Find more Phishing Funda....

Loading
Showing posts with label business. Show all posts
Showing posts with label business. Show all posts

Saturday, June 14, 2008

Beware of the Newest Activity Online: Phishing

No. I’m not talking here about the outdoor activity enjoyed
by many. And no again; I did not misspell it. Phishing is
the name given to the latest online scam where millions of
unwary Americans are getting their identities stolen.

This fraudulent activity is considered the fastest growing
crime of modern times. The favorite target groups of
phishers seem to be very young children and senior citizens,
as they do not often ask for credit reports, fill out credit
card applications or solicit loans. This allows the thieves
to go undetected for longer periods of time; but still, be
careful. We all are potential targets.

Remember when throwing away unshredded documents with
personal information in the trash bin was considered a big
risk for identity theft? While this still happens, identity
thieves have become more sophisticated in recent times, and
this is how they do it…

Phishers create bogus e-mails that look as if they came from
large, well-known institutions and banks, such as eBay,
Paypal, Citibank, EarthLink, and Wells Fargo among others.
These e-mails claim that you are due for an account update,
or that the account number, password, social security number
or other confidential information needs to be verified. Then
they warn you, stating that if you do not do it within a
certain period of time, that your account will be closed,
terminated, the service discontinued, or something to that
effect.

They even provide you with links to websites that look
legitimate, because they hijack the real logos of these
well known banks, and trusted institutions and companies.
And that is the scary part… these e-mails look 100%
legitimate, but they are not.

In some cases it goes even further… some of these phishers
are installing spyware on your computer to monitor your
online activities. So… should you leave the online world for
good? Not necessarily.

These are a few things you can do to protect yourself from
these scammers:

1. Do not respond to any e-mail that asks for personal
information from you, such as account number, credit card
number, user names, passwords, etc. If you suspect that the
e-mail, indeed, be legitimate, contact your bank or
institution to verify this.

2. When in doubt, visit the Anti-Phishing Working Group for
an update of the latest scams, and tips to avoid becoming a
victim. The website’s URL is www.antiphishing.org

3. Websites like www.Paypal.com, www.citibank.com, and
www.ebay.com, offer security tips and tell you what
information they’d never ask for in an e-mail.

4. Get anti-virus software and keep it up-to-date.

5. If you suspect you have received a fraudulent e-mail, do
not click on any links within it, and forward it to the FTC
at uce@FTC.gov

Finally, if you suspect you’ve been a victim of this fraud,
get a copy of your credit report immediately to check for
unusual activity. If you discover that you’ve been a victim
of identity theft, close your account at once and…

- Call the Credit Bureau.

- File a police report.

- Call the FTC ID theft hotline at (877)IDTHEFT.

- Alert other financial institutions where you have accounts.

According to the Anti-Phishing Working Group, phishers send
millions of e-mails a day, getting about 5% response. Even
with this low response, it is estimated that about 150,000
Americans have fallen prey to these scams since May of 2004.
Get informed. Do not become a victim yourself.

Wednesday, May 28, 2008

Phishing: A Scary Way of Life

The Federal Bureau of Investigation has identified “phishing” as the “hottest and most troubling new scam on the Internet.”

What is Phishing?

Phishing is a scam initiated via e-mail. Messages are “fishing” for personal and financial information. Most often, e-mails appear to be from reputable companies (internet service providers, telephone companies, etc), banks, and other financial organizations. The e-mail message often gives a story of the bank needing to update its personal information database or a financial institution claiming your personal data had been lost.

Who Phishes?

Hackers and Scammers looking for personal and financial information use phishing as an effective method of gathering information. Phishers imitate legitimate companies in e-mails to entice people to share passwords or credit-card numbers. Recent victims include:

• Bank of America
• Best Buy
• America Online
• eBay
• PayPal
• Washington Mutual
• MSN (Microsoft Network)

History of Phishing

The term phishing comes from the fact that Internet scammers are using increasingly sophisticated lures as they "fish" for users' financial information and password data. The most common ploy is to copy the Web page code from a major site — such as AOL — and use that code to set up a replica page that appears to be part of the company's site. (This is why phishing is also called spoofing.) A fake e-mail is sent out with a link to this page, which solicits the user's credit card data or password. When the form is submitted, it sends the data to the scammer while leaving the user on the company's site so they don't suspect a thing.

Avoid Phishing

Fortunately, common sense can save you from giving away your personal information. For example, be aware for the company requesting information. I have received e-mails from banks I have never had business with. Know that your bank or ISP will never ask for your information out of the blue. Banks do not update their databases and misplace information.

Tips To Avoid Phishing

• If you receive an unexpected e-mail saying your account will be shut down unless you confirm your billing information, do not reply or click any links in the e-mail body.

• Look for words misspelled or other grammatical mistakes.

• Before submitting financial information through a Web site, look for the "lock" icon on the browser's status bar. It means your information is secure during transmission.

• If you are uncertain about the information, contact the company through an address or telephone number you know to be genuine.

• If you unknowingly supplied personal or financial information, contact your bank and credit card company immediately.

• Suspicious e-mail can be forwarded to uce@ftc.gov, and complaints should be filed with the state attorney general's office or through the FTC at www.ftc.gov.

Wednesday, April 30, 2008

Social Engineering - The Real E-Terrorism?

One evening, during the graveyard shift, an AOL technical support operator took a call from a hacker. During the hour long conversation the hacker mentioned he had a car for sale. The technical support operator expressed an interest so the hacker sent him an e-mail with a photo of the car attached. When the operator opened the attachment it created a back door that opened a connection out of AOL's network, through the firewall, allowing the hacker full access to the entire internal network of AOL with very little effort on the hacker's part.

The above is a true story and it is an excellent example of one of the biggest threats to an organisation's security - social engineering. It has been described as people hacking and it generally means persuading someone inside a company to volunteer information or assistance.

Examples of techniques employed by hackers include:

  • Unobtrusively observing over your shoulder as you key in your password or PIN.
  • Calling helpdesks with questions or being overly friendly
  • Pretending to be someone in authority.

Social engineering attacks can have devastating consequences for the businesses involved. Accounts can be lost, sensitive information can be compromised, competitive advantage can be wiped out and reputation can be destroyed.

By implementing some simple techniques you can reduce the risk of your organisation becoming a victim or, in the event that you are targeted, keep the consequences to a minimum.

  • Make sure that all staff, especially non-IT staff, are aware of the risk of social engineering and what to do in the event of such an attack.
  • Conduct regular security awareness training so that all staff are kept up to date with security related issues.
  • Implement a formal incident reporting mechanism for all security related incidents to ensure there is a rapid response to any breaches.
  • Ensure that the company has security policies and procedures in place, that all staff are aware of them and that they are followed.
  • Put an information classification system in place to protect sensitive information.

Conduct regular audits, not only on IT systems but also on policies, procedures and personnel so that any potential weaknesses can be addressed as soon as possible.

 
Copyright 2009 Phishing : A Online Robbery.. Powered by Blogger Blogger Templates designed by Deluxe Templates