SCAM ALERT - Fake HDFC Bank Email - InstaAlerts: YOU'RE A/C ONHOLD

206°
Deal Cadet
budweiser

image

Expired
23 Comments  |  
12 Dimers
  • Sort By
Deal Cadet Deal Cadet
Link Copied

Instead of posting here, you should alert HDFC via Twitter.

I request you/the admin remove the link immediately.

Deal Newbie Deal Newbie
Link Copied
budweiser wrote:
Sender email id is not shown in mobile.
Modi: Youth hee desh ka bhavishya hsi.

Youth:
Benevolent Benevolent
Link Copied
ArasuS wrote:

Instead of posting here, you should alert HDFC via Twitter.

I request you/the admin remove the link immediately.

they do nothing. they will just say avoid clicking suspicious links and don't share opts. 
Deal Newbie Deal Newbie
Link Copied
Expand
Simbha3 wrote:
avoid clicking suspicious
Woh tou Kingfisher ne sabse pehle click kar di

aur janta ko bhi bata raha hai
ki yeh link hsi!

Matlab ab aur bhi paglo ko potential trap mei jaaney ka su'avsar prapt hoga!
Deal Cadet Deal Cadet
Link Copied

Vu and KG++

Critic Critic
Link Copied
Expand
Simbha3 wrote:
they do nothing. they will just say avoid clicking suspicious links and don't share opts. 
Reported the site & will update here tomorrow.
Deal Cadet Deal Cadet
Link Copied

Got the same mail, for a moment I thought it was genuine as my account is kind of actually blocked right now 😅

But just to be sure I checked the mail id first and it was some .nz mail id 


Deal Newbie Deal Newbie
Link Copied
dealpanda wrote:
But just to be sure I checked the mail id first and it was some .nz mail ID
Although possibly different for different victims, still
if you can share the address.

So that others can sense Amy pattern.

And those using browsers, even on the mobile site), can check sender details by tapping on 'view original message' or some such thing in your e-mail provider's site.

For gmail, using the basic html interface does it. https://mail.google.com/?ui=html.

Deal Cadet Deal Cadet
Link Copied
Expand
praveersavarkar wrote:
Although possibly different for different victims, still
if you can share the address.

So that others can sense Amy pattern.

And those using browsers, even on the mobile site), can check sender details by tapping on 'view original message' or some such thing in your e-mail provider's site.

For gmail, using the basic html interface does it. https://mail.google.com/?ui=html.

Mail id of the sender is [email protected] .co .nz

Deal Subedar Deal Subedar
Link Copied

This is why 2FA is required...

Mobile Guru Mobile Guru
Link Copied

Always pay attention to the URL (domain name in particular*) while logging into banking websites

https:// subdomain (netbanking / cards). domain( same as official site, hdfcbank in this case) .com

netbanking. hdfcbank.com - 

hdfcbank. netbanking.com -  ❌

Anything else - ❌

Deal Newbie Deal Newbie
Link Copied
Agnivo007 wrote:

This is why 2FA is required...

Can end up giving a false sense of security, when things really end up going down south in reality.
Deal Subedar Deal Subedar
Link Copied
Expand
praveersavarkar wrote:
Can end up giving a false sense of security, when things really end up going down south in reality.
Still one gets OTP/TOTP as additional layer of security even if account userid/password is phished...
Deal Newbie Deal Newbie
Link Copied
Expand
Agnivo007 wrote:
Still one gets OTP/TOTP as additional layer of security even if account userid/password is phished...
Not about banks, but in so far as lesser stuff like shopping portals are concerned, have had confirmed cases of (even Dimers) people loosing access to hackers despite two-factor.
Critic Critic
Link Copied

Update: site taken offline after my complaint to domain registrar.

Blogger Blogger
Link Copied
guest_999 wrote:

Update: site taken offline after my complaint to domain registrar.

Great job!

Hdfc display some customized message also.. after entering user ID.

Most of the times to see balance login OTP is a problem...better to have some option like display message

Critic Critic
Link Copied
Expand
hese wrote:

Great job!

Hdfc display some customized message also.. after entering user ID.

Most of the times to see balance login OTP is a problem...better to have some option like display message

Yes there is a security image option enabling which results in display of that security image(which you chose) after entering user id to confirm you are on genuine hdfc netbanking page(phishing websites won't have that customized security image linked with your user id).
Deal Lieutenant Deal Lieutenant
Link Copied
guest_999 wrote:

Update: site taken offline after my complaint to domain registrar.

How to complain?
Deal Newbie Deal Newbie
Link Copied

Reporting these kind of things is pain in the ass. Banks should make it easier to make a complaint with regards to phishing and spams instead of asking a user to fill a form with long list of details.

Critic Critic
Link Copied
Expand
rohan8397 wrote:
How to complain?
You need to use whois site to find the domain registrar of the website & then complaint to the domain registrar using abuse email mentioned in whois data or finding their "contact us/report abuse" option on domain registrar website.
replyuser
Click here to reply
Reply