Find more Phishing Funda....

Loading
Showing posts with label identity theft. Show all posts
Showing posts with label identity theft. Show all posts

Saturday, February 6, 2010

Surf Anonymously - Protect Your Personal Information by Hiding Your IP Address

Identity theft is one of the worst crimes anyone will experience. As the name of the offense suggests, it is an online crime wherein another person uses your identity for their personal gains. More often than not, your personal information is used to purchase products or even acquire services. The bad thing about this crime is that you may not know it before you see unknown credit card charges or collection calls about the products you did not acquire.

This type of online crime can happen to anyone who frequently uses the internet for various forms of transaction. If you are constantly shopping or paying your bills online there is a possibility that someone is already trying to monitor your activities. That could lead to identity theft once they gain access to your information.

Saturday, July 5, 2008

8 Simple Ways to Defend Against Evil Doers Both Online and Off

There once was a time when the only option people had when shopping was to either call in or snail mail in a catalog order form or to jump in the family car, fight through traffic, and wait in long checkout lines to complete the purchase.
Well, nowadays there’s still a few major mail order catalogs floating around and we all still visit our local retail outlets, but time has also introduced the internet as one of our options to shop from the comforts of home.
The internet has made shopping at home a breeze and along with it has unfortunately brought the so called ”Evil Doers” who I believe have such little happiness in their own lives that they must leech pleasure from the hardworking and innocent individuals of our wonderful and surrounding nations.
And yes, I am speaking of the ever growing problem known as Identity and Credit Card Theft.
As an online and offline consumer it is in my best interest to protect myself while at the same time wanting to help others protect themselves as well.
Below is a short yet thorough list of ways that you can follow to help yourself stay safe and be a happy consumer and keep “Evil Doers” at bay.
1) Always shred sensitive materials such as bank statements before throwing them away in the regular trash. Just because the paper documents are in the garbage doesn’t mean they are safe from peeping eyes.
2) Contact your local bank or credit card provider to request a card with a low limit. This can make you feel more at ease about shopping at those not so familiar places and can reduce the damages caused by such an ill intended individual if they get hold of your number.
Also never give out the 3-letter Card Identification Number found on the back of the credit card unless you absolutely trust the merchant you are dealing with.
3) NEVER give out your social security card number for any reason! If capable you are best to obtain a tax I.D. number from the Internal Revenue Service or local tax agency.
If any “Evil Doer” gets hold of your personal information such as home address, birth date, and Social Security Number you are at great risk of being victimized.
4) Only purchase items online through secure order pages which is typically indicated by a small, yellow, “Padlock” image usually located somewhere near the bottom of your internet browsers window.
5) If you ever receive an email asking for sensitive information and claiming to be from a company that you have an account with, NEVER supply the requested information and never click any links or hit reply to send such personal information back to the “company”.
Many legit companies will not ask for sensitive information via email.
If you get such an email you are better off to make a copy of the letter you received then close that browser window and then open a NEW window and access the company directly from their website address.
You should then submit the email you made a copy of to the company so that their anti- fraud personnel can take the necessary steps to send out warnings of possible fraudulent activity to be aware of to its members.
6) Be cautious about downloading and installing unnecessary programs onto your computer. If there are programs that you indeed must download ALWAYS scan the files for viruses and make sure that your anti-virus program is up to date.
There’s a wide variety of viruses that are distributed to unprotected computer systems and some of which are known as “Key Stroke Loggers” that record your sensitive log in names and passwords and then are made known to the trouble maker.
7) If possible try to utilize 2 different computers when using the internet.
One computer should only be used for general internet surfing just in case it was to obtain a virus such as a Key Stroke Logger so there would be little threat of someone getting your personal information.
Only use the second computer to access more sensitive information such as online banking or other important websites that require passwords and important information.
8) Finally, if there are young members of the family that have computer use privileges be sure to monitor and restrict the sites and programs they are allowed to use.
Many fraudulent individuals love to prey on the unexpecting and inexperienced web surfer.
In any case just be certain to contact the police or appropriate authorities the INSTANT you believe that you have become a victim of Identity Theft or Credit Card Number Theft.
The sooner you tell the authorities the better the chance they can help you recover from a financial catastrophe.

