Phishing Protection or Phishing Enabler?
A friend forwarded me a wine offer from his bank. But the email from his bank included additional information meant to verify the authenticity of the sender.
The bank included the last part of his postcode in the body of the message as well as his title and family name. If those were meant to be for verification purposes, why did it suggest he forward the email to someone else?
Yes, the forwarded email has all the verification details embedded in it. No, it's not the username and password, but it's everything someone would need to construct a phishing email that would be very hard to distinguish from a real one.
This has the feel of using a security measure as a marketing gimmick. Mixing marketing emails and those necessary for servicing a bank account is a difficult balance, but this is way off the mark.
Posted on: 18 August 2009 at 08:13 hrs

Comments are filtered automatically and should appear shortly after they been checked.