‘Confirm UCount Reward Points’ Phishing Scam Email

Outline:
Email claims that you have accumulated over R8,500 in UCount Reward points and should therefore open an attached file to confirm a redemption request for your points.



Brief Analysis:
UCount is a rewards programme offered by South Africa’s Standard Bank. However, this email is not from Standard Bank. Instead it is a phishing scam designed to steal your bank account login details via a fraudulent webpage made to look like a Standard Bank website.

Example:
Subject: Confirm UCount reward points
Your reward points from shopping have accumulated over R8,500.
Please check copy below to confirm redemption request.
Online Ucount.Processing




Detailed Analysis:
According to this email, your UCount reward points from shopping have accumulated over R8,500. The email asks you to open an attached file to confirm a redemption request for the accumulated points.

UCount is a rewards programme offered by South Africa’s Standard Bank. The programme allows you to collect reward points while shopping with a Standard Bank card.

However, this email is not from Standard Bank and the attached file does not allow you to redeem your UCount reward points as claimed. Instead, it is a phishing scam designed to steal your bank account login details. If you click the attachment, a fraudulent bank login form will open in your default browser.  The form is on a webpage that has been designed to closely emulate the genuine Standard Bank website. If you login on the fake webpage, your username and password can then be collected by criminals and used to hijack your Standard Bank account.

The bank has published the following alert on its login page to warn customers about the scam:

Important security alert! Standard Bank will never ask you to access your UCount Rewards account through a link in an email. Don’t fall victim to fraud!

There have been several variations of this scam. If you receive one of these emails, do not click any links or open any attachments that it contains.

Standard Bank has published information about such phishing scams on its website.




Password Phishing Scam

Last updated: March 16, 2016
First published: March 16, 2016
By Brett M. Christensen
About Hoax-Slayer

References
Phishing Scams – Anti-Phishing Information
Standard Bank – Phishing Information