joomla / joomla-websites

This repository is for reporting issues with the joomla.org websites only. Please report issues with the Joomla CMS at https://github.com/joomla/joomla-cms/issues/new
45 stars 50 forks source link

[forum.joomla.org] Website Phishing of Bank Negara Indonesia Takedown/Suspend #1990

Closed DerrellH closed 1 month ago

DerrellH commented 1 month ago

To Whom It May Concern,

I'm from copyright owner. Our Trademark for copyright you can check here: https://pdki-indonesia.dgip.go.id/search?type=trademark&page=1&keyword=BNI

I am writing to report a phishing project that is using your servers. I have conducted a thorough investigation of the project and have found the following evidence that it is a phishing project:

webbio.today

The website uses a design that is similar to the design of a legitimate website. The website requests personal information from users, such as usernames, passwords, and credit/debit card numbers.

The project uses the following URL:

webbio.today/Gebyarbni/login.html

Please suspend the URL

and also suspend the domain:

webbio.today

I am concerned that this website is posing a serious threat to the security of your users. I urge you to immediately suspend the website and take steps to prevent it from being used to steal personal information from users.

Thank you for your time and attention to this matter.

Thanks & Best Regards,

DRH

CTI Team | SOC Dept. | CISO Division Menara Grha BNI Jl. Jendral Sudirman No. 1, Karet Tangsin, Kec. Tanah Abang, Kota Jakarta Pusat - 12910 Mobile : +62 858 3800 2919

Simulator Screenshot - iPhone 15 - 2024-04-05 at 11 17 38

HLeithner commented 1 month ago

Hi @DerrellH

I'm sorry to hear this, but unfortunately we, as Joomla CMS / Open Source Matters, doesn't host any 3rd party websites at this time. The Website you see is the joomla CMS but the CMS is free Software and can used by almost anyone.

To your report, the Domain you linked is registered at namecheap, you may can reach them at abuse@namecheap.com or find a contact form at there website. The Website ist self is hosted at OVH at least that's the information I get for the resolved ip 51.68.147.13.

I'm closing this because we can't help you. If you think I miss anything please don't hesitate to add a comment here.

kind regards Harald

/cc @crystalenka @carcam