18 June 2013

Phishers target Nordea's one-time password system

12 October 2005  |  32401 views  |  0 Nordea

Scandinavian bank Nordea was forced to shut down part of its Web banking service for 12 hours last week following a phishing attack that specifically targetted its paper-based one-time password security system.

According to press reports, the scam targeted customers that access the Nordea Sweden Web banking site using a paper-based single-use password security system.

A blog posting by Finnish security firm F-Secure says recipients of the spam e-mail were directed to bogus Web sites but were also asked to enter their account details along with the next password on their list of one-time passwords issued to them by the bank on a "scratch sheet".

The scratch sheet contains a certain number of hidden passwords and each time the customer uses the online banking service they uncover the next password in the list to access to their account.

F-Secure says rather than the present code the customer was using, the bogus sites asked for the next available scratch code on the list, which suggests that the phishers were trying to collect the scratch codes to use later along with the stolen account details.

Comments: (0)

Comment on this story (membership required)
Log in to receive notifications when someone posts a comment

Related blogs

Create a blog about this story (membership required)

Related stories

19 September, 2005
30 August, 2005
24 August, 2005
03 August, 2005
02 August, 2005
24 June, 2005
23 June, 2005
17 May, 2005
26 November, 2004

Related company news

 

Who is commenting?

Featured job

Excellent salary with uncapped commission
Milton Keynes

Find your next job