# I pit internet banking

**URL:** <https://boards.straightdope.com/t/i-pit-internet-banking/265666>\
**Category:** The BBQ Pit\
**Created:** [September 23, 2004, 1:30pm UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666 "2004-09-23T13:30:52Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![ZombiesAteMyBrain](https://avatars.discourse-cdn.com/v4/letter/z/b4bc9f/32.png) [@ZombiesAteMyBrain](https://boards.straightdope.com/u/ZombiesAteMyBrain)\
**Post date:** [September 24, 2004, 11:22am UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/21 "2004-09-24T11:22:29Z")

</div>

> [@Cerri](#):
>
> Ugh. My total and utter sympathies. I hate to bring this up at such a shitty time, but given the destination of your absconded funds, I don’t even know where you’d check to see if you’ve been profiled (as in funneling money to terrorists, kind of profiled) in some way, as you’re in Ireland, but as I said, given your stolen moneys’ destination…I wouldn’t count it outside the realm of possibilities.
> 
> Have you contacted the authorities, I hope? As shitty as it is now, in today’s age of the War on Terror, you might be at risk for far worse a problem if someone gets a wild hair and thinks you’re funneling money to terrorist sources. =/

I thought it was ironic, in a sick sorta way, that they’re stealing money from Northern Ireland, which has its own terrorist problem, to send it to a place like that. The police are aware of what happened, though.  
I’m still waiting for that call that I’ve been promised [twice] from the bank manager though - I don’t know what I’m going to do if they won’t let me set up another account to collect my disability cheques and pay my direct debits. The ass-hole I spoke to yesterday wouldn’t hear of it - and it seems logical to me - in fact the CID man I spoke to yesterday said that that was what would happen when I went down to the bank - but they were no help at all.

I think they might have targeted me though - I had a Halifax account until recently to pay my mortgage - and I got a similar notification from the Halifax this morning. Or maybe that’s just paranoid.

I still don’t understand how I could click a link that took me to my banks real e-mail address and still get ripped off - the e-mail address on the link was correct, or I woulda caught on.

---

<div class="post-metadata">

**Author:** ![GSV\_Consolation\_of\_Dreams](https://avatars.discourse-cdn.com/v4/letter/g/f1d935/32.png) [@GSV\_Consolation\_of\_Dreams](https://boards.straightdope.com/u/GSV_Consolation_of_Dreams)\
**Post date:** [September 24, 2004, 11:59am UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/22 "2004-09-24T11:59:07Z")

</div>

It’s quite possible to display a link in a Microsoft email program so that it looks like one address, but the link actually goes somewhere very different.

Usually the URL of their fake site is very close to the real address so that even if you are suspicious, a quick glance at the Address box wouldn’t always tip you off.

Bottom line, never, ever for any reason click a link in an email to any site that has your credit card details.

Oh, and make sure your email program is set to show all messages in plain text only. Makes it harder to fool you.

---

<div class="post-metadata">

**Author:** ![Shrinking\_Violet](https://avatars.discourse-cdn.com/v4/letter/s/df705f/32.png) [@Shrinking\_Violet](https://boards.straightdope.com/u/Shrinking_Violet)\
**Post date:** [September 24, 2004, 12:18pm UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/23 "2004-09-24T12:18:47Z")

</div>

Zombies, I really feel for you. ☹

I wouldn’t pit the Abbey for what happened as regards the scam - it happens equally to all financial institutions (I got 5 spoof emails yeaterday alone, none of which were “from” institutions I bank with, although occasionally a relevant-looking one will turn up). It isn’t their fault you were unaware of this particular type of scam … it’s been very much in the news of late.

But I certainly _would_ pit the Abbey for their unhelpful attitude towards helping you out of this predicament. Maybe you could contact the Benefits Office and ask them to send you giros until it’s all sorted out?

Wishing you a speedy solution.

---

<div class="post-metadata">

**Author:** ![Anonymous\_Coward](https://avatars.discourse-cdn.com/v4/letter/a/94ad74/32.png) [@Anonymous\_Coward](https://boards.straightdope.com/u/Anonymous_Coward)\
**Post date:** [September 24, 2004, 1:00pm UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/24 "2004-09-24T13:00:36Z")

</div>

I feel for you.

