This article was co-authored by Mitch Harris. Mitch Harris is a Consumer Technology Expert based in the San Francisco Bay Area. Mitch runs his own IT Consulting company called Mitch the Geek, helping individuals and businesses with home office technology, data security, remote support, and cybersecurity compliance. Mitch earned a BS in Psychology, English, and Physics and graduated Cum Laude from Northern Arizona University.
If you suspect an email that appears to be from Bank of America is in fact fraudulent, don't panic. These emails, called phishing emails, are actually sent to hundreds and thousands of people at a time in the hopes that one or two people will fall for the scam. As long as you learn how to recognize the signs of phishing, how to report it, and how to keep your information safe, you can protect yourself from identity thieves and scammers of all types.

This article was co-authored by Mitch Harris. Mitch Harris is a Consumer Technology Expert based in the San Francisco Bay Area. Mitch runs his own IT Consulting company called Mitch the Geek, helping individuals and businesses with home office technology, data security, remote support, and cybersecurity compliance. Mitch earned a BS in Psychology, English, and Physics and graduated Cum Laude from Northern Arizona University. This article has been viewed 189, 920 times.
Malicious Bank Of America (bofa) 'statement Of Expenses' Themed Emails Lead To Client Side Exploits And Malware
To report a Bank of America phishing email, start by forwarding it to abuse@bankofamerica.com and calling the bank directly to report the fraud at 1-800-432-1000. If you’re unsure whether you have a phishing email, look for signs like poor grammar and spelling, requests for personal information, or claims that your response is urgent. Additionally, a scam email will usually include a fake email address like @bankofamerica.us or @bankofamerica.net, as opposed to the legitimate domain name @bankofamerica.com. For more tips, like how to protect your personal information, read on!In the middle of June, security firm Armorblox observed a BOA phishing arrive in a customer’s inbox. The message informed the recipient that BOA was in the process of recycling its customers’ inactive email addresses. In support of this ruse, the attack email instructed the recipient to verify their email address by clicking an “Update email address” button. It warned them that the email address could become available to someone else, thus preventing BOA from sending important account information, in the event the recipient didn’t comply.
Clicking on the “Update email address” button embedded in the email message redirected the recipient to a phishing site designed to look like the Bank of America official login page.
The issue with the phishing campaign above boils down to the fallacy that an entity like Bank of America could recycle users’ email accounts.
Regional Banks Squeezed By Higher Interest Rates
Recycling email addresses in general isn’t a new practice. Yahoo is known to have previously recycled email addresses. This didn’t go so well back in 2013 when these email addresses’ new owners were still receiving messages for their previous owners. Some of those emails even contained passwords, according to Naked Security. In response to these issues, Yahoo and Facebook worked together to develop the Require Recipient Valid Since (RRVS) email security protocol, as Techlicious reported at the time.
But recycling email addresses makes a lot more sense for Yahoo because the organization is an internet service provider (ISP) that enables users to obtain a free email account. It directly deals with email services for users. As such, it’s in a position to interact with and/or recycle inactive email addresses if it so chooses.
![]()
The same cannot be said for the Bank of America. As a financial institution, BOA has the authority to ask that users update their emails and/or contact information. But it has no control to transfer an email address from one user to another.
Bank Of America® Customized Cash Back Rewards Credit Card
Armorblox noted that digital attackers had designed the attack emails specifically to trick users into overlooking that point. As its researchers noted in a blog post:
The sender name impersonated Bank of America, making the email likely to get past eye tests when people glanced through it amidst hundreds of other emails in their overflowing mailboxes. The email language and topic was intended to induce urgency in the reader owing to its financial nature. Asking readers to update the email account for their bank lest it get recycled is a powerful motivator for anyone to click on the URL and follow through.

The phishing emails described above made their way past email security controls for several reasons identified by Armorblox in its research. These included the following:
Warning: Bank Of America Giving Access To Random Accounts
The attack campaign described above wasn’t the first operation in which malicious actors sent out phishing emails that abused Bank of America as a lure. Back in the middle of June 2020, for instance, | AppRiver came across an attack email not dissimilar from the one described above. Via the use of spoofing tactics and social engineering techniques, that message claimed that Bank of America could not verify the recipient’s account information. It then instructed the recipient to confirm their contact information by clicking on a “Sign In” button and authenticating themselves.
Not every BOA-themed phishing email spotted in the wild has stolen the Bank of America’s branding to come across as legitimate. Indeed, | AppRiver also came across a more “subtle” email attack operation that lacked BOA’s logo. (The email message did use spoofing techniques to create the appearance that it came from the Bank of America, though. It also mentioned the financial institution several times in its body text.) Using the claim that BOA had detected unusual activity, the attackers used their email to pressure the recipient into verifying their account by clicking on a “Click Here To Securely Unlock Your Account.” The email warned that recipients would lose access to their accounts within 24 hours unless they verified themselves.

The | AppRiver team came across one more BOA-themed phishing email in recent weeks. Arriving only with the subject line “Important Message, ” the attack email informed the recipient that they needed to reconfirm their email address and mobile phone number in order to continue to process money transfers. The email also sought to assuage the recipient’s concerns by informing them how they could verify the message’s legitimacy:
Bank Of America Credit Card Customer Service & Contact Numbers
Want to confirm this email is from Bank of America? Sign in to Online Banking and go to Alerts. The Alerts History lists the Alerts sent to you in the past 60 days. To verify that this email is from Bank of America, confirm your last sign-in date is correct. To access Online or Mobile Banking, go directly to bankofamerica.com or use our Mobile Banking App.
The email included an “update contact information” link. Recipients who clicked on the link found themselves redirected to website designed to look like the Bank of America login page. That website concealed a phishing kit designed to steal a recipient’s credentials.

Organizations can defend themselves against phishing attacks such as those described above by investing in their email security. They can do this by deploying a tool that’s capable of scanning incoming messages for signs of known threat behavior. This solution should perform these analyses while allowing legitimate correspondence to reach their intended destination.
Posting Komentar untuk "Bank Of America How To Change Email Address"