Hot on HuffPost Tech:

See More Stories
AOL Tech

Users of Online Bill Pay Service Redirected to Ukranian Virus Site



Do you use CheckFree.com to pay your bills online? Maybe you noticed something fishy going on with the Web site if you tried to log in during the overnight hours last week. Users of the site were redirected to a Ukrainian Web site that attempted to download malware onto their computers. It was a blank Web page with a simple login and password line, so we doubt many users were fooled – at least we hope many users weren't fooled into providing their private information.

It seems a hacker got a hold of CheckFree's domain registrar information and changed where Internet servers would direct users who typed in the company's Web address.

According to CheckFree's domain registrar Network Solutions, someone logged in to CheckFree's account using all the right information. This means Network Solutions itself wasn't hacked. Somehow, someone out there got the real login and password information that CheckFree uses – and is supposed to keep secure and private – to manage its Web domain name.



Were CheckFree's users put at risk? The quick answer is yes – and CheckFree's statement that "that the attack occurred during off-peak hours when customer traffic to its Web site is typically low" isn't too reassuring.

Surprisingly, CheckFree says the malware wasn't set up to gain access to people's bank accounts. Instead, it was a simple effort to gather logins and passwords that people keep or use on their computers.

Mike Haro, senior security analyst at Sophos told the folks at CNET News, "The fact that they used a blank page to download a Trojan (not exactly subtle) says to me one of two things: a) they fell into these credentials and chose the fastest way to get something done, expecting the breach to be quickly detected; or b) they got more than we're being led to believe."

We've written about CheckFree before. We like their innovative approach to online bill pay and the fact that you can pay more than 300 different kinds of bills through them. But convenience doesn't matter when security goes by the wayside. [Source: CNET.]

Tags: billpay, checkfree, malware, security