Your Peace of Mind is our Commitment

Contact Us English Recent Articles

HSBC Phishing Detection Challenge

First published: 26th April 2016

We are often told to watch out for suspicious emails, but what is suspicious? Could you tell the difference between a real and fake notification from your bank? This challenge uses a real and a fake notification "from" HSBC bank to a 'Business Direct' account holder, see if you can tell which is which. Black rectangles have been used to obscure customer information in the screenshots.

Notification A

This email:

Has a link to this webpage:

Notification B

This email:

Has this webpage attached:

What is the Risk?

HSBC Business Direct accounts use a security device that generates six-digit codes that must be used in conjunction with the user's password to log into the HSBC website. Neither of these notifications asks for the security device code, so not enough information is collected to enable unauthorised transactions. However, this does not mean the money in the account is safe, this may be the first step of a multi-stage attack. Alternatively, the target might not be the HSBC account at all, but the victim's email account.

The Answer and Comments

Notification A is the fake. What doesn't help us distinguish between them?

What might help:

In this case, if the fake notification successfully tricks the end user, the attacker will have access to their email account. HSBC is not responsible for keeping your email account secure. However, Banks might benefit from taking a wider view of helping their customer's overall security. Very often, when looking at suspicious messages, we are not certain about the attacker's ultimate objective. In this case, if the attack is successful, the attacker will be able to access the victim's email account, and will know they have an HSBC Business Direct account. How will they seek to monetise that information?

Updated: 06th May 2016

Commercial Banking at HSBC commented:

We would like to explain that protecting our customers' information is our main priority.

If you receive any suspicious e-mail in the future, please report to us by sending e-mail to [commercialbanking@hsbc.com.hk] or call our Commercial Banking Service Hotline on (852) 2748 8288, press #-7-6 after language selection.

Updated: 13th June 2016

In a further reply, Commercial Banking at HSBC added:

We would like to explain that protecting our customers' information is our main priority.

You can refer the following links for more details:

[www.business.hsbc.com.hk/en-gb/resource-centre/online-security]
[www.business.hsbc.com.hk/en-gb/hk/campaign/cyber-crime-protection]


Gallery

E-mail AE-mail A hi-res
Notification ANotification A hi-res
E-mail BE-mail B hi-res
Notification BNotification B hi-res

More Information