Halyk Bank and KZ-CERT have identified new phishing resources
The KZ-CERT Computer Incident Response Service of JSC State Technical Service (hereinafter referred to as the Service), together with JSC Halyk Bank of Kazakhstan, identified new phishing resources disguised as an Internet resource homebank.kz .
In total, eight Internet resources were recorded, the pages of which are visually identical to the official Internet resource, but at the same time have slight differences in the spelling of the Internet address. The attackers offer victim users to enter a trusted phone number/identifier or login, password and SMS code to log into their personal account homebank.kz . If a user follows the lead of scammers and fulfills all these conditions, this allows attackers to compromise personal data and accounts.
Such links to phishing Internet resources are most often distributed by scammers through targeted advertising on popular social networks using an enticing headline or a similar name of a well-known brand in order to attract as many victims as possible.
The KZ-CERT service has carried out work on notifying hosting providers and CERTS from near and far abroad related to the specified information security incident. To date, the Internet resource is unavailable.
"Always double-check the information according to which you are promised unexpected purchases, prize draws, lottery winnings, compensation, etc. and are offered to transfer money for winnings to your bank account or bank card. Under no circumstances do banks carry out mass email mailings of letters with attached files, links and forms for logging into Internet banking system sites," Halyk Bank of Kazakhstan JSC recommends.
Earlier, the KZ-CERT Service has already reported on the identification of five Internet resources that imitated homebank.kz . (https://www.cert.gov.kz/news/11/131 )
The KZ-CERT service strongly recommends:
• When clicking on the link, pay attention to the address bar – the name of the domain name. Pay attention to the extra characters in the official name of the Internet resource of the organization or company conducting the campaign.
• Pay attention to the content of the site: fonts, grammatical errors, low-quality images, outdated design, excessive amount of advertising and various links on the page. If, when clicking on links, you are redirected to pages that are different from the official website, then this is a phishing resource.
• Do not enter authorization data on questionable Internet resources.
• Do not enter your personal data, bank card data and keep them safe. Do not tell anyone the 3-digit CVV/CVC code (on the back of the bank card). Do not report the incoming SMS code from the bank.
• Do not send copies of your documents that contain personal data, identity card data, bank card data, etc.
• Banks never request usernames, passwords, codes from SMS messages and other confidential identification and personal data by means of letters or in any other way.
If you encounter an information security incident, please inform our specialists at the toll-free number 1400 (around the clock) or send a request to the Telegram chat: https://t.me/kzcert .