Phishing scam via SMS: fraudsters impersonate 365.bank

Fraudsters are sending SMS messages in which they impersonate 365.bank and lure recipients to a fake website with alleged rewards. The aim is to obtain login and payment information.

Phishing scam via SMS: fraudsters impersonate 365.bank

False SMS from "365.bank" lure recipients with rewards and steal payment information

The portal zive.aktuality.sk is warning of a new phishing scam in which fraudsters impersonate 365.bank. Through SMS messages, they attempt to direct recipients to a fraudulent website.

The message claims that the customer has several thousand points available in a loyalty programme and that the validity of the current reward period will expire soon. Products from Apple, Sony electronics and other goods are listed as incentives.

The SMS contains a link to a website mimicking the official bank website — however, it is not the 365.bank domain. The fraudsters ask the recipient to reply to the message with the letter "Y", close the message and reopen it, or enter the link manually into the browser.

After clicking on the link and entering a telephone number, "available rewards" are displayed. The website then requests contact information, email and payment card details.

The fraudsters deliberately work with a sense of urgency — the rewards will expire soon according to the message. A combination of time pressure and an attractive offer may cause some users to click without verification.

Multiple warning signs point to the scam: the message came from an unknown foreign number with the +63 area code, and the domain used does not belong to 365.bank.

Users should not respond to such messages, should not open any attached links, nor should they enter any information on websites to which the SMS directs them.

If someone has already opened the link, they should not fill in login credentials, passwords or payment card information on the website, and should not confirm any transactions in the banking application. If information has already been entered, they should contact the bank immediately and consider blocking the card.

The fraudsters' aim is to obtain login credentials for online banking, payment information, or to persuade the victim to confirm a fraudulent transaction.

Source: Google News SK — Crime (sk)

Read this article in the original language