Thursday March 30, 2006

Banks Hit With New Spoofing Attacks

It scares me that an ISP for a large bank can actually let themselves get hacked resulting in legitimate banking traffic being redirected to phishing sites.

Attackers were able to hack servers run by the Internet service provider that hosted the three banks' Web sites. They then redirected traffic from the legitimate Web sites to a bogus server, designed to resemble the banking sites. Users were then asked to enter credit card numbers, PINs, and other types of sensitive information.