Phishing for bank customers

One day, a large majority of email addresses in the domain of a country received email messages which said the following:

LOGO of the BANK

Dear customer,

We have received new payment.

Please, enter to your account.

Email addresses received this message even if their users did not have an account with this bank. Imagine that some percentage of the people who received this email were customers at this bank. As a result, the majority of those customers clicked the link and logged in to their internet banking accounts. We received an email from the bank that their customers had lost lots of money.

The investigation results showed that this letter came from an email address which was in the country domain and also the ...

Get Learn Social Engineering now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.