One week on from the tragedy of Cyclone Debbie Hitting the North East Coast state of Queensland in Australia, victims are being targeted by another tragedy. Last night security researcher Adam Bennett from the Red Piranha threat Intelligence team picked up a phishing campaign targeted at the already tired and battered people caught up in this natural disaster. Cyclone Debbie's 163km/h winds and more than 240mm of rain has effected nearly half the East Coast of Australia and caused multiple fatalities. Queensland Premier Annastacia Palaszcuk said the damage bill for Cyclone Debbie's trail of destruction in Queensland was expected to be in the billions.

The unsophisticated phishing campaign is a NAB (National Australia Bank) account reactivation letter sent via email. The email contains a link ““ that looks like a real National Australia Bank domain but the link “” will actually direct the target to another site hosting a fake NAB login page.

Sample of Email message used

Once the target has entered the credentials into the fake page the actors would then have access to the victims real account details.The Indicators of compromise have been reported to our friends via the Open threat exchange and we warn our clients not to click on links or open attachments from unsolicited emails at any time.

Fake Login page used to grab credentials

Date Published
April 05, 2017