Citizens Bank phishing scam


Here are a couple phishing scams received targeting Citizens Bank customers.

Note that the deactivated url in the message below was actually linking to http://ebanking-services.citizensbanking.com.file-id011.com/  The part after .com was the same.

The subject lines on Citizens banking phishing scams that I’ve received so far have been:

  • our new security measures
  • urgent notification from customer service
  • Citizens Bank: online form released
  • Security alert

Dear Citizens Bank customer,

We would like to inform you that we are currently carrying out scheduled maintenance of banking software, that operates customer database for Citizens Bank Business Express service.
Every Business Express customer has to update his Business Express online account. In order to update your account, please complete a Business Express Customer Form.
Please use the link below to access the form. The link is unique for each account holder.

http://ebanking-services.citizensbanking.com/Nubi/cust-directory/form.aspx?cid=555839788390159077256487573083712615808266913568107807092805376216301296619

Thank you for your cooperation. We apologize for any inconvenience brought.
This is auto-generated email, please do not respond to this email.
Citizens Bank Technical Department

Another one had the url:

http://ebanking-services.citizensbanking.com/Nubi/cust-directory/form.aspx?cid=5391123441245159987443809052367059298757802

which linked to http://ebanking-services.citizensbanking.com.file-id017.co.in/

And another one had:

http://ebanking-services.citizensbanking.com/Nubi/cust-directory/form.aspx?cid=045830499345346657164115307985915973519

which linked to http://ebanking-services.citizensbanking.com.dlls-to.mn/