Scam alert! Users of THESE banks should not fall prey to this phishing scam

In this cyber scam, users are being asked to submit an application for the disbursement of the income tax refund.


Scam alert! Users of THESE banks should not fall prey to this phishing scam

Representational image

Share

Written By

Edited By

Tanya Rao

Source

DNA webdesk

Updated: Mar 19, 2021, 03:53 PM IST

Cyber scams are on a surge lately and the latest one is targeting users of various banks. A big phishing scam is doing the rounds wherein customers State Bank of India, ICICI, HDFC, Axis Bank and Punjab National Bank face a major security threat.

The revelation was made by New Delhi-based think tank CyberPeace Foundation along with cybersecurity services firm Autobot Infosec. Cybercriminals dupe users on the internet into revealing their personal information which can lead to major financial losses as well.

In this cyber scam, users are being asked to submit an application for the disbursement of the income tax refund. It comes with a link that directs users to a webpage looking like the income tax e-filing web page. These dubious links originate from the US and France.

The scamsters are using plain 'http' instead of the secure 'https' in the links. Moreover, users are being asked to download an application from a third-party source instead of Google Playstore or App store.

When a user opens the said link, he/she is directed to a new page that resembles the income tax e-filing website. Once you click on the 'Proceed to the verification steps' option, you will be asked to submit personal information such as full name, PAN, Aadhar number, address, pincode, date of birth, mobile number, email address, gender, marital status and banking information like account number, IFSC code, card number, expiry date, CVV/CVC and card PIN.

Users might be tricked into thinking that the website is legit as the name of the bank will automatically be detected from the IFSC code entered in the form. After following a few steps of confirmation and entering login details, the user faces the risk of financial losses.