Security alerts, advisories and notifications for the EMU community.
June 30, 2005
Another phishing schemer
It's really quite simple: Don't click on links in emails!
In the IS Connection blog Jack has written about the practice of phishing, sending emails that appear to come from legitimate institutions--eBay, major credit card companies, etc.--and urge readers to enter personal information into an online form to "verify their identity."
One recent example of the genre is a an email purporting to be from the National Credit Union Administration--"the federal agency that charters and supervises federal credit unions...across the country. The email talks about "security measures" and urges readers to "fill in the form...to complete the verification process." It sounds good, but the email is completely bogus.
The full text of the phishing email: ------------------------------------------------------------------------
Account Info Verification
Dear FCU holder account,
As part of our security measures, we regularly screen activity in Federal Credit Unions (FCU) network. We recently noticed the following issue on your account: A recent review of your account determined that we require some additional information from you in order to provide you with secure service. Case ID Number: PP-065-617-349 For your protection, we have limited access to your account until additional security measures can be completed. We apologize for any inconvenience this may cause. Please log in to your FCU account to restore your access as soon as possible.
You must *click the link below* and fill in the form on the following page to complete the verification process.
Click here to update your account [http://protug.com.tw/secure/fcu/consumerinfo/update/update.htm]
In accordance with NCUA User Agreement, your account access will remain limited until the issue has been resolved. Unfortunately, if access to your account remains limited for an extended period of time, it may result in further limitations or eventual account closure. We encourage you to log in to your FCU account as soon as possible to help avoid this. We thank you for your prompt attention to this matter. Please understand that this is a security measure intended to help protect you and your account.
We apologize for any inconvenience.
Sincerely, NCUA Account Review Department
------------------------------------------------------------------------
Please do not reply to this e-mail. Mail sent to this address cannot be answered.
About NCUA
The National Credit Union Administration (NCUA) is the independent federal agency that charters and supervises federal credit unions. NCUA, backed of the full faith and credit of the U.S. government, operates the National Credit Union Share Insurance Fund (NCUSIF) insuring the savings of 80 million account holders in all federal credit unions and many state-chartered credit unions. During the 1990s and into the 21st century, credit unions have been healthy and growing. Credit union failures remain low and the Share Insurance Fund maintains a healthy equity level. The National Credit Union Administration (NCUA) is comitted to maintain a safe environment for over 80 million account holders in all federal credit unions and many state-chartered credit unions. Protecting the security of holders account and of the Federal Credit Unions (FCU) network is our primary concern.
NCUA Share Insurance Logo

