
...and more!
|
|
Bogus Email Sent - As If From CitiBank (8-24-04)
|
| Citibank.message@emailmessage.citibank.com using -f Date: Tue, 24 Aug 2004 10:04:49 +0500 From: Citibank Support <Citibank.message@emailmessage.citibank.com> Subject: ATTN: Immediate attention required (Citi.com) To: citibankcustomer@aol.com X-IMAIL-SPAM-DNSBL: (SpamCop,c1a7ed62004e087688,127.0.0.2) X-IMAIL-SPAM-VALFROM: (c1a7ed62004e0789) X-RCPT-TO: dmail.com> Content-Type: text/html; CITIBANK(R) Dear Citibank Customer: Recently there have been a large number computer terrorist attacks over our database server. In order to safeguard your account, we require that you update your Citibank ATM/Debit card PIN. This update is requested of you as a precautionary measure against fraud. Please note that we have no particular indications that your details have been compromised in any way. This process is mandatory, and if not completed within the nearest time your account may be subject to temporary suspension. Please make sure you have your Citibank ATM/Debit card and your login details at hand. To securely update your Citibank ATM/Debit card PIN please go to: Customer Verification Form ( <--- Bogus/Fraudulent Link) Please note that this update applies to your Citibank ATM/Debit card - which is linked directly to your checking account, not Citibank credit cards. Thank you for your prompt attention to this matter and thank you for using Citibank! Regards, Customer Support __________________________________________________________ >> Let your home pay for something now. And down the road... >> Get $50+ To apply now, please visit: http://tracking.citibank.com/cbol/_recon2.asp?o=50AP ---------------------------------------------------------- (C)2004 Citibank. Citibank, N.A., Citibank, F.S.B., Citibank (West), FSB. Member FDIC.Citibank and Arc Design is a registered service mark of Citicorp |
What happens next:
When the email recipient clicks on the "Customer Verification Form" link, they are directed to CitiBank's website, with a Pop Up Window that appears in front of a legitimate CitiBank webpage.
This dupes the customer into thinking that the
Pop Up is a legitimate part of the website, where they need to fill in
their account information. |
![]() |
After you've filled in their Bogus/Scam form they politely thank you, and tell you to close the window - for your security of course! - and this leaves the customer with a legitimate citibank window open, making it appear as though you've filled out a legitimate citibank form. |
![]() |

