Behind that site is a faker maker from Ghana, active online for years.
Back in 2013, when his first fraudulent domain name - access-offshore.us - got reported he was:
Registrant Name: Hannah Ematele
Registrant Organization: Primus Hosts
Registrant Address1: 24 Nungua Rd
Registrant City: Nunga
Registrant State/Province: Accra
Registrant Postal Code: 23301
Registrant Country: Ghana
Registrant Country Code: GH
Registrant Phone Number: +1.240783277
Registrant Email: bobbyefekodo05@gmail.com
or with atlanticshippingsecurity.com a year later:
Registrant Name: HANNAH EMATELE
Registrant Organization: PRIMUS HOSTS
Registrant Street: 24 NUNGUA RD
Registrant City: NUNGUA
Registrant State/Province: ACCRA
Registrant Postal Code: 23301
Registrant Country: GH
Registrant Phone: +233.240783277
Registrant Fax: +233.240783277
Registrant Email: BOBBYEFEKODO05@GMAIL.COM
Now, while registering his fake sites, he is:
Registrant Name: Osei Isaac
Registrant Street: 2, Station Road
Registrant City: Glasgow
Registrant State/Province: Giffnock
Registrant Postal Code: G46 6JF
Registrant Country: GB
Registrant Phone: +44.702240783277
Registrant Fax: +233.240783277
Registrant Email: bobbyefekodo05@gmail.com
There is a basic obligation of a Registrar to check the accuracy of the details provided by anyone registering a domain name. In this case, not a single check was made. We see the same phone number used with different country codes over the years; same email address used with different names - a sex change in and between, while being apparently located on different continents. Last, but not least, no one noticed that a Ghana phone number is used for a UK location.
Few of the fraudulent domain names are using .us, while pretending to be American companies.
In all those cases, the registrant details show:
Registrant Name: Osei Isaac
Registrant Street: 2, Station Road
Registrant City: Glasgow
Registrant State/Province: Giffnock
Registrant Postal Code: G46 6JF
Registrant Country: GB
Registrant Phone: +44.702240783277
Registrant Fax: +233.240783277
Registrant Email: bobbyefekodo05@gmail.com
Registrant Application Purpose: P1
Registrant Nexus Category: C11
Translating: Nexus Category: C11 means the registrant is a United States citizen; application purpose: P1 means Business use for profit. In other words, a person supposedly from Glasgow, and using a Ghana phone number, can pretend to be an American citizen creating a business, even if that business impersonates well known banks.
Some of the websites shows:
WE ARE CURRENTLY UNDERGOING MAINTENANCE
In other cases, the main page of the fraudulent website is empty.
The content is there and the victims receive direct links for the pages where that content is hidden.
No real company will use this practice for their website.