Users are tricked into handing over their information on a replica of the genuine website

Mar 4, 2013 19:11 GMT  ·  By

Barclays customers should be on the lookout these days for emails in which they’re informed that they have one urgent security message.

Entitled “You Have An Urgent Security Message !!!” the emails appear to originate from [email protected]. However, as millersmiles.co.uk shows, the address is spoofed.

When recipients click on the links contained in these emails, they’re taken to a compromised website which hosts a cleverly designed Barclays phishing page. On this site, victims are requested to provide all sorts of personal and financial information.

A similar variant of this phishing page was making the rounds back in April 2012. At the time, victims were lured to the malicious site via emails which informed them about a security maintenance process.

However, to make this latest variant (see screenshot) even more legitimate-looking, the cybercriminals have added a security warning in which they inform users that they will never ask for their passwords or PINs by phone, text, email or letter.

In order to avoid falling victim to such scams, be sure to check if the site you’re on is hosted on the legitimate Barclay’s Web domain. If you’re a victim of this phishing scheme, notify the financial institution immediately.