Wednesday, December 30, 2009

Got Email from your Bank? Check it properly

There's a term in hacking called "phishing". Wikipedia gives it's definition as:

"In the field of computer security, phishing is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication."

In simple words, "Phishing" is capturing your personal information (especially banking passwords and account details) by fraud.

I got an Email from ICICI Bank. The Email asked for my net Banking information.



The Email looks like a normal mail. But,
1. No mail from any bank asks for any personal information on mail.
2. When you click on "Show Details" (in Gmail), it shows the server name the mail was sent from. In normal cases, the server name will be your banks name, but in the mail which i got, it was not the case. See the server name below.



You can also get such mails. So just beware.

But there's a simplest thing you can do to save yourself from these fruads. ALWAYS KEEP YOUR WEB BROWSER UPDATED. My firefox is upadated to the latest version. So the moron who sent this mail couldn't do anything. Even after clicking on the mail, my Firefox didn't open the page and showed me this message:


Some idiot created this without checking it on all browsers and sent it to me. What a fuckall hacker!

But still beware and don't give any personal details to anyone on mail. Even if it lands you on the website the site must be your bank's website with actual URL. I once got a similar mail and it landed me to a website called ICICILOANS.COM. Always check the URL. Your bank's official website will always be HTTTPS://icicibank.com and not HTTTP://iciciloans.com. check for the prefix HTTPS.
Also, always forward these type of mails to your bank's helpdesk so they can take some action towards this.

Beware otherwise someone can empty your Bank A/C or Credit card in minutes.

2 comments:

  1. Hi Kamaksh,

    Thanks for spreading the word on such deceptive emails. You're right - there are unscrupulous elements we all have to beware of.

    You'll be glad to know ICICI Bank already has precautionary measures in place to counter phishing. A large part of it is informing customers of what they need to be aware of at all times.

    How ICICI Bank customers can avoid becoming victims of phishing and other online scams.
    1. Log in to www.icicibank.com
    2. Once you login, ensure that the URL on the browser begins with https://infinity.icicibank.co.in
    3. Ignore all pop-up windows asking for login details or other sensitive information. ICICI will not ask for any information in pop-ups
    4. Please forward the e-mail received by you at antiphishing@icicibank.com for us to investigate
    5. Verify the security certificate of the site you are on by clicking on the padlock icon of your internet browser.

    We hope you find this of value. Please do reach us at care@icicibank.com if you'd like to connect with us.

    Regards,
    ICICI Customer Service Team.

    ReplyDelete