I had one of my accounts drained through ATM fraud (someone duped my card and recorded my PIN somehow), and it’s a terrible feeling. The bank was _very_ nice to us so all we had to do was sign a waiver stating that the money was stolen, and within 2 days the money was back in our account.

Here’s hoping that everything works out well for you.

---

<div class="post-metadata">

**Author:** ![Snickers](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@Snickers](https://boards.straightdope.com/u/Snickers)\
**Post date:** [September 24, 2004, 3:31pm UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/25 "2004-09-24T15:31:24Z")

</div>

First they eat your brain, now they take your money! No fair!

Hoping that you get a good resolution. Hang in there - we’re pulling for you.

---

<div class="post-metadata">

**Author:** ![ZombiesAteMyBrain](https://avatars.discourse-cdn.com/v4/letter/z/b4bc9f/32.png) [@ZombiesAteMyBrain](https://boards.straightdope.com/u/ZombiesAteMyBrain)\
**Post date:** [September 24, 2004, 5:26pm UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/26 "2004-09-24T17:26:16Z")

</div>

> [@Shrinking Violet](#):
>
> Zombies, I really feel for you. ☹
> 
> I wouldn’t pit the Abbey for what happened as regards the scam - it happens equally to all financial institutions (I got 5 spoof emails yeaterday alone, none of which were “from” institutions I bank with, although occasionally a relevant-looking one will turn up). It isn’t their fault you were unaware of this particular type of scam … it’s been very much in the news of late.
> 
> But I certainly _would_ pit the Abbey for their unhelpful attitude towards helping you out of this predicament. Maybe you could contact the Benefits Office and ask them to send you giros until it’s all sorted out?
> 
> Wishing you a speedy solution.

Thank you so much, everybody who has given me info [and sympathetic letters] about this. I told my solicitor about it this morning - and he thought Abbey were negligent in writing instead of phoning when these eejits first tried to access my account. [its a bit like seeing someone breaking into a house and then writing to the police to come and deal with it, rather than lifting the phone.]

He said there was nothing really he could do immediately, but to go back to the bank today and mention that I’d spoken to him if they were still unhelpful. It worked like a charm - they’re setting up a new account for me tomorrow, they’re transferring all the direct debits, pension and disability payments for me, and now they’re talking about days, rather than weeks or months, before I get the money back. And they were much more polite too!!

---

<div class="post-metadata">

**Author:** ![mhendo](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mhendo/32/3159_2.png) [@mhendo](https://boards.straightdope.com/u/mhendo)\
**Post date:** [September 24, 2004, 5:32pm UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/27 "2004-09-24T17:32:01Z")

</div>

Great news, **Zombies**!

Hope it all goes smoothly for here on.

And now you know what (not) to do next time you get one of those emails. 🙂

---

<div class="post-metadata">

**Author:** ![ZombiesAteMyBrain](https://avatars.discourse-cdn.com/v4/letter/z/b4bc9f/32.png) [@ZombiesAteMyBrain](https://boards.straightdope.com/u/ZombiesAteMyBrain)\
**Post date:** [September 24, 2004, 5:42pm UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/28 "2004-09-24T17:42:35Z")

</div>

> [@Snickers](#):
>
> First they eat your brain, now they take your money! No fair!

LOL, Snickers - thanks for making me laugh.

Have you seen this article [DIY phishing kits hit the Net • The Register](http://www.theregister.co.uk/2004/08/19/diy_phishing/)  
about how you can download a free kit with everything you need to run this scam. It amazes me that this sorta thing isn’t a target for the homeland security guys, here and in the USA - but maybe they’re having too much fun reading people’s private e-mails to be bothered much about crooks/terrorists in Kazakhstan ripping off their bank accounts.

