Site navigation

Monzo Phishing Campaign Targets Online-banking Customers

David Paul

,

Monzo phishing campaign
A new campaign has targeted online banking users of the popular UK fintech to steal credentials, research has found.

A sophisticated Monzo phishing campaign appears to be targeting the UK bank’s online customers.

According to new research, the digital banking platform is suffering an ongoing phishing campaign targeting Monzo users and attempting to steal their accounts.

Security researcher William Thomas released a new report discussing the Monzo phishing campaign, funding that cyber actors are targeting the bank’s “golden link”, which is sent to users for them to login to for the first time.

The digital bank has become increasingly popular in the UK as it allows users to open an account without having to visit a branch. Users simply apply, receive their golden link and sign up.

In a new report, Thomas explains hackers begin the phishing process by taking a user’s email address and then a series of other pieces of private information.

“It first takes your email, then collects your email account credentials, then asks for your Monzo PIN, followed by your name and phone number,” Thomas said.

“These details are enough to compromise a user’s email account and Monzo account,” he added.

If users provide the requested details into the online form, threat actors have started the process of gaining and taking over a user’s account.

According to Thomas, when installing the Monzo app on a new device, like the threat actor’s smartphone, the service sends the “golden link” to the new device with a verification link.

With access to victims’ email accounts, hackers can simply click on this link and verify their device, giving full access to the Monzo account.

“Additional social engineering steps might be involved, but there are many one-time passcode (OTP) stealing bots and other guides on how to trick victims into giving up access to the attacker,” Thomas added.

Thomas said the threat actors are using the Cazanova Morphine kit to create the Monzo phishing landing page.

In addition, he added that four domains were noticed on the same ASN, which targeted users of Revolut, a popular online payments service.


Recommended


“Research into the domain itself via URLscan.io uncovered 33 other identical sites, dating back to 11 November 2021,” Thomas said in his blog post.

“All 34 domains were hosted on the same three CIDRs in Russian IP space with NForce Entertainment (AS43350). Interestingly, the Monzo-themed domains also used two Guangdong-based Registrars (Eranet and NiceNic).”

Monzo had already been revealed as having bad security when it comes to online services, according to a study.

Consumer watchdog Which? saw viewed the security system protocols of fifteen banks tested by a team of volunteers, while cybersecurity firm 6point6 deployed experts to test defences across September and October last year.

In mobile banking, Monzo came last, on 46%. It scored three out of five in login and encryption, four out of five for account management, but only one out of five for navigation and logout.


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

David Paul

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data