Thursday, July 3, 2008

Protect Your Little Black Book

The movie Little Black Book features a young woman, Stacy, who is frustrated when her boyfriend refuses to share information about his past relationships. When his PDA, a Palm Tungsten C, falls into her hands, she is faced with a conundrum. Does she give it back, or does she explore it? If she gave it back, we wouldn’t have a movie, now would we? Stacy then proceeds to identify his ex-girlfriends and contact them. Let the games begin.
Could this really happen? Of course it could. Most PDA’s contain a plethora of information about a person and their activities, their digital footprints. People store contact information, appointments, meetings and midnight rendezvous’. They store passwords, login ID’s and PIN numbers. They have photos of people they know and sometimes in awkward circumstances. It’s a lot to have to explain. The courts are only beginning to grapple with how to handle the content in a PDA. One person’s little black book can be very incriminating indeed.
For the rest of us, we have nothing as exotic; however, we are all in danger of exposure and threat. Identify theft has become one of the largest white-collar crimes. There is enough information in the average PDA for someone to take over your life. So, what’s the solution? Give up your PDA? No. You face the same problem with the typical day planner. It has all of the same information, it’s just not as accessible. In fact, a PDA has certain advantages over a planner. You can password protect some of the data. You can even encrypt data. Most importantly, you have a backup. The data is safely stored on your computer and archived on external media if you have taken the proper steps.
That duplication of data also means an identity thief has more ways to get to it. So, what can you do? Well, the first concern is to make sure that you backup your data. Synchronize your PDA at least daily. I synchronize my Treo 600 2-3 times each day, usually when I arrive at my office or leave it. Backing up your data means that you should be creating a copy on tape, CD, zip disk, flash ROM or other external media and storing it offsite. If you are not, you are asking for trouble and your business is at risk. If your PDA is ever stolen, you will need to restore that data on a new PDA.
Next, you need to minimize the amount of data someone can actually access. Let’s face it, if a hacker really wants to get your data, they will succeed. However, not every criminal is a super hacker. Sometimes you just want to keep your information from prying eyes. Just because you labeled something as private in your PDA doesn’t mean someone else can’t read it. It depends on what application you synchronize with. If you sync with Outlook, records that are private on your PDA may be public in Outlook.
The best way to protect passwords and PIN numbers is to store them in a password application that encrypts the data. The best applications have both a PDA application and a desktop application that allows access to the information from either system. The trouble is converting that data from whatever format it’s in currently. I’ve struggled with this one myself. There is no easy method I’ve found so far. Just set aside time to copy and paste the data into the password application. It might take a few hours to get that information into a secure application.
If you’re worried about someone viewing your schedule, the best approach is to archive your past history periodically. Outlook has settings that allow you to specify to how often calendar events will be archived. This will wipe the history from your PDA also. Archives are usually stored in an external file that can be accessed later.
If you have incriminating photos, delete them. If you want a copy, save it on external media like tape, CD and flash ROM. For contacts, you can archive them or simply move the record to an external file. Outlook allows you to create a .pst file that you can use to save email, calendar, address, tasks, or other information. Once you move a record, it will be removed from your PDA.
And, don’t forget to delete the cookies and memory cache on your PDA’s web browser. Remember that website you checked out last week? Is that something you want everyone else to know about? I don’t think so.
Don’t forget physical security; keep an eye on your PDA. It’s possible to take steps to protect your data and remove your digital footprints. Protect your little black book and it will protect you.

Thursday, June 12, 2008

Information Security for E-businessmen: Just a Couple of Ideas

If you constantly deal with bank or electronic accounts, it must be
your worst nightmare--to wake up and learn that you are a bankrupt.
Some crook stole your personal data and all the money you have been
sweating blood for years has flown to somebody else's account. Almost
everybody must have heard that such a tradegy is called identity theft
and millions of people in the USA alone suffer the same every year.
Poor consolation for its victims, isn't it?

Unfortunately, businessmen frequently are targets for identity
thieves, especially online. Lots of articles on identity theft,
"how-to-avoid" tips, and scary stories about the victims circulate
through the Web and other media. The authors remind people again and
again that they should be cautious when giving anybody their private
info as well as care for their PCs' security. But in spite of all
their effort identity theft is still the most rapidly growing crime.

