Phishing attack on SBB customers: fake websites steal credit card data
Criminals deceive SBB customers with counterfeit websites and obtain credit card data. Cybercrimepolice.ch warns of the scheme.

Forged SBB tickets at bargain prices – police warn of phishing wave
Criminals have developed a new fraud scheme that specifically targets SBB customers, as Blick reports. In doing so, deceptively authentic copies of the SBB website are created, whose URL differs only minimally from the original and whose design appears nearly identical.
On the counterfeit pages, alleged SBB tickets are offered at unusually low prices. Journey times, routes and platforms appear authentic – travellers can even choose between first and second class. Only on the final payment page does the actual purpose become apparent: there, the perpetrators demand sensitive data such as credit card number, expiry date, security code or Twint information.
The fraudsters subsequently use this data for illegal withdrawals and further fraud. Cybercrimepolice.ch currently warns against the scheme.
SBB explains on request that they are monitoring the situation intensively and report newly discovered phishing pages immediately to the Federal Office of Cybersecurity. "We also recommend this approach to potentially affected customers," the company states. Media spokesperson Reto Schärli emphasises to Blick: "SBB continually develops security measures for login and payment processes and regularly raises customer awareness of cyber risks."
Source: Blick