ALKHOBAR, 27 December 2005 — On Sunday, the Samba Financial Group became the target of a “phishing” attack. E-mail directed users of Samba Online banking services to proceed to an “authorization page” where they would be assisted in measures to increase their level of security in regard to Samba’s Internet banking transactions. A link in the e-mail led to the site, www.sambaonlineaccess.com, which had been registered on Sunday specifically for use in the attack. At the site, a registration form requested such details as user name, password and national ID number. The intention of the fraud was to steal financial and personal information from Samba customers.
After being notified of the phishing attack, the Internet Services Unit at KACST blocked the URL. As of yesterday afternoon, however, www.sambaonlineaccess.com was still live and could be accessed by anyone outside of Saudi Arabia. This is of particular concern to Samba customers who may be traveling abroad at this time and while accessing their e-mail might respond to the fraudulent request for information. Samba has not made a specific announcement in regard to Sunday’s phishing attack. They are however aware of the threat and have long posted guidelines at the Internet Security section of www.samba.com.sa.
Phishing attacks are global threats.
Phishing is a variation on the word fishing. Criminals “phish” for personal information by setting out hooks and hoping that some recipients of their fraudulent e-mails will take the bait. According to Aberdeen Group, identity theft worldwide is expected to cost consumers, businesses and government organizations $2 trillion by the end of 2005. “Not only Samba Financial Group but banks and other institutions worldwide have been targeted in phishing attacks,” said Mirza Asrar Baig, CEO, IT Matrix, a local network security provider. “The banks in Dubai and their customers have already been victims of phishing attacks. The criminals are improving their techniques and looking for ‘bigger fish,’ so it is to be expected that Saudi Arabia’s consumers and financial institutions will be targets.” Sunday’s attack was well put together. The Arabic used in the phishing attack’s e-mail was excellent. The criminals had attempted to duplicate as much as possible the “Samba style” in the design and even fonts used in the e-mail and fraudulent website. Samba does emphasize on its own website though that users of its online banking services should never give out their personal or financial information in response to an e-mail.
“The Saudi Arabian Monetary Agency and all the banks have been discussing the need to run national level awareness campaigns to inform consumers of such criminal activity as phishing attacks and other online fraud,” commented Baig. “With Sunday’s attack, the potential for victimization of the Kingdom’s consumers has become quite real. The best tool to defend against phishing is user education. Online banking customers should be aware that banks would never send out an e-mail asking them to provide personal information. Be aware to be more secure.”