Software developers are doing their best, too. They can't be of much
help if somebody plainly looks over your shoulder and writes your
credit card number down. It's for you to take care and never reveal
your personal info to anybody who asks for it. What they can do is to
create new solutions to the urgent problems like data stealing.
Keylogging spyware--the very programs that make lots of such crime
possible--are pretty much written about lately. These programs
secretly monitor everything users do on their PCs.

Keyloggers are used--by themselves or as a part of a virus or a Trojan
-- much more widely than PC users think; it is an open secret that the
lion's share of identity theft that happens online is because of
keylogging spyware. The losses caused by stealing PINs, logins, and
other valuable data, are well comparable with the damage from viruses.
Actually, if a virus or a Trojan contains a built-in key logger module
(and it often does), the end user finds himself in a pretty tough
situation. The problem is that most anti-keylogging programs warn
users when it is too late. The data have already been captured and
sent. Why does it happen?

Almost all anti-spy software existing at the present moment works
using the same scheme: spy program is detected and then blocked or
eliminated. Detecting viruses or spy software is the crucial step of
the whole process--all the protection depends on whether the anti-spy
software is able to detect as many spies as possible. Signature bases
which all these products depend on, is actually the "list" of
signatures – small pieces of spy programs' codes. Anti-virus or
anti-spy program actually scans the system and compares its codes with
those in signature bases. So, in this case only the spies whose
signatures already are in the base will be detected and eventually
"caught". As long as anti-spy software is regularly updated and the
system doesn't come across some unknown spyware product, everything is
all right.

The problem is that lots of programs which could be used for stealing
data are not included into signature bases right now. Some of them
will never be.

There is good deal of people capable of creating something brand-new
spy, unknown to anti-spyware developers. The period of time when a new
spy already exists, but the updates have not been released yet, is the
very time when hackers make their biggest profits.

Spy programs can be created for the specific purpose, such as
industrial espionage, so they will never be represented in the base.
Moreover, some monitoring programs can be used as spy programs as
well, though they are not always included into signature bases. As we
can see, a signature base is the weak spot of anti-spy protection; it
is, so to speak, a joint in the armor. Information thieves also know
about it.

Fortunately, software developers are constantly looking for new
solutions. One of the new trends in anti-spyware developing is not to
use signature bases as means of detecting spyware. There is three
basic advantages in such an approach. First, the product gets rid of
its the least reliable part; second, there is no so urgent need for
updates anymore; and last, but certainly not least-–the product
becomes capable of blocking the destructive activity of even unknown
spyware. To read more about this new approach follow the link in the
signature.

When products of such a kind become widespread, there would be much
more problems for hackers in future. However, there is no guarantee
that no innovative spy software appears in response.

Whether we like it or not, all malware "evolves" very quickly; new
schemes are being developed, and new software which online criminals
create and utilize becomes more and more malicious and "selective".
New keyloggers as well as keylogger-containing viruses and Trojans,
appear all the time; the losses these programs may cause to a business
are enormous. That is why in some businesses there is an acute need
for separate anti-keylogging protection.

Saturday, April 12, 2008

7 Ways to Protect Yourself Online

Based on information provided on the Internet World Stats website, there are about 1.3 billion internet users worldwide. Some of these users are friendly people who want to enjoy entertaining themselves, communicating with friends and family, or researching and shopping. There are others who may be conducting business online and there are stil others who are there to harm your computer.

The Internet can be a great place to do a lot of great things, but special care should be taken to make sure conditions are as safe as possible.

Here they are:

1) Scan for viruses - It doesn't matter as much about what program you are using as it does how often you use it. Having the best virus software and never using it is about as bad as having no software at all. Computers can become infected in a number of different ways, so it makes sense to scan and scan often.

2) Scan for spyware - It's really not a great thing when someone can watch what you're doing from your home or business computer. Whether they are watching directly or indirecting, using software, caution should be taken to make sure spyware is removed.

