Phishing Lessons from Barclaycard

I just bought a new hard drive online. As part of the payment process I was redirected to a Barclaycard site that asked me for a few additional details and then signed me up for their new online payments security scheme. So far so good.

They then sent me an email. An HTML email containing a link I could follow to log on to their secure server. Actually the mail didn’t come from a Barclaycard domain but from securesuiteemail.com who I’ve never heard of. So basically they sent me a mail which, apart from the fact that the links really do go to their site, is indistinguishable from ten phising emails I get every day.

Maybe it’s just me but I’m not convinced that by encouraging people to trust this kind of mail they’re really doing their bit to educate hapless web users about the perils of phishing.


Copyright Andy Armstrong, 2005. Entries (RSS) and Comments (RSS).