October 13, 2005

One Time Password Phished

The Register reports that a Swedish internet bank was forced to shut down its website for a short time last week after its one-time password security system was targeted by a new type of phishing scam. Last  week, according to a blog posting by Finnish security firm F-Secure, fraudsters targeted customers of online bank, part of Nordic financial services group Nordea.

Recipients were directed to several fake websites, thought to be based in South Korea, and asked not only for their account details, but also for the next password on their list of one-time passwords.

F-Secure explains that Nordea’s online banking customers are given a scratch sheet, which contains a certain number of hidden passwords. As customers use the service they uncover the next password in the list, which gives them access to their account.

According to F-Secure: “Regardless of what you entered, the site would complain about the scratch code and asked you to try the next one. In reality the bad boys were trying to collect several scratch codes for their own use.”

The bank discovered the attack last Monday night, and shut the site for around twelve hours.

This is said to be the first time that a phishing scam has targeted such a password system, which is intended to be more secure than a normal fixed-password scheme.