3) Avoid internet scams - If it sounds too good to be true or if you're getting something for nothing, avoid it at all costs. There are probably scams being created every day that focus on people's emotions in order to persuade them to take some type of unwise action. If you fall for a scam, it can costs hundreds or thousands of dollars and can be hard to dispute if you try to prove that the actions were fraudulent.

4) Avoid hoaxes - Hoaxes play on people's emotions especially to forward emails that contain myths or folklore. Since the emails may sound like something that has actually occurred, people forward them and the process continues.

5) Report and Recognize Phishing - Phishing involves someone trying to obtain your personal information such as bank account information through cleverly designed emails and webpages. The best thing to do is to report these types of incidents to the necessary authorities. The key component is actually recognizing the phishing attempts. If you receive an email that asks for personal information or has a link to login to an account, avoid it 99% of the time. Most organizations will not ask for social security numbers, account numbers, or passwords from email.

6) Avoid pornography - The best solution for avoiding most pornography that exists on the web is to install a filter. One of the filters that I recommend can be found Bsafeonline.com.This will take care of most of the process. Inappropriate sites will be blocked and parents can take an active approach at controlling the internet use in their home.

7) Use caution when blogging - Blogging can be a great thing most of the time. It is great for search engine optimization and building communities online, but caution should be used when including information that is personal or when discussing details of other people's lives. In addition, to keep people from stalking you, I would not suggest chronicling every detail of your every day life.

Devin Dabney is a computer consultant, author, speaker, and entrepreneur who is the founder and CEO of DabneyWorks Computer Consulting. DabneyWorks provides remote and in-person computer assistance , website design and auditing, and business consultation.

Sunday, February 24, 2008

An Alternative Method To Protecting Yourself From Phishing

Phishing is one of the leading trends in cyber crime. Basically, phishing occurs when websites that appear to be the one you are looking for are actually those belonging to people that want to steal your personal information. While some web browsers and internet security softwares will attempt to protect you from phishing attacks, they are not perfect. In many cases, the end goal of phishing is to obtain enough personal information to steal your credit cards numbers, or access to bank accounts.

Along with creating websites and emails that mimic legitimate businesses like paypal, phishing is also evolving into other trends. Basically, anything that will get you to transmit personal and financial information can be exploited for phishing purposes. This includes social websites, as well as those set up for the sale of merchandise.

One of the best things you can do is make sure that anything you enroll in online does not provide the same information that you gave to your banks and other lenders. This is especially important if you enjoy singing up for news forums, or other groups that ask identifying questions that you answered for your bank. As an example, the last four digits of your social security number, or mother's maiden name are very common questions. Unfortunately, in the hands of someone intent on phishing, this information can be used to obtain your credit card information.

Therefore, when it comes to online forums where you do not expect to engage in financial transfers, treat your password backups like a real password. This includes using a different backup for each site you enroll with. Also, you should use a "hardened password" that includes at least 8 letters, one number, and a non alpha-numeric character. Not only will this stymie phishing attempts, if they do try to use the information you gave them, you will know exactly what site the fraudulent activity came from.

If you find yourself wanting to open a financial account online, and need to provide information similar to what has been requested by your credit card company, or bank, the same advice applies. Simply treat your backup information like a secure password. With a legitimate bank or credit card institution, you can always call them later on and have these things reset if need be. This is far less troublesome than becoming the victim of a phishing attack.

Because cyber crime is only limited by the ideas that people get, many different schemes can be used to steal personal information. Over the years, phishing has evolved as the premier way to gain financial information and steal personal identities. Banks and many other financial institutions often utilize backup passwords or other information to help identify you. When enrolling in social groups, it is vital to treat this information like any other type of personal information. By using words or information different from what you would use with your bank, you may well help prevent a phishing attack, and also help investigators determine where it came from.

Monday, February 11, 2008

Phishing Filter - How to Use Phishing Filters to Prevent Any Information Theft

A lot of people are actually still afraid of using computers due to the fact that they can have viruses and people can manipulate them in order to serve their purposes.

This argument actually holds true but there are actually different types of "manipulations" that people can do. This is where anti-viruses and viruses come into play and one of the most recent developments is creating phishing filters.

Phishing is the act of "fishing" information via the internet, there are a lot of ways to do this from emails to spywares, and people can access your computer and steal your information without you knowing it.

