Two-Factor Phishing

Phishers consider nothing sacred, not even two-factor authentication: at least one has already phished for the second factor.
If you visit the site and enter bogus information to test whether the site is legit — a tactic used by some security-savvy people — you might be fooled. That’s because this site acts as the “man in the middle” — it submits data provided by the user to the actual Citibusiness login site. If that data generates an error, so does the phishing site, thus making it look more real.

Citibank Phish Spoofs 2-Factor Authentication, Brian Krebs, 10 July 2006

This could be because the people behind such phishing scams are often pretty tech-savvy people themselves. Funny how that happens when there’s money in it.

-jsq

One thought on “Two-Factor Phishing

Comments are closed.