A live site phishing demo. The target is a small Federal Credit Union in Hawaii. The fake website was asked to be taken down by the author after this demo. The author compares the two websites and finds out that the original website has been registered since 1995 and the fake website was registered just 2 days before launching the phishing attack. The look and feel of the site is the same as the original one. Only minor difference (which can easily be overlooked) is an extra alphabet “i” in the url. The original website is http://hawaiiusafcu.com/ and the fake one has the url http://hawaiusafcu.org/
Infective banner ads are not new, but it’s not so common for them to come with major websites like mlb.com and nhl.com. This video shows how easily even major websites can become victims too, and how difficult it is for them to prevent it.