19 April 2023
Cyber security
19 April 2023
Cyber security
Lately, there have been very frequent offers from retail chains and various online stores where goods and services are much more affordable if you make the purchase online. This trend has been present globally for a long time, and since a few years ago, it has not bypassed Serbia either. You have probably heard of Black Friday, the popular shopping holiday, or Cyber Monday, a day when shopping is done online with various benefits.
Discounts and promotions for online purchases have become common, but unfortunately the information overload, as well as the times we live in, make our attention lower than adequate, which altogether gives the opportunity for various internet "pickpockets" to steal our money and data.
The latest in a series of frauds is the possibility of a very favorable purchase of "Antistress Mattress", dimensions 160x200cm. Very favorable, for sure, it would only cost you all your personal data and money from the account.
Namely, when you decide to buy this item via the link you received, you have the option to choose your bank and pay for what you want. Rest assured that the same scam exists for various other items, not just the mentioned mattress, but this one with the mattress is the most recent one we have detected. The image you see is the authentic image of the page that was part of the scam a few days ago.
The probability that you have an account in one of the banks on the list is huge, so if you are not extremely careful and you know from personal experience that this is not a practice for online shopping, you will click on the icon of your bank.
When you click on your bank's icon, a window opens that looks identical to your eBanking. In the case of Erste Bank, it is the following picture. And no, this is not a picture from our eBanking, but an excellent copy. The layout of the page has been specially adjusted for each of the banks on the list, so if you are a client of another bank and you click on another icon, you will get the view of the eBanking page of that specific bank.

We have to admit that this scam was executed masterfully, and that only extremely careful people checked the address field and saw that they were not in their bank's eBanking, but in an unknown location.
The first thing that should be suspicious in this case, in addition to the fake address, is that there is no https protocol, and that it requires logging into eBanking, instead of the usual payment card entry or QR code scanning.
Logically, you are asked to enter your details, username and password. If you do that, you will not be able to pay for the mattress at that moment, but you will give the fraudsters your access data and subsequently they can actually log in to your eBanking and dispose of your money and all the data that exists there.
It can be a really big problem, and that is why with this text we appeal to everyone to be very careful when performing any internet activity, and to always be skeptical about data protection. In this particular case, the competent colleagues were urgently notified of the existence of this fraud and managed to "take down" the disputed site that collected data in record time, but it is only a matter of time when something similar will appear again.
Internet scams have been increasingly common and harder to recognize, and unfortunately the scammers are getting more and more skilled at what they do. In order to protect ourselves and shop safely, taking into account the recommendations regarding the protection against the corona virus, but also the potential attackers on our data and money, see the tips below.
Eight Tips for Safe Online Shopping