• On TV.com: ADAM LAMBERT'S A Big Faker
August 22, 2007 2:39 PM PDT

Phishers take advantage of Wells Fargo's woes

by Robert Vamosi
  • Font size
  • Print
  • 5 comments

Although they look similiar, the fraudulent site above uses a URL that isn't SSL-protected (note the white address bar), nor is it from the Wells Fargo top-level domain (note the numbers in the URL). The fraudulent site also uses an older version of the Wells Fargo log-in page.

Sites monitoring phishing activity are today reporting an increase in Wells Fargo phishing sites as thieves looking to take advantage of an outage over the weekend have started sending out e-mail pretending to be from the San Francisco-based institution.

On Sunday Wells Fargo experienced an outage of its ATM and online banking services. The problem, which also affected back-end systems for the bank's mortgage, equity and student loans, had been resolved as of Tuesday afternoon. Because the bank needed to use backup records, individual account balances might not up be up to date for a few more days. Through the media, the bank has apologized for any inconvenience. However, phishers have wasted no time in sending out their own e-mails, pretending to be from Well Fargo.

The legitimate Wells Fargo site is SSL-protected (note the yellow address bar), uses the Wells Fargo top-level domain, and features the latest log-in page design.

Banks typically do not send e-mail to their customers; that should be your first warning sign. In one e-mail that begins "Dear Wells Fargo customer ...," users are invited to link to a fraudulent Wells Fargo phishing site in order to update account information. The site, still active on Wednesday afternoon, looked similar to the legitimate Wells Fargo site; however the phishing site did not use the latest page redesign, nor was the URL secure through Secure Sockets Layer (SSL) encryption, nor did it mention Wells Fargo within its top-level domain. When compared side-by-side with the legitimate site, the differences (especially within the address bars) should be obvious.

When accessing your online bank accounts, use a previously bookmarked URL or type in the address yourself. Once on the banking site, make sure the address bar shows a SSL connection (usually the address bar will be a different color and display a tiny paddle lock) before typing in a user ID or password. Also, the latest versions of Firefox 2 and Internet Explorer 7 include built-in antiphishing tools to block fraudulent sites, but these tools must be enabled first.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Add a Comment (Log in or register) (5 Comments)
  • prev
  • 1
  • next
Wrong headline
by qwerty75 August 22, 2007 3:03 PM PDT
Should say:

"Phishers take advantage of the publics continuing fascination with technical ignorance."

If the population at large would take an hour or two out of their lives to learn a little, they would fall "victim" to this.
Reply to this comment
Wells Fargo Still Showing Glitches
by nickerbocker79 August 22, 2007 3:43 PM PDT
I made a deposit on Monday unaware of what happened over the weekend. The deposit I made was credited to my account twice. I wonder how long before they catch that.
Reply to this comment
typo
by hrosenman August 22, 2007 3:49 PM PDT
"... (usually the address bar will be a different color and display a tiny paddle lock)"

That should be "padlock"
Reply to this comment
As ye sow ...
by NoVista August 22, 2007 4:50 PM PDT
I wouldn't like to see any individual hurt by such activities. But! no sympathy for the scum company and their slimy foreclosure and other tactics.

http://www.innercitypress.org/wells.html
Reply to this comment
IT's WAR. Cyber War. And the Internet is the Battleground.
by disco-legend-zeke August 23, 2007 9:56 AM PDT
The massive DOS outages, spamming, and other attacks on the Internet are not just skript kiddies playing around. Those that are not terrorists are criminal organizations.

One IP address in France made 3 or four ADMIN login attempts per second for several hours last week.

Its time for the good guys to start taking action, or we will go back to standing at long lines and bank-by-mail systems.
Reply to this comment
(5 Comments)
  • prev
  • 1
  • next

The browser battles go on and on

roundup From Firefox to IE and from Chrome to Opera and Safari, there's no sitting still for browser makers looking to keep their products fresh and competitive.

3G wireless still holds promise

The next generation of 4G wireless may get all the headlines, but advanced 3G technology will likely dominate services for the next few years.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right