Which? and DNS Research Federation find more than 2,000 copycat bank website URLs reported in 2023

Research published by Which? and the DNS Research Federation found more than 2,000 web addresses imitating UK bank brands were reported to a phishing blocklist in 2023.

Which? and the DNS Research Federation (DNSRF), an Oxford-based non-profit that researches domain names and internet governance, published findings on 26 March 2024 on copycat bank websites reported during 20231. The DNSRF searched a specialist phishing blocklist for addresses containing a list of UK banking brands supplied by Which?, and separately examined the ScamAdviser blocklist1.

More than 2,000 URLs containing the specified UK bank brands were reported to the phishing blocklist in 2023, according to the findings1. The affected banks were Barclays, HSBC, Halifax, Lloyds, Monzo, Nationwide, NatWest, Santander and Starling1. On ScamAdviser's blocklist, which was filtered to URLs with a "trustscore" of less than 50 out of 100, more than 2,000 URLs containing the brand names were also found1. Copycats mimicked the same brands as in the phishing blocklist, with the addition of Clydesdale1. Across both blocklists, the words Santander and Barclays appeared the most1.

Which? said the data is inexact and experimental1. TSB was excluded from all results because it proved a common string of letters that generated many false positives, such as mattsbong.com, seemingly unrelated to banking scams1. Which? said it was impossible to view and check that the sites were genuinely fraudulent because they had already been taken down, and that copycat sites not on blocklists may have been missed, as some are active only for days or hours1. It cited the Global Anti Scams Alliance State of Scams Report 2023, which found 59% of victims did not report their scam experience to the police or authorities1.

Which? said all five banks it approached, Santander plus the big four groups Barclays, Lloyds, HSBC and NatWest, responded and confirmed they employ tools to monitor for sites impersonating their brands and issue takedown requests1. NatWest Group said it employs Netcraft, a specialist takedown provider, and works directly with the internet service providers TalkTalk and BT Group because both are willing to block fraudulent domains on their networks1. NatWest told Which? this amounts to about 15,000 sites taken down per month, reaching 37,000 at its peak1. The bank said that in most cases it cannot act purely on the basis of a domain registration containing its brand name, as it may have a legitimate purpose1.

"It's an industry where consumers' voices aren't strong, even though it's consumers who are badly hurt by rogue sites."

Which? reported that the domains industry operated, and continues to operate, on a first-come-first-served basis, and that at the time of writing the industry continues to self-regulate1. It said the UK government is currently consulting on new powers to seize domains being used for criminal purposes1.

Why it matters for households

Copycat bank websites are used in impersonation scams: Which? said fraudsters collect details such as account numbers from unsuspecting bank customers and later use them to con the same people into sending money, often by posing as bank staff1. Customers of Barclays, HSBC, Halifax, Lloyds, Monzo, Nationwide, NatWest, Santander and Starling were among the brands imitated in the phishing blocklist data for 2023, with Clydesdale also appearing in the ScamAdviser data1. Which? said that although banks attempt to get lookalike websites taken down, the number being registered, and sometimes inadequate responses from the firms that register domains, mean the sites stay up long enough to find victims1. The findings cover reported URLs for 2023 and do not set out how many people lost money or how much.

Which? set out steps it says reduce the risk of landing on a fake banking site, including avoiding links and numbers in emails, texts and instant messages and instead using contact details from a bank card or statement, paying attention to browser warning screens, and using a domain lookup service such as Who.is to check when a site was registered1. It said scam sites can be reported to the National Cyber Security Centre, and that victims of fraud should report it to Action Fraud, or call the police on 101 in Scotland1. More on how these approaches work is set out in our guides to fake websites and online shopping scams and phishing, vishing and smishing.

What happens next

The UK government is consulting on new powers to seize domains being used for criminal purposes, according to Which?1. No outcome or timetable for that consultation is given in the article1.

Sources1 cited
  1. Beware the scammers imitating bank websites - Which? which.co.uk