Normally the accounts that people try to phish are financial accounts that cannot be subjected to information trace - especially if they can keep you locked out long enough to get the money into a bank and run away with it.

The most common ones in the internet are Paypal and Ebay Accounts. Apart from the usual spyware tools, scammers are using simple emails targeted at unsuspecting users. These emails come with subject lines like: "Last Warning", "Password Change Required" or "Your account is suspended" and a whole lot more.

These e-mails would appear to have come from eBay or PayPal and provide a link to their own phishing page. Now these pages are designed just like the original pages and the unsuspecting user ends up providing his/her sensitive information like username/password or Credit Card Information to these duplicate pages.

That's why I would like to add one piece of advice to all users that you should always see where the link is taking you by seeing the tool tip and then if it takes you to your usual Paypal address, follow the link.

Now in order to avoid this e-mail to ever land in your inbox you need to use a phishing filter. One of the most common ones at the moment is the Bayesian Filter that allows you to blacklist or whitelist certain individuals. It also easily integrates to popular email clients such as MS outlook.

By using this filter 90% of these types of messages will not arrive in your inbox, thus greatly increasing your phishing protection and it saves you a lot of time.

The next thing you need to use is anti-spyware software. One good program available in the market is called ad-aware by lavasoft. It is always updated and it is extremely simple to use. It runs through your computer like a virus scan - except that it only looks for spyware, which most of the time is not recognized by your virus scan as a threat to your system. Just download it and run it at least once a week and it will prevent any kind of phishing spywares to enter your system.

Now, all you need to do is just to keep these programs updated to protect your information and continuous awareness over phishing issues will also help you to be ahead of the curve and keep the scammers at bay.

Author and internet entrepreneur Bernard Pragides offers expert advice and tips regarding identity theft. Learn more about identity theft and fraud by visiting his identity theft blog and his website http://www.IdentityProtek.com for more helpful information.

Monday, February 4, 2008

Phishing 101 - How To Defend Yourself Against Phishing Attacks

What is Phishing?

Alarming numbers of Australians still do not know what the internet scam called 'phishing' (pronounced "fishing") is, nor are they adequately protected against it, a Galaxy survey has found.
Phishing is a type of fraud that tricks people into giving out their personal and banking information through hoax websites or phony emails which steal people's personal information, such as credit card numbers, account data, usernames and passwords. Many of the hoax/phishing emails may appear to come from legitimate and trusted business that you might have dealings with, such as, banks (eg. CBA) and online organisations (eg. eBay and PayPal), Internet service providers (eg. MSN and Google). The message may look quite authentic, featuring corporate logos and formats similar to the ones used for legitimate messages. Typically, these emails lead recipients to fake websites designed to trick the customer into entering their personal banking details. This information is then used to steal your money!

Because the emails look so official and convincing, they are very effective for criminals.

Criminals send out millions of these fraudulent e-mails to random e-mail addresses, whether or not they are a customer of the organisation, in the hope of luring unsuspecting innocent persons into providing their personal banking details.

If the link is followed, the victim often also downloads a malicious program which captures his/her keyboard strokes including any typed information, such as banking login details and sends them to a third party.

How to Identify E-mail Fraud

So, how do you know if the email you received is fraudulent? Here are a few things you should know:

  • Your bank will NEVER send you an email, or call you on the phone, asking you to disclose personal information such as your credit card number, online banking password or your mother's maiden name.
  • Be suspicious of unsolicited emails that have a sense of urgency and warnings that your accounts will be closed or your access limited if you do not reply.
  • The email might claim that your details are needed for a security and maintenance upgrade, to ‘verify’ your account or to protect you from a fraud threat. The email might even state that you are due to receive a refund for a bill or other fee that it claims you have been charged.
  • Does the email look professional? While some fraudulent emails may look professional at first glance, if you look more closely you may notice spelling and bad grammar, unusual language or branding that is not quite right. Fraudulent emails are not personalised and, instead, are addressed in general terms, such as 'Dear valued customer'.
  • If you receive an email notifying you that an email money transfer is being sent from a person you do not know, delete the email as it is likely fraudulent.

