Online banking warning!

Messages
10,921
Name
wayne clarke
Edit My Images
Yes
It seems theres a very clever virus attacking those who use online banking, the virus mimics the banks own website when you log on to your bank and collects the data with a very similar page (but asking for a few more details than usual) it even fools the banks on security comfimation software.
So take great care eveybody.
Wayne
 
As always, even if you are slightly unsure, then don't enter any details and call your bank immediately. They'll be able to confirm what you should or shouldn't be seeing!
 
Yes, it's called phishing and they have been doing it for ages.

DON'T log in to a bank's website unless YOU typed the web address in. Don't click links in emails that take you to an address 'similar' to your banks address!
 
Thanks for the heads up :clap: we use online banking
we do have anti virus and firewall but will be extra careful anyway:)
Pete
 
Also, never click a link in an email. Always type in the address/URL in the address bar as you usually do. The scams etc use quite devious looking web addresses that look very similar to the correct ones(eg www.rbss.co.uk or www.na1ionwide.co.uk or www2.nationwide.co.uk......etc. NOTE - these are only examples)


Too slow...... was beaten to it by jontucker
 
Yeah, always check the addresses. They will always link to some dodgy site that might look like the proper address but often are completely different.
Another good thing to do is to send the email and link to the real bank. Usually something like security@rbs.com or somesuch. You'll get a nice thankyou and confirmation email.
 
This is working even if you type in the address, thats the clever part, it puts up a page over the banks own one (somehow) it seems most AV's are not getting it either.

Sorry Mods, just noticed I posted this in the wrong place, thanks for moving.
 
OK, if its a virus that has now been picked up surely the av's are updating against it?
 
This is working even if you type in the address, thats the clever part, it puts up a page over the banks own one (somehow) it seems most AV's are not getting it either.

Sorry Mods, just noticed I posted this in the wrong place, thanks for moving.


Paypal were hacked in a similar way a year or so back, when you went to login you were on the genuine Paypal login page but were then redirected to a fake Paypal site. Very clever,Paypal managed to catch it fairly quickly though.
 
always check before you put in any details that you are encrypted to that web site and read the licence/certificates,firefox and ie8 search bar lights up green if it checks out ok.
 
always check before you put in any details that you are encrypted to that web site and read the licence/certificates,firefox and ie8 search bar lights up green if it checks out ok.

I didn't know that and a wee try shows green on FF but not on IE8?
 
Thanks for that I'll stay off the banks's site for a couple of days till they get it sorted..
 
to be honest i wouldnt panic. as long as your AV is up to date and you dont go downloading anything silly off the internet you should be fine.

i certainly wont stop using internet banking.

still interested to find the source of the OPs post, none of the leading AV sites seem to have anything new listed?
 
It's happened to my brother and one of the guys I work with today, one of the banks was nat west (my brothers) I don't know what the other was for sure but think he's with bank of scotland (or whatever it's called now). Nat west know about it, my brother rang them because he was suspicious of the site, they seemed to know something was going on but wanted more details. It's fooling the banks own safety comfimation as well.
My brothers pc is pretty good on anti virus, he was a tech with ibm so he's knows his stuff with web safety.
 
if its that big im surprised there this isnt more widely known to be honest.

no offence but until there is an official threat update id concider what the natwest "technical support" said as hearsay.
 
It's happened to my brother and one of the guys I work with today, one of the banks was nat west (my brothers) I don't know what the other was for sure but think he's with bank of scotland (or whatever it's called now). Nat west know about it, my brother rang them because he was suspicious of the site, they seemed to know something was going on but wanted more details. It's fooling the banks own safety comfimation as well.
My brothers pc is pretty good on anti virus, he was a tech with ibm so he's knows his stuff with web safety.

I am with HBOS and see no changes to their website. I can only think there might be two possibilities - it is a dodgy link in someone's email (but those you should always check) or someone hacked their site ...
 
Paypal were hacked in a similar way a year or so back, when you went to login you were on the genuine Paypal login page but were then redirected to a fake Paypal site. Very clever,Paypal managed to catch it fairly quickly though.

this is more likely related to DNS poisoning rather than actually hacking the site.
it's really easy to send you to "www.paypal.com" and show you the real site, but redirect "login.paypal.com" (or similar) to a phishing site without actually doing anything to Paypal itself.

just checked all relevant virus/threat reporting sites, and i cant find anything relating to this being a new phenomena. therefore this is likely to relate to the following:
1: SSL injecting (which has been fixed via updates to all major browsers)
2: CSS injecting (also fixed).
3: malware installed onto your computer

i am pretty confident to say this is not a problem with the banking sites, and is not a reason to go all panicy and stop using Internet banking. do you stop using ATM's because someone reports their card stolen ?
 
i am pretty confident to say this is not a problem with the banking sites, and is not a reason to go all panicy and stop using Internet banking. do you stop using ATM's because someone reports their card stolen ?

+1

the problem is that things like this are like the snowball effect, someone gets in a panic and sends an email to all their mates, then all of them send it on and before you know it loads of people arent using online banking.
 
