Websense Security Labs has received reports of a phishing attack that targets customers of Nordea.
Users receive a spoofed email message claiming that a new security system has been implemented, and that account details must be verified. The email provides a link to a phishing site that attempts to collect user account information.
This phishing site is hosted in the Hong Kong Special Administrative Region of China and was down at the time of this alert.
Translated phishing email text:
How do you do, dear customer!
For Nordea, summer 2006 been one of the most full of illegal operations. Confidential information about our customers is more and more often interesting for scammers. It is rtt many who turn to us because we protect their account against loss of money.
Up til September 1 should all of our customers activate the new account safety system. We have done a lot of work for it. The system has been checked by leading specialists in the e-payment system industry and all independent experts have already certified its completeness in regards to fighting fraud. On the ground that this information can be used by criminal elements, we do not piblicate it publicly.
You have been randomly selected to participate in the systems final testing. For now we suggest that you click on < URL REMOVED > and through a normal online banking login activate the new security system. For now you may notice some irregularities whilst working. We know that they exist, and ask you to not give us any further information about possible problems, we will resolve them on our own.
We want to inform you that from September you will have to use the new security system anyway, or your accounts will be blocked til you have verified your full personal information. That is why we suggest you start to implement the new security standards as soon as possible.