First Google Result Isn't Always Real: How Scammers Forge Bank Websites
Translated from Lithuanian, summarized and contextualized by DistantNews.
At a glance
- Scammers are creating fake websites that mimic legitimate bank and government sites to steal login credentials.
- These fake sites are visually identical to real ones, making them difficult to detect, even for experienced users.
- Users are warned to verify website addresses carefully and not to automatically approve phone-based security requests.
Cybercriminals are increasingly using sophisticated phishing tactics to defraud individuals in Lithuania, with fake websites designed to mimic trusted institutions like banks and government agencies. These fraudulent sites are visually indistinguishable from legitimate ones, making it difficult for even experienced users to spot the deception. According to M. Kutkaitis, an expert, scammers exploit the common practice of users accessing services through search engines. By entering search terms like "X bank" or "Sodra," users may click on the first available link, which could lead to a malicious site.
The National Cyber Security Centre reported that its DNS firewall blocked approximately 59,000 attempts daily in March, indicating the scale of these attacks. Scammers meticulously replicate official logos, colors, and even text. The primary indicators of a fake site often lie in the URL itself, which might be longer, contain extra symbols, or have unusual endings. Kutkaitis advises users to be wary of addresses like "bank-login-secure123.com."
Beyond simply entering login details, users who fall victim to these scams may be prompted to approve actions on their phones in real-time. Kutkaitis stresses the importance of not automatically confirming phone requests. Users should only approve actions they have initiated themselves and understand the purpose of the transaction. Unexpected requests, especially when not actively using a banking service, should be a red flag to stop and investigate.
While secure connections (HTTPS and a padlock icon in the browser) indicate encrypted communication, they do not guarantee a site's legitimacy. Scammers can also utilize these security features. Therefore, the most crucial defense is critical evaluation and vigilance. Kutkaitis emphasizes that checking the domain name itself is paramount to ensure one is on the official institution's website. This scheme is not limited to banks; fake sites are also created for utility companies, government portals, and tax agencies, leading to rapid data theft and account takeovers.
Originally published by Delfi in Lithuanian. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.