Search our Spoof Library...
Another Spoof Email and Phishing Scam report by MillerSmiles.co.uk - click this image to go to our home page.

Official notice for all Halifax Customers
29th March 2004

please forward any scams you've received to spoof@millersmiles.co.uk

 

Report Summary
Date Reported
29th March 2004
Apparent Sender
Halifax online <online@halifax-online.co.uk>
Return Address
Halifax online <online@halifax-online.co.uk>
Subject
Official notice for all Halifax Customers
Format
HTML
Method
disguised link leads to bogus web content & Genuine page is shown in seperate browser window as backdrop to bogus pop up
Bogus Web Content?
Yes
URL of web content
http://218.44.251.101/h/formslogin.php
RISK LEVEL
Medium
WARNINGS

1. Employs script to open the genuine halifax-online.co.uk home page as a backdrop to the bogus page.

 

Spoofed Halifax email leads to the genuine Halifax Online page but with a pop up which contains a bogus page ...

 

This spoofed Halifax email brings us another instance of forged web content being presented in front of a genuine site home page to trick users into believing that they are seeing a genuine pop up generated by the genuine site.

In this instance, Halifax Online customers are the target of this Phishing Scam, with a link in the spoof email (see image below) triggering a series of browser windows which ends up with one window for the halifax-online.co.uk home page and another 'pop up' style window in front of that (see image below).

The actual URL of the bogus pop up (use File menu/Properties, or right click/Properties, to see the URL) is http://218.44.251.101/h/formslogin.php which resolves to an ISP in Japan. Any data submitted into the forged sign in page will be processed through a PHP script located on the same server.

If you have received this email, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content or the same but with the fake page(s) hosted by a different provider. Also, once you have received one of these hoaxes, it is also common place to receive at least another one and usually a day or two after the first, although not necessarily from the same apparent sender.

 

The Spoof Email ...

Dear Valued Customer,

- Our new security system will help you to avoid
frequently fraud transactions and to keep your
investments in safety.

- Due to technical update we recommend you to
reactivate your account.

Click on the link below to verify and begin using
your updated Halifax account.

To verify your account, please visit the Halfax
website at https://www.halifax-online.co.uk/_mem_bin/formslogin.asp

We appreciate your business. It's truly our
pleasure to serve you.

Halifax Customer Care

 

The bogus web page (which is presented as a pop up style window in front of the genuine halifax-online.co.uk home page)...

Official notice for all Halifax Customers bogus web page.

 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...
 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...

Email Alerts
Add your email address to our email alert service...
Subscribe

Privacy Policy

RSS News Feed
Tap into our Scam Alert service using your News Reader or Aggregator (including My Yahoo!).
Scam Alert News Feed

You can even put the latest alerts on your own web site.

Click here to learn more about RSS News Feeds and our Scam Alert Service!

Resources links - use one of the links below to access more information on Spoof Email & Phishing Scams.

Library of Spoof Email Phishing Scams

Brief guide to Phishing

Full article on spoof email scams

Spoof URL Checker

Link Checker

Browser URL Spoofing Vulnerability Check

Latest browser bug aids Phishing Scams - beware!

Destinations - other resources available on the MillerSmiles.co.uk web site.

Click the arrow to return to previous page

Home

Guides...

Book Terminology

How to identify a first edition book

Auction Watcher

List of the main Auction Sites world wide