Phishers Target Swedish Bank

By

A phishing attack has broken new ground by attacking a Scandinavian bank operating a one-time password.

Researchers at Finnish security company F-Secure spotted the large-scale attack on Tuesday night (October 4) against Nordea Sweden, the largest bank in the Nordic countries, with more than 4 million internet customers in eight countries.


F-Secure chief Mikko Hypponen said the attack was special because the emails were in Swedish, and because Nordea operates a one-time password system, consisting of a scratch sheet, which the customer scratches to uncover the next available PIN code for login.

The mail claimed that Nordea was introducing new security measures, and asked customers to go to one of two fake sites hosted in South Korea (www.nordea-se.com and www.nordea-bank.net).

The sites look authentic and asks customers for their personal number, access code and the next available scratch code.

"Regardless of what you entered, the site would complain about the scratch code and asked you to try the next one. In reality the bad boys were trying to collect several scratch codes for their own use," Hypponen said in his bulletin warning of the danger.

Phishing attacks were initially predominantly in English, but they have now branched out into German and Danish earlier this year. This is the first in Swedish.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Microsoft knew of SharePoint security flaw in May, initial patch ineffective

Microsoft knew of SharePoint security flaw in May, initial patch ineffective

ACSC alerts to exploited MS SharePoint remote code execution flaw

ACSC alerts to exploited MS SharePoint remote code execution flaw

"PoisonSeed" attack does not bypass hardware MFA

"PoisonSeed" attack does not bypass hardware MFA

Qantas obtains court order to prevent third-party access to stolen data

Qantas obtains court order to prevent third-party access to stolen data

Log In

  |  Forgot your password?