Hackers hit State Bank of India users with text phishing scam

Several SBI users have been targeted with a phishing scam where hackers have flooded them with suspicious text messages

SBI
SBI | File
IANS New Delhi
2 min read Last Updated : Mar 01 2021 | 1:59 PM IST

Several users of the State Bank of India (SBI) have been targeted with a phishing scam where hackers have flooded them with suspicious text messages, requesting them to redeem their SBI credit points worth Rs 9,870.

The link associated with the text messages redirects the user to a fake website and on the landing page, the user is asked to submit personal information along with sensitive financial details like card number, expiry date, CVV and Mpin in a 'State Bank of India Fill Your Details' form.

According to the investigation by New Delhi-based think tank CyberPeace Foundation along with Autobot Infosec Private Ltd, the website collects data directly without any verification and is registered by a third party instead of having the registrant organisation name of State Bank of India, making it all the more suspicious.

"Moreover, according to SBI, they never communicate with their customers via SMS or emails containing links with regard to the user's account. Any reputed banking entity also does not use Wordpress like CMS technologies on their official website for security reasons," the foundation said.

The personal information sought on the malicious website is name, registered mobile number, email, email password and date of birth.

After the form is submitted, the user is directed to a "thank you" page.

"The domain name of the website can be traced to India, and the registrant state was found to be Tamil Nadu," the report mentioned.

According to the report, it was observed that the form takes user inputs without performing basic validation of data type.

For example, the registered mobile number field, which should only accept numerical values also accepts text input. This can also be confirmed from the source code, where the input type for the field is mentioned as 'text' instead of 'number' or 'tel'.

"The email password field shows the entered password in clear text instead of keeping the characters hidden. A similar source code observation is noted," it added.

"The card number field accepts an infinite number of digits instead of only 16 digits, which SBI cards usually have. All these instances of negligence clearly indicate bad coding practice," the foundation said.

--IANS

na/in

(Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

Topics :sbiIndian banking sectorcybersecurity

First Published: Mar 01 2021 | 1:51 PM IST

Next Story