Back to advisories
High
2 min read

A Look into Deceptive Practices Targeting Bank Customers

Malicious actors have been quick to capitalize on the situation by setting up fake or replica versions of corporate banking websites.

Alert: Deceptive Practices Targeting Bank Customers

Overview

These malicious actors have been quick to capitalize on the situation by setting up fake or replica versions of corporate banking websites to deceive individuals into divulging their personally identifiable information.

Example of Deceptive Tactics

Phishing Site Example

The image above shows an example of how threat actors create convincing fake websites to harvest credentials.

Attack Methodology

Phishing Infrastructure

  1. Domain Registration: Typosquatting and look-alike domains
  2. Website Cloning: Pixel-perfect copies of legitimate bank sites
  3. SSL Certificates: Free certificates to display the padlock icon
  4. Hosting: Bulletproof hosting to avoid takedowns

Distribution Channels

  • SMS phishing (Smishing)
  • Email phishing campaigns
  • Social media advertisements
  • Search engine manipulation
  • WhatsApp messages

Observed Targets

Several Nigerian banks have been impersonated:

  • First Bank
  • GTBank
  • UBA
  • Access Bank
  • Zenith Bank
  • And others

Red Flags

URL Indicators

  • Misspellings in domain names
  • Extra characters or hyphens
  • Unusual TLDs (.xyz, .online, etc.)
  • IP addresses instead of domains

Page Indicators

  • Requests for full card details including CVV
  • Requests for OTP or tokens
  • Grammar and formatting errors
  • Missing or broken features

Protective Measures

For Customers

  1. Always type bank URLs directly—never click links
  2. Verify the SSL certificate details
  3. Use official banking apps
  4. Enable transaction alerts
  5. Never share OTPs with anyone

For Banks

  1. Implement domain monitoring
  2. Rapid takedown procedures
  3. Customer awareness campaigns
  4. SMS sender ID protection
  5. Email authentication (DMARC)

Response

If you've entered information on a fake site:

  1. Contact your bank immediately
  2. Change your passwords
  3. Monitor your accounts
  4. Report to authorities

WhiteHat NG Banking Security Alert