If you searched for "vietinbank phishing", "vietinbank scam" or "vietinbank compromised", you almost certainly arrived with a link in hand. A message, an SMS, an email. You want to know whether the page it opens belongs to the bank. This article answers that, and it uses what our own analysis measured rather than what anybody claims.
What we measured on the real domain
Our assessment of vietinbank.vn runs from the evidence we could collect on 2026-08-11. Four of those facts are ones you can check yourself on any page claiming to be the bank, and they are the four a convincing fake struggles hardest to reproduce.
- The address resolves to https://www.vietinbank.vn/. That is the host the real site answers on. A page that looks identical on a different hostname is a different site, whatever the logo says.
- The domain has been registered for 18.32 years. Impersonation domains are usually days or weeks old, because they get taken down and replaced.
- The certificate is an Extended Validation certificate, issued by GlobalSign GCC R3 EV TLS CA 2025. EV means a certificate authority verified the legal identity of the organisation behind the site. Anyone can obtain the ordinary padlock in minutes; almost nobody can obtain an EV certificate in a bank's name.
- No reputation service flagged it. VirusTotal, Google Safe Browsing and the host abuse feeds were all clear at assessment time.
Was VietinBank compromised?
Not according to anything we could observe. Our analysis looks at what a site serves, how it behaves while it loads, its registration and hosting, and what third-party threat feeds say about it. On that evidence the bank's own site came back clean and scored in our high-trust band.
That is a statement about what we measured, not a guarantee about a company's internal systems, which no external scan can see. If you have been told your account is affected, contact the bank through a number or address you already had, never through the message that told you.
Treat a bank being hacked and a bank being impersonated as separate things. A lookalike page does not need any access to the bank's systems. It only needs you to believe it is the bank for long enough to type in your details. That is why the checks below focus on the page in front of you, not on the bank itself.
How an impersonation gives itself away
A copied page can reproduce the design perfectly. It cannot easily reproduce the things underneath it.
- The hostname. Read it from the right: the part immediately before the first single slash is the real domain. A page at
vietinbank.vn.secure-login.examplebelongs tosecure-login.example, not to the bank. - The age. A domain registered last month, impersonating an institution that has been online for eighteen years, is the single loudest signal there is.
- The certificate. The padlock only means the connection is encrypted. Encryption between you and a criminal is still encryption. Check who the certificate was issued to, not whether a padlock exists.
- Urgency. Real banks do not close your account in twenty minutes because you did not click a link.
Check the link you were sent
- Read the hostname from the right. The real site answers on www.vietinbank.vn. If the address is anything else, you are on a different site, however familiar the page looks.
- Check how old the domain is. The bank's own domain has been registered for 18.32 years. A domain that is only days or weeks old is a strong warning sign.
- Look at who the certificate was issued to. Don't stop at the padlock. At assessment time the real site used an Extended Validation certificate, which ties it to a verified organisation.
- Ignore the deadline. A message that says your account will close unless you click right now is using pressure, not information.
- When in doubt, go around the message. Contact the bank through a number or address you already had, never through the link or phone number in the message.
Paste the address into the free website checker and you get the same assessment this article is built on: registration age, hosting, certificate, what the page served, and what the reputation feeds say. No account is needed and the full report is free to read.
If the message asked you to send cryptocurrency, the wallet checker screens an Ethereum or TRON address against issuer freezes and sanctions exposure before you send anything. Every site we have assessed is listed in the risk directory, and the aggregate picture is in the Risk Index.
Two related reads: how to tell whether any website is legitimate walks through the same checks on a site you have never heard of, and our crypto phishing and credential theft piece covers what happens after someone does enter their details.
Frequently asked questions
Is vietinbank.vn a scam?
Was VietinBank compromised or hacked?
How do I know if a VietinBank page is real?
The page had a padlock. Doesn't that mean it is safe?
TrustSniffer is an independent analysis service. This article reports what our own automated assessment of vietinbank.vn found on 2026-08-11, and nothing on this page is supplied by or endorsed by the bank. A site can change after it is assessed; the live report always shows the current one.