How to Avoid E-mail Fraud

There are some simple steps you can take to avoid becoming the victim of phishing scams:

  • Be skeptical. Fraudulent emails can look like they come from a real bank and organisation email address. If you have any doubts about an email that looks like it is from your bank or a reputable company, contact them before responding to ensure that it is legitimate. But do not use the toll-free number, email address or website address provided in the email: they may link you to the criminals rather than the bank. Use a phone number, email address or website address that you know is correct.
  • NEVER send your personal, credit card or online account details through an email.
  • NEVER send money, or give credit card or online account details to anyone you do not know and trust.
  • Do not give out your personal, credit card or online account details over the phone unless you made the call and the phone number came from a trusted source.
  • Always enter your bank or organisations website using the website address (URL) that you know is accurate - use a bookmarked link or type the address in yourself: NEVER follow a link in an email.
  • Review credit card and bank account statements as soon as you receive them to check for unauthorised charges.
  • Check your credit report at least once a year by contacting the Australian credit reporting agency Veda - Tel: 1300 762 207.
  • If the email links to a website, check the website address carefully. It's easy to disguise a link to a site. Scammers often set up fake websites with very similar addresses (eg. substituting similar-looking characters, so that paypal.com could be (and has been) spoofed as paypaI.com or paypa1.com. Similarly, a zero can be substituted for the letter O within a URL.) The longer the URL, the easier it is to conceal the true destination address.
  • Do NOT cut and paste a link from the message into your Web browser — as mentioned above, phishers can make links look like they go one place, but that actually send you to a different site. Some scammers send an email that appears to be from a legitimate business and ask you to call a phone number to update your account or access a 'refund'. Because they use VoIP (Voice over Internet Protocol technology), the area code you call does not reflect where the scammers really are. If you need to reach an organisation you do business with, call the number on your financial statements or on the back of your credit card, or type in the web address yourself.
  • NEVER enter your personal, credit card or online account information on a website that you are not certain is genuine.
  • On the Internet, whenever entering personal information, ensure that you are using a secure website. Look for https:// rather than just http:// in the address bar of your Web browser as well as a closed padlock in the bottom right corner of your browser.
  • Make sure that your computer is protected. Install anti-spam, anti-spyware and anti-virus software and make sure they are always up-to-date. You should also install a personal TWO-WAY firewall to act as a barrier to viruses and other external attacks and check for operating system patches and upgrades on a regular basis.
  • Do NOT open suspicious or unsolicited emails (spam): delete them.
  • Be cautious about opening any attachment or downloading any files from emails you receive, regardless of who sent them.
  • Update your browser.
  • NEVER use public computers to access private information. Internet kiosks at hotels and other businesses are convenient but often have Trojans and keyloggers installed that collect and transmit your information to the criminals.

What Should You Do If You Receive a Fraudulent E-mail?

If you suspect that you have received a hoax email, you should take the following action:

  • Axiom suggests that you treat phishing emails as spam and delete the email immediately from your Inbox and Deleted Items folder without opening.
  • Do NOT reply to the email, and do NOT click on any links in the email, or open any files attached to them. Never call a telephone number that you see in a spam email.
  • Spam emails are a proven method for distributing viruses and other unwanted programs. If you have clicked on the link within the email, complete a full security scan of your computer (to check for computer viruses, trojans and spyware).
  • If you have responded to any email by providing your confidential information, or believe you are a victim and have lost money as a result of phishing activities, please contact your financial institution and the local police immediately.

Final thoughts

Criminals have learned that they do not need to pull a gun on you to get your wallet or purse. They're using the Internet to steal your money and identity! Take a few simple steps to stop them, and don't become an identity theft statistic.

David Furlong is a qualified and experienced IT specialist and Technical Trainer. His list of credentials includes MCSE, MCSA, Dip IT, and a Masters in Networking and Systems Administration.

As manager of a computer consultancy firm, Axiom Networking Solutions, he recommends AVG Internet Security to his clients as a solid and reliable choice. For more information or to download your FREE 30 day AVG trial, please visit http://www.avg-antivirus.com.au

 
Copyright 2009 Phishing : A Online Robbery.. Powered by Blogger Blogger Templates designed by Deluxe Templates