---

<div class="post-metadata">

**Author:** ![Colophon](https://avatars.discourse-cdn.com/v4/letter/c/f05b48/32.png) [@Colophon](https://boards.straightdope.com/u/Colophon)\
**Post date:** [September 24, 2004, 6:01pm UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/29 "2004-09-24T18:01:55Z")

</div>

I agree that it’s a mean and nasty scam, but seriously – **how can anyone that uses internet banking not be aware of the phishing scam?** It’s like, lesson 101. I don’t know about Abbey, but my bank (NatWest) displays a warning about this scam _every single time I log in_. I’ve had plenty of phishing emails, I either bin them, or, if I’m feeling vindictive and have a few minutes to spare, go and spam their phoney log-in page with all manner of fake details and passwords such as “Fuckoffanddiemorons”. That gives me a teeny bit of satisfaction.

Anyway, I hope you get your money back. I know that my bank has a clause whereby if you give your login details to someone else, even inadvertently in the way you did, you are liable for the loss. I sincerely hope your bank doesn’t hold you to this.

Anyone else that uses internet banking, please note: YOUR BANK WILL NOT ASK YOU TO LOG INTO A PAGE BY EMAIL.

---

<div class="post-metadata">

**Author:** ![ZombiesAteMyBrain](https://avatars.discourse-cdn.com/v4/letter/z/b4bc9f/32.png) [@ZombiesAteMyBrain](https://boards.straightdope.com/u/ZombiesAteMyBrain)\
**Post date:** [September 24, 2004, 6:59pm UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/30 "2004-09-24T18:59:48Z")

</div>

> [@Colophon](#):
>
> I agree that it’s a mean and nasty scam, but seriously – **how can anyone that uses internet banking not be aware of the phishing scam?** It’s like, lesson 101. I don’t know about Abbey, but my bank (NatWest) displays a warning about this scam _every single time I log in_. .

Sorry, but all banks arn’t the same - I’ve never seen a warning from Abbey - and you can only find it on their website if you specifically go looking for it - it’s not on the front page, but just 4 lines at the very bottom of their [very long] security page - most of which would bore you silly before you got to the relevant part - its a lot of self-praise about how great their security is - blah, blah!

So I don’t think it’s fair for you to say “It’s like lesson 101” when you have no experience of how my bank works. Maybe now that so many of their customers have been caught this time round they’ll upgrade their security. I’m far from being the only victim - it’s impossible to get through to their fraud office at the moment - all lines are permanently engaged.

---

<div class="post-metadata">

**Author:** ![Go\_You\_Big\_Red\_Fire\_Engine](https://avatars.discourse-cdn.com/v4/letter/g/eada6e/32.png) [@Go\_You\_Big\_Red\_Fire\_Engine](https://boards.straightdope.com/u/Go_You_Big_Red_Fire_Engine)\
**Post date:** [September 25, 2004, 12:41am UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/31 "2004-09-25T00:41:02Z")

</div>

> [@Colophon](#):
>
> Anyone else that uses internet banking, please note: YOUR BANK WILL NOT ASK YOU TO LOG INTO A PAGE BY EMAIL.

Not true.

> [@My Mail](#):
>
> One of your future dated funds transfers via Suncorp Internet Banking has been unsuccessful
> 
> We cannot advise you of the account number and transfer details via e-mail as this message is not secure. A secure message containing this information  
> is waiting for you online. Simply logon to Internet banking at  
> suncorp.com.au and select Secure Messages from the  
> Service Centre menu located at the top of the screen.

I didn’t follow their link though. I clicked on my own bookmark.  
And I pit the bank for something else too. Well I pit my shitty maths first, for not calculating that when I transferred money to savings, I would be $5 short on rent to pay. So I log in, it tells me, it’ll try again the next day, or I could cancel the transaction. So I do. And I transfer money into my account, set up a new transaction. But the money doesn’t go into my account in time, my new transaction doesn’t get set-up somehow, and the old one tries to go ahead again… but oh no! that $100 I transferred from my sub-account to my main account hasn’t made it yet. So it fails again. I delete it again, and set up a new transaction. I hope it works this time.

Of course your situation is a lot worse.

---

<div class="post-metadata">

**Author:** ![GawnFishin](https://avatars.discourse-cdn.com/v4/letter/g/e9bcb4/32.png) [@GawnFishin](https://boards.straightdope.com/u/GawnFishin)\
**Post date:** [September 25, 2004, 2:35pm UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/32 "2004-09-25T14:35:49Z")

</div>

> [@GuanoLad](#):
>
> I keep getting emails to log in to my Citibank account to verify my information.
> 
> But unfortunately for them, I’m not with Citibank. I don’t even know Citibank. Indeed, there is **no Citibank in Australia**.

Don’t be so sure about this. You may be proven [wrong](http://www.citibank.com.au/). Check out their office at 350 Collins St. 😃

---

<div class="post-metadata">

**Author:** ![casdave](https://avatars.discourse-cdn.com/v4/letter/c/c6cbf5/32.png) [@casdave](https://boards.straightdope.com/u/casdave)\
**Post date:** [September 25, 2004, 2:43pm UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/33 "2004-09-25T14:43:37Z")

</div>

What I dont understand is how they can actually collect.

One con doing the rounds is when you sell a major item like a car.

What happens is that you are given a cheque, to pay for ti, and the buyer collects when it has cleared, except that it isnt properly cleared at first, even if it appears on your bank balance.

A couple of days later the bank informs you that there was not enough money to cover the transaction and you are screwed.

Now if they can hold back payment to you like this, why cant they do the same to the phishers.

It should work its way down the line, the money appears to be transferred, the bank suspect something and the electronic movement of money stops before it gets cleared for cash payment.

It cannot be hard to track down where the final payment was made, and given the cameras in banks it shouldnt be hard to identify the perps.

---

<div class="post-metadata">

**Author:** ![TellMeI\_mNotCrazy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tellmei_mnotcrazy/32/3419_2.png) [@TellMeI\_mNotCrazy](https://boards.straightdope.com/u/TellMeI_mNotCrazy)\
**Post date:** [September 25, 2004, 3:04pm UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/34 "2004-09-25T15:04:30Z")

</div>

> [@casdave](#):
>
> What I dont understand is how they can actually collect.
> 
> One con doing the rounds is when you sell a major item like a car.
> 
> What happens is that you are given a cheque, to pay for ti, and the buyer collects when it has cleared, except that it isnt properly cleared at first, even if it appears on your bank balance.
> 
> A couple of days later the bank informs you that there was not enough money to cover the transaction and you are screwed.
> 
> Now if they can hold back payment to you like this, why cant they do the same to the phishers.
> 
> It should work its way down the line, the money appears to be transferred, the bank suspect something and the electronic movement of money stops before it gets cleared for cash payment.
> 
> It cannot be hard to track down where the final payment was made, and given the cameras in banks it shouldnt be hard to identify the perps.

I’m sure that once the funds hit their account, they just take it and run. It’s not as if they’re opening new accounts with any real information.

---

<div class="post-metadata">

**Author:** ![yojimbo](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/yojimbo/32/232_2.png) [@yojimbo](https://boards.straightdope.com/u/yojimbo)\
**Post date:** [September 25, 2004, 3:18pm UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/35 "2004-09-25T15:18:12Z")

</div>

Wow. That must have been a horrible time for you **ZombiesAteMyBrain**. I’m glad it seems to be working itself out.

I only heard about this sort of con quite recently as well so it’s not as well known over here as it may be in other places.

Thanks for reminding everyone to be very careful when it comes to the net and your money.

---

<div class="post-metadata">

**Author:** ![ZombiesAteMyBrain](https://avatars.discourse-cdn.com/v4/letter/z/b4bc9f/32.png) [@ZombiesAteMyBrain](https://boards.straightdope.com/u/ZombiesAteMyBrain)\
**Post date:** [September 25, 2004, 4:23pm UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/36 "2004-09-25T16:23:57Z")

</div>

> [@Sublight](#):
>
> I get these from Citibank on a regular basis. The problem is, even when the source is legit, it can be fishy; one of Citibank Japan’s own executives got busted recently for scamming accountholders.

A friend of mine in Japan nearly got caught by the Citibank scam this week - he was saved by the fact that the page took so long to open that he got bored and gave up. And then he got my e-mail and realised he’d nearly been had.

