The unsolicited message requires credulous users to fill in the new new customer form. Bank of America continues to be exploited by phishers around the globe. The sensitive data card number, expiration date, card ID number, PIN, first and last name and email address is stolen using done1.php1php1. The link does not lead to the e-banking portal, but to a registered Web page that mimics the appearance of the original Web site. The pop-up window informs the duped users about their automatic log out and redirection towards the (real) homepage.”]
Source: https://www.bitdefender.com/blog/hotforsecurity/bank-of-america-sends-electronic-customer-forms/