pass TOTALLY unnoticed.

The suspicious URL remains in the address bar. The phish server is hosted on a server in Hubei Province, China.  Phish website on IP: 219.138.133.5


Mail this pageMail this page

Sponsored Links:
AVG 7.0
2 years of protection and all the technical support you need to successfully protect yourself.