Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
bank security

Chase Phishing and the XBALTI Kit: What the 2021 Report Means for Customers

A 2021 report described a Chase-targeting XBALTI phishing flow that collected more than login credentials. Here’s how to verify suspicious messages and respond if you entered information.

By TheFinanceBase Team 3 min read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A convincing Chase-branded sign-in page can collect more than a bank password—and a redirect to Chase afterward does not prove the page was genuine. A 2021 Cyren report, summarized by SecurityWeek, recorded a 300% increase in Chase-targeting phishing URLs in Cyren’s telemetry from mid-May to mid-August 2021. That was a relative change in URLs observed by one vendor, not a count of victims or all attacks, and it is not a current threat rate.

What the 2021 XBALTI report found

SecurityWeek reported on October 5, 2021, that Cyren had detected a 300% rise in URLs targeting Chase during the three months from mid-May through mid-August 2021. SecurityWeek also described Chase as the sixth most-targeted brand in those observations and as a close second to Office 365 among phishing kits Cyren collected during the preceding six months. Each figure belongs to that dated dataset; none establishes Chase’s present-day ranking or the number of customers affected. Read SecurityWeek’s account of Cyren’s findings.

The report described XBALTI as a phishing kit used against Chase and Amazon. In the analyzed Chase example, a fake page was hosted on a compromised Brazilian website. It asked for Chase login credentials, email credentials, further personal information, credit-card details and address information. The report said submitted details were emailed to the attacker and saved in an HTML file on the compromised site, before the visitor was redirected to the official Chase website. This describes the analyzed example, not necessarily every version of the kit.

A 2024 ACM CCS paper excerpt lists XBALTI among multi-target phishing kits and includes Chase and Amazon target instances in its dataset. That is a later research data point, not evidence that a live XBALTI campaign against Chase is active or prevalent now. See the available paper excerpt.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why a realistic page or successful redirect is not proof

Phishing pages can imitate a bank’s branding and sign-in flow. If a fake form sends information to an attacker and then redirects to Chase, the redirect happens after the information may already have been collected. Seeing a familiar Chase page afterward—or receiving no obvious error—does not establish that the earlier page was legitimate.

Judge the message by how you reached the sign-in page, not just what the page looks like. Do not follow an unexpected text or email link to sign in. Open the Chase app, type a Chase address you already know, or call a number you have independently verified. The FTC’s advice is: “If you think the message could be legit, contact the company or bank using a phone number, email, or website you know is real.” FTC: Protect yourself from phishing scams.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
Ideal for Gifting; Ideal for a bookworm; Compact for travelling
$10.99
SaleBestseller No. 5
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
It can be a gift option; Comes with secure packaging; Helpful in various ways
$9.15
Best Value
Sale
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
  • It can be a gift option
  • Comes with secure packaging
  • Helpful in various ways
Rank #2
Sale
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
  • Ideal for Gifting
  • Ideal for a bookworm
  • Compact for travelling
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do with a suspicious Chase message

  • Do not click, reply, or provide information. If you already opened a link, do not enter credentials or payment details. A message asking you to act urgently is still not a reason to use its link.
  • Verify through a known route. Use the Chase app or a website address you enter yourself, or call a number you already know is genuine. Do not rely on contact details supplied in the suspicious message.
  • Report suspected Chase phishing email to Chase. Forward it to [email protected], following Chase’s current instructions. Chase’s security guidance also advises stopping communication with suspicious senders.
  • Report it to the appropriate public channels. The FTC accepts fraud reports at ReportFraud.ftc.gov; suspicious email can also be forwarded to [email protected]. The FTC’s phishing guidance explains how to recognize and report phishing. Follow current instructions on each service.

If you entered information on a suspected fake site

  1. Contact Chase through a trusted channel promptly. Explain what you entered, ask how to secure the account, and review recent transactions. Follow the bank’s instructions; do not use contact information from the suspicious page or message.
  2. Change exposed passwords. Change the Chase password and any other account password that reused it. Use unique, strong passwords and turn on multifactor authentication (MFA) where available. CISA recommends these protections, but MFA is not a guarantee against phishing: some methods can be vulnerable if a fake page solicits a one-time code in real time. CISA password and MFA guidance and CISA guidance on phishing-resistant MFA.
  3. Take identity-recovery steps if identity details were exposed. If you provided a Social Security number or other identity information, use IdentityTheft.gov for steps tailored to your situation.
  4. Check the device if anything was downloaded. If clicking the link also downloaded a file or software, update your security software and scan the device, as the FTC recommends. FTC: What to do if you were scammed.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Money Desk

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.