Halifax online banking attempted hacking

Has anyone else come across this recently? I logged into my Halifax online banking earlier this morning with usual username, password and memorable info (selected characters), all as normal, having arrived at the main screen with my various accounts it appeared greyed out with a popup box in front requiring all sorts of useful information including debit card number, expiry date, 3 digits on back, DOB etc etc. Right clicked and checked properties and it appeared to be a legit https address but obviously I didn't fill any of the information in and logged out of my account sharpish.

Just checked again on another PC and didn't get this and my account looks fine, no suspicious activities. Have virus-scanned the original Pc (with Avira), found something which it then quarantined, but a further login to Halifax still brings up this iffy popup.

Any ideas how to get rid of this please, or other useful advice?

Thanks.
Just because you used to be you think everybody else is, don't you?
«1

Comments

  • opinions4u
    opinions4u Posts: 19,411 Forumite
    Try installing and running the free version of Malware Bytes.

    http://www.malwarebytes.org/products/malwarebytes_free/
  • Try 'Trusteer Rapport'. Sorry cannot place links atm. Google it. Should be free to use.

    They are used by HSBC and the likes. Your browser could be hijacked. Make sure your Anti-virus is up-to-date. When running Malwarebytes. Best boot into Windows safe mode.
  • agrinnall
    agrinnall Posts: 23,344 Forumite
    10,000 Posts Combo Breaker
    Nothing to do with hacking, as o4u suggests it's probably malware on your PC. I wouldn't personally use Rapport, I would doubt the effectiveness of any software that has to be constantly forced on customers, if it was that good we'd be using it anyway.
  • Gromitt
    Gromitt Posts: 5,063 Forumite
    You might have a http://en.wikipedia.org/wiki/Man-in-the-browser somewhere hiding in your PC. Don't make any transactions as they can be altered between your PC and bank (such as changing the destination account, amount, and so on). Might also be recording your screen and key board, so might be wise to change your login details.

    Problem is, even if you get rid of the popup, there might be some other software still intercepting your banking. Only way to be sure when banking information is at risk is to reformat.
  • agrinnall wrote: »
    Nothing to do with hacking, as o4u suggests it's probably malware on your PC. I wouldn't personally use Rapport, I would doubt the effectiveness of any software that has to be constantly forced on customers, if it was that good we'd be using it anyway.

    I personally would not use Rapport either on the grounds I don't enjoy having anything monitoring my network activities - all AV-suites do this with their anti-phishing modules.

    It does however, have it's merits. It's designed for someone without much network security knowledge.

    I've used it before with no problems and I've seen others who used it in the past and had certain legitimate network activities/programs blocked.

    This software does advertise to work deep down, even blocking man-in-the-middle attacks, trojans, browser-hijack etc.

    Here's a good tech-link

    _ttps://krebsonsecurity.com/2010/04/a-closer-look-at-rapport-from-trusteer/

    (replace the '_' with a 'h')
  • Jim431
    Jim431 Posts: 139 Forumite
    Part of the Furniture 100 Posts Combo Breaker
    As someone has already suggested it is probably a Man-in-the-browser type attack.

    This has probably got into your browser. You don't say which browser you are using but you could try looking at the addins and plugins and try disabling anything suspicious.

    However it would probably be better to go to the control panel and just uninstall the browser completely and download a fresh copy.

    If you are using Internet Explorer then I would strongly advise you to move to another browser such as Firefox because their development community is far more pro-active in defeating attacks.

    Since becoming aware of this type of attack I now have a portable version of Firefox in a read only folder that I use for any secure logins.
    Also do regular spy-ware scans.
  • Try posting in the techie sub-forum on MSE.
    http://forums.moneysavingexpert.com/forumdisplay.php?f=29
    The experts on that board will be of considerable assistance in cleaning up your computer of wahtever is in it.
    In very bad cases of infection they sometimes recommend a total rebuild/factory restore of the computer.
  • dalesrider
    dalesrider Posts: 3,447 Forumite
    Ring Halifax get them to suspend your internet banking till this is sorted and then totally reset ALL details.
    PIA I know. But is the only sure way.
    Never ASSUME anything its makes a
    >>> A55 of U & ME <<<
  • Goldiegirl
    Goldiegirl Posts: 8,805 Forumite
    Part of the Furniture 1,000 Posts Rampant Recycler Hung up my suit!
    It does sound as if your browser has been hijacked.

    Just over a year ago my old PC was on it's last legs and all sorts of viruses were getting in. Fortunately for me I was just about to get a new laptop.


    I logged in to Paypal on the old PC, and got an overlay simlar to the one that you describe, asking for Social Security number, banking details and driving licence number.

    The fact that I had logged into paypal made it seem genuine, but the thing that rang alarm bells was that they were asking for American details, e.g Social Security number rather than National Insurance number, and Routing Code (which they actually mis-spelt as routine code) instead of Sorting Code number.

    Fortunately, my new laptop arrived, and when I logged into Paypal with that, there was no overlay. I changed my log in details, and had no further trouble.

    If you are not able to sort this out your self I'd suggest getting professional help in, at least you'd know for sure that your finances were safe.
    Early retired - 18th December 2014
    If your dreams don't scare you, they're not big enough
  • zeke
    zeke Posts: 461 Forumite
    Thanks for all the advice to date. Haven't had much of a chance to sort the affected PC to dater but I have changed my login details on another PC, the account seems OK so far. I'll try malwarebytes next, see what comes up. Yes my browser is IE, never tried anything else to be honest.
    Just because you used to be you think everybody else is, don't you?
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 349.7K Banking & Borrowing
  • 252.6K Reduce Debt & Boost Income
  • 452.9K Spending & Discounts
  • 242.6K Work, Benefits & Business
  • 619.3K Mortgages, Homes & Bills
  • 176.3K Life & Family
  • 255.5K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 15.1K Coronavirus Support Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.