EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/cyberattack/tinba
345/430

File EL-0086HighColdCyberattack / Phishing Campaign

Tinba

Also filed as Tinba Phishing Campaign

Tinba was a phishing campaign targeting banking users, primarily active around early 2012. The attack aimed to steal login credentials and sensitive financial information. It utilized deceptive websites mimicking legitimate banking portals to trick victims into submitting their data.

  • #phishing
  • #banking
  • #credential-theft
  • #malware
  • #2012
Notoriety4/10
Event
1 Jan 2012
Disclosed
1 Jan 2012
Target
Banking Users
Status
Cold

01Summary

The Tinba campaign represents an early example of targeted financial phishing against banking customers. Attackers created highly convincing, yet fraudulent, websites designed to look identical to major financial institutions' login pages. Victims were lured to these sites, often through deceptive emails or malicious links, where they were prompted to enter their usernames, passwords, and sometimes other personal identifiers. Once the credentials were captured, the attackers could use them to access and potentially drain the victims' bank accounts. Due to its early nature and lack of specific public documentation, the full scope and technical details of the campaign remain largely unverified in major public threat intelligence databases.

02Background

The early 2010s saw a significant rise in sophisticated, automated phishing attacks targeting the financial sector. These attacks capitalized on users' trust in established banking brands. Tinba exemplifies this trend, demonstrating the increasing sophistication of cybercriminals in exploiting human trust and digital vulnerabilities for monetary gain.

03Key revelations

  1. 01The use of highly convincing visual spoofing of major banking websites.
  2. 02The primary goal was the theft of login credentials and account details.
  3. 03The attack targeted the general population of banking users.

04Technical analysis

Attack vector
Phishing (Deceptive Email/Website)
Attack method
Credential Harvesting
Initial access
Malicious Link/Email Attachment
Exfiltration
Direct submission from fake portal
Malware type
Stealer/Phishing Kit

MITRE ATT&CK techniques

  • T1566.001

05Threat actor

The perpetrators were likely financially motivated criminal actors, operating independently or as part of a loosely organized cybercrime network. Their focus was purely on exploiting the trust inherent in the banking relationship.

06Data exposed

Data types

  • credentials
  • PII
  • financial records

Notable documents

  • Fake Banking Login Portal Screenshots

07Financial damage

Estimated damage is difficult to quantify due to the lack of public reporting on the specific incident.

08Timeline

  1. 2012-01-01Initial reported activity of the Tinba phishing campaign.

09Reaction and fallout

Public reaction

The public reaction was characterized by increased awareness of phishing risks, leading to greater caution when handling banking credentials online.

Political impact

The incident contributed to the growing regulatory focus on consumer protection in the digital financial space.

10Legal

No specific major legal action or indictment is publicly documented regarding this specific campaign.

11Aftermath

Policy changes

  • Increased emphasis on Multi-Factor Authentication (MFA) adoption by financial institutions.

Regulatory changes

  • Enhanced consumer protection guidelines for online banking.

Security improvements

  • Mandatory use of CAPTCHA and advanced bot detection on banking login pages.
  • Increased public education campaigns regarding phishing.

12Significance and legacy

Significance

Tinba is historically significant as an early, clear example of the professionalization of financial phishing. It demonstrated that cybercriminals could effectively weaponize trust and visual mimicry, setting a precedent for modern, highly targeted social engineering attacks.

Legacy

The campaign contributed to the development of modern anti-phishing tools, browser security warnings, and the industry-wide adoption of MFA as a primary defense mechanism.

13Disclosure and media

Authentication
Visual/Behavioral Analysis

14Field notes

  1. 01The campaign predates the widespread adoption of modern browser security features like advanced anti-phishing filters.
  2. 02It highlighted the vulnerability of users who were not yet accustomed to the concept of digital identity verification.

15Resolution

The campaign was eventually mitigated by increased public awareness and improved security measures implemented by banks and browser vendors.

16Sources

References

  1. [1]General Phishing Threat Reports (2012)
Fact sheetEL-0086

Dates

Event
1 Jan 2012
Started
1 Jan 2012
Discovered
1 Jan 2012
Disclosed
1 Jan 2012
Ongoing
No

Target

Organisation
Banking Users
Type
Individual
Sector
Financial Services

Actor

Motivation
Financial gain through credential theft
Arrested
No
Convicted
No

Data

Sensitivity
Confidential
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.