I woke up this morning to see 2 email requesting that i should update my online account with GTB and Springbank, 2 separate emails.
Funny because i don't have account with these bank, I did a little bit of poking and realised the links in the email directs unsuspecting users to a different URL
VERY INTELLIGENT, REPLACING "a" WITH "e" AND "c" WITH "e"
i tried to feed in wrong login details as login and i was directed to the real website, its obvious that my entry has already been save to a database before redirection.
You know one bad thing here is that the email address was spoofed, so the email appears to be sent from GeNS@gtbplc.com
so if yahoo users have already added the email address to their address book, then yahoo users will see the address book icon next to the message as if it came from the right source
A little background check shows the 2 sites were hosted by the same hosting company www.abimco.com because thats where the DNS server points to
I have got the GTB letters like 4 times now but the Springbank own just arrived today, the funnies part of the story is that I don't operate Springbank account.