---

<div class="post-metadata">

**Author:** ![Blalron](https://avatars.discourse-cdn.com/v4/letter/b/35a633/32.png) [@Blalron](https://boards.straightdope.com/u/Blalron)\
**Post date:** [September 25, 2004, 8:35pm UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/37 "2004-09-25T20:35:02Z")

</div>

> [@ZombiesAteMyBrain](#):
>
> A friend of mine in Japan nearly got caught by the Citibank scam this week - he was saved by the fact that the page took so long to open that he got bored and gave up. And then he got my e-mail and realised he’d nearly been had.

It’s not like the banks aren’t warning people about this. Citibank’s website has an alert about these scams on its front page.

---

<div class="post-metadata">

**Author:** ![casdave](https://avatars.discourse-cdn.com/v4/letter/c/c6cbf5/32.png) [@casdave](https://boards.straightdope.com/u/casdave)\
**Post date:** [September 26, 2004, 1:24pm UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/38 "2004-09-26T13:24:14Z")

</div>

> [@](#):
>
> I’m sure that once the funds hit their account, they just take it and run. It’s not as if they’re opening new accounts with any real information.

This is where I have the problem of understanding how they get their hands on the money.

In the example con I gave, the bank ensures that the funds physically exist, they might put the numbers on your balance temporarily, but they have a means of checking it.

If I wish to draw on funds that have been paid in to my account, the bank will not let me until it has cleared, and dpending upon th institution, this can take up to 8 days - yikes.The bank in this case noticed well within that time and yet it would appear that the money has been withdrawn.

If financial insitutions actually abided themselves to the rules they impose on us ordinary proles, this wouldn’t have happened, they obviously cleared it way ahead of what they allow you and me to access money, so it appears from the outside that actually they just impose these rules on us, not to protect us, but to hang on to our money a little longer, which is what consumer groups have been saying for years.

[http://www.moneyworld.co.uk/features/2002/f160902\_genfinance\_12.html](http://www.moneyworld.co.uk/features/2002/f160902_genfinance_12.html)

That relates to cheques, but they also do the same on electronic transfers, ordinary consumers cant get to their cash even if they are online banker until the cash has cleared.

Actually Abbey is one of those institutions that have a long clearing time for balance transfers, it used to be 11 days but its slightly shorter now.

---

<div class="post-metadata">

**Author:** ![ZombiesAteMyBrain](https://avatars.discourse-cdn.com/v4/letter/z/b4bc9f/32.png) [@ZombiesAteMyBrain](https://boards.straightdope.com/u/ZombiesAteMyBrain)\
**Post date:** [September 26, 2004, 8:06pm UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/39 "2004-09-26T20:06:00Z")

</div>

According to this article [http://uk.news.yahoo.com/040923/12/f37df.html](http://uk.news.yahoo.com/040923/12/f37df.html) the majority of these scams involve the hacking of the **real** bank website.

> [@](#):
>
> Nine out of 10 financial and commercial websites contain flaws that could allow computer crooks to swindle users out of their cash, according to a new report…
> 
> …However, the majority of flaws discovered by NGS did not involve fake sites. Instead, NGS most frequently found configuration errors that could be used to redirect sensitive information from a legitimate web site to a fraudulent one without the user knowing.

---

<div class="post-metadata">

**Author:** ![GSV\_Consolation\_of\_Dreams](https://avatars.discourse-cdn.com/v4/letter/g/f1d935/32.png) [@GSV\_Consolation\_of\_Dreams](https://boards.straightdope.com/u/GSV_Consolation_of_Dreams)\
**Post date:** [September 27, 2004, 7:39am UTC](https://boards.straightdope.com/t/i-pit-internet-banking/265666/40 "2004-09-27T07:39:05Z")

</div>

That’s not **quite** what the article says, although what it does say is scary enough.

Although the cross-site scripting attacks are possible, there’s no evidence there that this is the method most phishers actually use. i think it would a be a lot more complicated for them to hack the real website than to cook up a fake version of their own.

[Previous page](https://boards.straightdope.com/t/i-pit-internet-banking/265666.md?page=1)
