Metro Bank's customers who have received the "Debit Notification" email alerts like the one below are asked not to follow the instructions in it. This is because the link in the fake email alert will only take the recipients who have clicked on it to a phishing website, looking like Metro Bank’s website, where they will be asked to sign-in with their account credentials. But, once the potential victims attempt to sign into the fake website, their credentials will be sent to the cybercriminals behind the scam, who will use it to gain access to their victims’ accounts. Once the cybercriminals have access to their potential victims' accounts, they will steal their money and use their accounts fraudulently.
The "Metro Bank Direct Debit Notification" Phishing Scam
From: Metro Bank
Sent: Friday, 2 February, 21:35
Subject: Metro Bank : Direct debit notification
To: Recipients
Go online to view changes to your balance hxxp://metrobankonline.co.uk.irantg.com/
It is important for Metro Bank's customers to remember that they should never click on a link to sign into their online accounts, especially links in email messages. The safest way to sign into their online accounts is to go directly to www.metrobankonline.co.uk in their web browsers or search for "Metro Bank" using a popular search engine. If there is something wrong with their accounts or there is something that they need to do, they will be notified right after signing in.
Recipients of phishing Metro Bank emails like the one above, who have clicked on the link in them and have attempted to sign into the phishing website they were taken to with their accounts’ credentials, should change their passwords and contact Metro Bank immediately.