New CFAI Website (scam)

People not familiar with phishing may fall for this. This isn’t funny.

You’re kidding me? It looks legit to me, and I was told by Tom Robinson in person that a site like this would be available.

None of the links work…

Wonderful, I fell for it. Now what do I need to do? I was expecting a site like this per my converstion with Tom Robinson not too long ago at a CFA Society Event.

What? Are you talking about the link that someone posted to myCFA? I had read about the beta in the March Executive update and the links on the site work for me…

its legitimate…its clearly located at the cfainstitute.org domain, and couldnt be a phishing site unless someone hacked the domain.

o no. we da munkey now

Did you get this message when you first went there? There is a problem with this website’s security certificate. The security certificate presented by this website has expired or is not yet valid. Security certificate problems may indicate an attempt to fool you or intercept any data you send to the server. We recommend that you close this webpage and do not continue to this website. Click here to close this webpage. Continue to this website (not recommended). More information If you arrived at this page by clicking a link, check the website address in the address bar to be sure that it is the address you were expecting. When going to a website with an address such as https://example.com, try adding the ‘www’ to the address, https://www.example.com. If you choose to ignore this error and continue, do not enter private information into the website. For more information, see “Certificate Errors” in Internet Explorer Help.

To be safe, go to the original site and change your password.

Dreary Wrote: ------------------------------------------------------- > To be safe, go to the original site and change > your password. I did not receive any certificate errors and my browser always asks. I’ll change my pw but I don’t think there is anything to be worried about… I hope.

why would anyone wanna phish for our CFA website passwords anyway? lol

i was thinking about that too. credit card info for books bought?? they may also want to check out my level one scores too

It is 100% legit. I got an email from CFAI to fill in their yearly member survey ( it’s a real link to the old web site, with tons of questions, can’t be fake). After about 30 minutes, I completed the survey and then I was asked if I would like to try out the beta version web site, which I did.

The certificate issed is a good certificate, it’s a class 3 Verisign certificate. It’s also issued to CFAI, which is good. It’s very hard to fake such certificates. However, I think CFAI should be more careful…they may know about finance well, but they surely don’t understand web security. They should have either had a general web site for testing the beta, i.e., no need for userid+password. Or, they should have let you get to the beta from within the regular site (after you authenticate).

thems Wrote: ------------------------------------------------------- > why would anyone wanna phish for our CFA website > passwords anyway? lol maybe its another desperate cfa candidate who will change your registration to zimbabwe test center, so that his chance increase :wink:

I did the satisfaction survey and was taken to the new site at the end. I’m pretty sure it’s legit. There’s almost no way the beta site could do the number of things that it does without it being a true CFA site unless the phishers spend inordinate amounts of time programming it… Phishers generally try to catch low-hanging fruit… it just doesn’t pay off. The new beta site seems pretty neat… I just have to learn to re-navigate it.