It seems theres a very clever virus attacking those who use online banking, the virus mimics the banks own website when you log on to your bank and collects the data with a very similar page (but asking for a few more details than usual) it even fools the banks on security comfimation software.
So take great care eveybody.
Wayne

Can I ask the OP to clarify something in an attempt to clear this up?

Are you, or whoever has been affected, visiting the bank site

1) via a link in an email,

2) via a saved bookmark in your browser,

3) via a link provided in a Google search results page or

4) by typing in the full address into the browser?
 
NatWest have be ecouraging the use of Trusteer software for additional security. We are using it on any site on which we use sensitive info such as card details, bank details, etc.

http://www.trusteer.com/

Anthony.
 
how did NatWest tell you that ? i've not had anything from NatWest telling me to use a random third party to access my account.
 
Are you, or whoever has been affected, visiting the bank site

1) via a link in an email,

2) via a saved bookmark in your browser,

3) via a link provided in a Google search results page or

4) by typing in the full address into the browser?

Also, the OP says it's a virus, where does this virus come from? if 'they' know it exists 'they' should be able to say how it's being propagated.

Also which bank? there are hundreds if not thousands of banks, I find it impossible to believe that a virus can mimic the look of every bank website in the UK let alone those abroad. Phishing has been around for a long time and sites set up to capture your personal data this way can look very convincing, but phishing is not a virus and it targets a specific bank per link.
 
Still a wee bit sceptical about all this and intend to continue all my online banking.
 
NatWest have be ecouraging the use of Trusteer software for additional security. We are using it on any site on which we use sensitive info such as card details, bank details, etc.

http://www.trusteer.com/

Anthony.

Doesn't get glowing reviews everywhere. It appears to stop certain programs accessing the registry and thus not working.
 
Also, the OP says it's a virus, where does this virus come from? if 'they' know it exists 'they' should be able to say how it's being propagated.

Also which bank? there are hundreds if not thousands of banks, I find it impossible to believe that a virus can mimic the look of every bank website in the UK let alone those abroad. Phishing has been around for a long time and sites set up to capture your personal data this way can look very convincing, but phishing is not a virus and it targets a specific bank per link.
I know. So little information, so much scaremongering. Which is why I'm trying to take this back to basics with that question. TBH, I don't believe a word of it. I'm guessing it stems from link-clicking in a phishing email.
 
I havent seen anything like this from Natwest either...

I just checked NatWest and they're recommending the use of an application called Rapport - no mention of Trusteer at all.
 
I just checked NatWest and they're recommending the use of an application called Rapport - no mention of Trusteer at all.

The application is called trusteer rapport ,been using it for quite a while .
 
right, it just "encrypts" data from your keyboard input to your browser.

so, malware writers can just hook into the OS before the application encrypts the data, therefore bypassing it :P
 
Yes, the software is called Rapport - produced by Trusteer. It came up on the NatWest site some time ago and after ignoring it on a number of occasions, I checked into it and it seems okay so I went ahead with it.

Here is a link to some info...

http://www.natwest.com/global/media/y2009/m-3.ashx

Anthony.

Doh! I just saw it when I logged in earlier, seems like they've redesigned the site since my last login...

Not sure I want a plug in active on my browser the whole time though...
 
plus i cant see how a "plugin" which runs within the browser can encrypt keyboard entries before they get the browser...
 
plus i cant see how a "plugin" which runs within the browser can encrypt keyboard entries before they get the browser...

This what Trusteer say on their site

"...Trusteer Rapport locks down your browser once you connect to a sensitive website such as your bank. Any malicious software that tries to ride on the browser is left out of the locked down browser, and cannot access your sensitive information and transactions. Rapport also locks down communication between your browser and the bank, preventing any network-based attack from diverting traffic to fraudulent locations...."

I cannot believe somebody like NatWest hasn't looked into the efficacy of using this software before recommending it - indeed urging us to use it. I will admit that I cannot personally explain the technical details of how it does what it does.

Also, the cynic in me thinks that if I ever have a problem with my online banking, one of the first things I will be asked is "are you using Rapport"?...And you can guess the rest.

Anthony.
 
quite how a plugin which runs as a BHO can "lock down the browser" and "encrypt the data being received from your keyboard" is beyond me :P
 
Dear forum members,

After reviewing this forum thread we thought it would be useful to clarify how Rapport works. We are passionate about what we do and are always striving to give you the best protection when carrying out your online banking.
Trusteer Rapport plugs into the operating system, the browser, and network communication through-low level drivers and API hooking. It does not use any BHO technology as suggested in this forum thread.
Trusteer Rapport protects you in the following ways:
· Encrypts keystrokes

· Blocks interfaces into the browser

· Prevents external code from entering and executing inside the browser

· Prevents tampering with browser executables

· Prevents traffic from being captured or redirected to a fraudulent website.

This browser “lock-down” concept is based on a policy set by the bank and is content sensitive (it can be applied to various data fields and pages based on the bank’s policy). Trusteer Rapport also helps the bank identify new patterns of suspicious activity (AKA “zero-day attacks”) and block accounts from being compromised.
We hope this helps clarify everything and if anyone has any questions then please don't hesitate to ask. You can also contact us at support@trusteer.com for any questions or problems.

Sincerely,
The Trusteer Support Team
 
Back
Top