Skip BreadcrumbHome / Security / False messages with only an attachment - Do not open the links

False messages with only an attachment - Do not open the links


We have been alerted concerning e-mail messages with the subject
“Segue o documento em anexo”, (The document is hereto attached),
without any text or request, containing only an attachment, supposedly a Word file.

Example of the fake e-mails received:

 

and

 

These are Phishing attempts wherein, when you open the link sent,
you install malicious software without even knowing it.

After this malware is installed on your device, we verified that, when you login to millenniumbcp.pt,
you get a web page identical to the Bank's website and a pop-up, warning that you need to install
a security module “Instalação do Módulo de Segurança”, asking you to enter your Multichannel Code,
afterwards sending a text message with an Authorization Code, as per the screen images below:

 

 

Clique para aumentar Clique para aumentar Clique para aumentar Clique para aumentar

 

Following this phishing of the User's access codes, the cyber-criminal requests the
installation of the App Code Generator, allegedly for protection against frauds.

By installing this app, the smartphone/tablet gives access to personal data,
among which the contents of text messages, as follows:

 

(This App was already removed from the stores.)

 

 

Please reminded that...

To access Millennium bcp's homebanking services the Bank NEVER requests your mobile phone number or the installation of security software;
Whenever you access your bank accounts through the Millennium bcp website, check if the address starts with https://ind.millenniumbcp.pt/ (for the Individuals access) and https://emp.millenniumbcp.pt (for the Companies access) and that, at the end of the address bar, a lock is shown, as follows:

Endereços

Millennium bcp always sends electronic messages without links;
The Millennium bcp's website is accessed using a User Code and three random positions of the Multichannel Code and Millennium bcp never requests the installation of software/security apps (or other), therefore any such request is a fraud attempt;
Carefully read the SMS received containing the Authorisation Codes since the transaction data are identified in the SMS;




Additional information

  • Phishing aims to, abusively, steal personal data through messages that take the user to fake websites, imitating those you usually access and requesting that you enter confidential data;
  • Analyse the e-mails you receive before opening them, always confirming the source, the subject and the spelling and, if you remain with doubts, delete the e-mail without opening it;
  • Avoid opening links to external websites as well as opening executable files;
  • Never provide personal information or data in an e-mail reply;
  • Install (if you haven't done so yet) an antivirus software and update it regularly.




Remember: The protection of your assets and of your computer depends on you!





If you ever find something out of place at www.millenniumbcp.pt/en or if you need further information
please call us on 91 827 24 24 / 93 522 24 24 / 96 599 24 24 / +351 21 005 24 24 (from Portugal or abroad)
(Personal Assistance 24/7).



Individuals - Security information Companies - Security information

 

​​