Clients of Banco Nacional, Costa Rica’s largest bank in terms of deposits and account holders, were targeted this weekend by an email phishing attack that was detected by members of the financial institution’s online security team after some of their customers reported suspicious activity.
The official announcement was posted on bnmascerca.com, which is Banco Nacional’s online portal for press releases, on Monday afternoon. The press release explained that the attack was identified around 11:00 am. By 11:45 am, Internet-savvy clients contacted the bank and reported that one of the fake websites set up for the phishing attack was hosted at the following uniform resource locator (URL – Web address):
![]()
The BN Seguridad team stated that they were working with Internet security firms and service providers to take the adequate measures against this attack. Major Internet service providers ICE and RACSA were blocking access to the malicious website on their networks.
One client who contacted Banco Nacional on their Facebook Timeline explained that the phishing email was very well-designed and even used the bank’s branding, color scheme, slogans, style of graphics, and font. Although specific details about the content of the dodgy email message and the counterfeit Web page were not released, a client expressed was concerned that this particular phishing scheme went as far as to ask details about the victim’s token device that is used to generate one-time access codes.
Microsoft provides the following definition of this cybercrime scheme:
Phishing email messages, websites, and phone calls are designed to steal money. Cybercriminals can do this by installing malicious software on your computer or stealing personal information off of your computer.
Cybercriminals [may] also use social engineering to convince you to install malicious software or hand over your personal information under false pretenses. They might email you, call you on the phone, or convince you to download something off of a website.
Of particular concern is the fact an RSA SecurID software token was cloned by an Internet security researcher in 2012. Writing for technology news website Ars Technica, Dan Goodin explained that this kind of cloning could be applied to lost or stolen smartphones that run soft tokens. Although Banco Nacional does offer software tokens that may be installed on smartphones and tablets, Internet banking clients are encouraged to use the black plastic hardware tokens that can fit in a keyring. The security measures of Banco Nacional’s Internet banking portal are extensive to the point of being frustrating, but the bank can boast that this secure system has never been breached.
Banco Nacional reminds clients that confidential information such as Internet banking access codes are never asked by the bank via email; therefore, any email messages that request this information should be immediately reported to BN Seguridad or to any bank employee. Moreover, clients should never click on any links contained in a suspicious email.




