Hi all, just to make you aware of a phishing email I received recently with the subject ‘Service Account Configuration Change Detected’. Luckily I spotted that the domain name for the sender was notifications@trading2l2.com. Notice that it is 2l2.com i.e. ‘2L2’ not ‘212’. Sneaky sods used a lowercase L instead of a number 1. Very hard to spot, so please be aware.
Contents suggested that a sizeable payment from my account was due in the next few days and that I should reply to the email if I had concerns.
Thanks for sharing this - that’s a very sneaky one. The lowercase “l” in place of the “1” is easy to miss, especially at a glance.
I’ve flagged it internally so the team is aware and take measures. Really appreciate you taking the time to warn others as well. This article may come in handy for anyone looking for tips on keeping their account secure: Stay Cyber Smart: Safeguard your Trading 212 account – Trading 212.
That is a clever phising attempt. I’m always concerned that in a moment of inattention that I may get caught by something like this. I’d like to offer some suggestions to you and everyone else to help mimimise risk.
Forward that email to report@phishing.gov.uk which is the official UK reporting mechanism. They should make an effort to block that email and domain.
For T212. Please keep an eye open for when that domain and similar domains become available and purchase them for the protection of your customers.
Use of a password manager can help if you get directed to a bogus domain and have to enter credentials. The password manager program will not be able to match T212 to an invalid domain. Of course, you then transfer much of your vulnerability to the password manager so make sure that you use a hardware key such as a Yubikey to secure the password manager.