Friday, October 20, 2006

You Get a LInE, I'll 6et a PoLe, We'll Go D0wn to the Phishin' Hol3

I was taking a look at my spam this evening when I noticed a mail from Bank of America. Hmmm... I thought. What possibly could make Gmail think that this was spam?

The first line gave it away:
Your Online Banking is Blocked

We recently reviewed your account, and suspect that your Bank of America account may have been accessed by an unauthorized third party. Protecting the security of your account is our primary concern. Therefore, as a preventative measure, we have temporarily limited access to sensitive account features.

To restore your account access, we need you to confirm your identity, to do so we need you to follow the link below and proceed to confirm your information:

http://sitekey.bankofamerica.com.signon.do.onlinesecureserver.us

Tank you for your patience as we work together to protect your account.

Sincerely,
Bank of America Customer Service

*Important*
Please update your records on or before 48 hours, a failure to update your records will result in a temporal hold on your funds.


Bank of America, N.A. Member FDIC. Equal Housing Lender
© 2006 Bank of America Corporation. All rights reserved.
These people are very stupid, and yet I'm sure that there were some people today who were dumb enough to click on that link and enter their account information. Two things:

Bank of America (or any banking institution) no longer puts direct links to the signon page in their e-mails to customers, or anyone. They all tell you to go to the site and sign in, manual-like.

Professional correspondence from a company that does billions of dollars worth of business will not replace the word "temporary" with "temporal," or say "Tank you for your patience...."

Okay, three things. I just noticed that it was not even sent to the e-mail address I have on file with the bank.

Please be careful with e-mail messages. If you have any sort of question about a peice of correspondence telling you that there's trouble with your account and your identity needs to be verified, just pick up the phone or go to the bank yourself. Those are the only ways to be sure.

Sweep the leg, people.


No comments: