As with anything the bad guys do, they react to anything we do to try to prevent them from having success. One of the things we told our users was to ignore alerting messages that their bank (and any other bank they are not a customer of) seems to send them and tells them their account has been abused. It seems that it is finally having it's effect as the phishers are changing tactics.
These kind of arms races require us to increase awareness constantly and to make users more resilient all the time. If we fail this our users, customers, ... will fall prey and we will have failed our users and/or customers in the end.
From: Chase Manhattan Bank
To: victim@example.com
Subject: [ $20 Reward Survey ]
Dear Chase Bank Customer,
CONGRATULATIONS!
You have been chosen by the Chase Manhattan Bank online department
to take part in our quick and easy 5 question survey.
In return we will credit $20 to your account - Just for your time!
Helping us better understand how our customers feel benefits everyone.
With the information collected we can decide to direct a number of
changes to improve and expand our online service.
We kindly ask you to spare two minutes of your time
in taking part with this unique offer!
SERVICE: Chase Online? $20 Reward Survey
EXPIRATION: March - 13 - 2006
Confirm Now your $20 Reward Survey with Chase Online? Reward
services.
The information you provide us is all non-sensitive and anonymous
No part of it is handed down to any third party groups.
It will be stored in our secure database for maximum of 3 days
while we process the results of this nationwide survey.
Please do not reply to this message. For any inquiries, contact
Customer Service.
Document Reference: (87051203)
Copyright 1996 - 2006 Chase Bank, N.A. Member FDIC Copyright © 2006
It was formatted much more fancy in html, but I chose not to show that here.
Of course the link in there doesn't go to anything owned by JPMorgan Chase & Co.
Now let's have a look at that website collecting so called "non-sensitive and anonymous" information.
It starts out all rather innocent

but then it goes on to ask you more details. Details that are far from non-sensitive and anonymous. But remember the psychology: the user just has answered a whopping 5 questions and is now going to get his 20 bucks. He'll even sell his mother for it, or at least tell them her name along with what is going to cost him much more than that 20 bucks he'll never get.
The details they want to know:

chaseonline.new-reward-survey.us. 600 IN CNAME premium.geo.yahoo.akadns.net.
premium.geo.yahoo.akadns.net. 300 IN A 66.218.79.174
premium.geo.yahoo.akadns.net. 300 IN A 66.218.79.175
premium.geo.yahoo.akadns.net. 300 IN A 66.218.79.177
premium.geo.yahoo.akadns.net. 300 IN A 66.218.79.184
premium.geo.yahoo.akadns.net. 300 IN A 66.218.79.185
premium.geo.yahoo.akadns.net. 300 IN A 66.218.79.186
premium.geo.yahoo.akadns.net. 300 IN A 66.218.79.188
premium.geo.yahoo.akadns.net. 300 IN A 66.218.79.173
Login here to post a comment. Diary Archive