Security Alert - Malware Threat
A new computer malware dubbed “SpyEye” has been targeting local internet banking applications recently. When a customer tries to access his bank account from a computer infected with “SpyEye”, the malware will attempt to transfer funds out of his account to a fraudulent third party account. We would like to encourage all CIMB Bank customers to be alert to the potential risks of this malware and have put together the following commonly asked questions for your information:

How do I know if my computer has been infected with malware?

• You are prompted for your CIMB Clicks ID, Password and One-Time Password in the same web page.
• You will receive multiple prompts for your login information even after having entered your login credentials.
• You are re-directed to a bogus site where you are prompted to wait for 1-10 minutes for the system to check your information.
• You will receive SMS notifications for transactions which you did not perform, e.g. the addition of a third-party payee or a funds transfer that you did not initiate.

If you encounter any of the above scenarios while using CIMB Clicks, your computer is likely to be infected with the "SpyEye" malware. You should take a screenshot of the browser with the URL, close the browser and report the incident to CIMB Bank.

Please call CIMB At-Your-Service (+65) 6333 7777 or email atyourservice@cimb.com for assistance.

Afterwhich, you should refrain from using the computer for online banking services until it has been checked and cleared of the malware.

What should I do to keep my information safe online?

• Avoid using public computers (e.g. library or airport), shared computers or any computer that does not belong to you for online banking.
• Always enter the internet banking URL (www.cimbclicks.com.sg) manually into the address bar.
• Ensure that the security lock appears in the browser and the URL changes from http:// to https://.
• Read any SMS notifications that you receive carefully.
• Do not enter any token or SMS OTP for transactions you did not initiate or request.
• Ensure that you have the latest anti-virus updates on your computer.
• Perform a virus scan on any USB storage device (thumb drive or mobile phone) before uploading any information to your computer.