Phishing
The Internet has opened up so many possibilities to each
and every one of us, it's hard to imagine what life was
like before the Internet existed. But with computers and
technology has also come a new breed of criminals.
They're savvy with programming and computers, and know
just how to commit fraud with ease using the Internet.
And for us, the innocent victim, we can find ourselves
ripped off in a big way without even knowing it's
happened until too late.
Phishing is one of the simpler and more popular forms of
Internet fraud. Basically, the criminal will send you an
email that looks exactly like a legitimate email from a
reputable source. Often these come in the form of emails
from your bank, or from eBay. The idea behind the email
is to get you to pass over private or financial
information, which the fraudster can then use to empty
your bank accounts or credit cards. In the worst cases,
these criminals use the information to steal your
identity, taking out loans and destroying your credit
history completely.
While it may seem that the deck is stacked in favor of
the criminals, there are things you can do to avoid
getting ripped off by a phishing scam. First, never
respond to any email that appears to come from your bank
or credit card company. Often these are designed to make
you panic, suggesting that someone has changed your
account password or accessed your account from an
unfamiliar location. You are told to login at the web
address contained in the email, so that you can verify
your correct details. Instead, all that happens is the
criminal's computer records the information which is
then used to log in to and steal from your accounts.
The bottom line is that no financial institution will
ever contact you via email and request this sort of
information. They are well aware of the dangers of
phishing, so the last thing they would do is confuse the
issue by sending out similar emails themselves. So if
you receive an email that appears to be from a financial
institution you do business with, remember:
- Don't click on any links
- Don't call any phone numbers in the email
- Don't reply to the email
Instead, look up the bank's phone number and call them
directly yourself. Tell them about the email and ask if
it's legitimate. I can almost guarantee it won't be. The
people who send out phishing emails are getting more
sophisticated, stealing logos and mimicking bank emails
to perfection, but don't be fooled. When in doubt, call
the bank directly yourself.
As well as protecting yourself from phishing emails, you
also need to protect yourself from sites and emails that
phish your personal information. Be very wary of typing
in your bank account details, social security number,
personal details, PIN numbers or passwords. Never
respond to an email asking for these types of
information. When you need to enter information into a
website for any reason, make sure it's a secure website
(look for the padlock icon down the bottom of your
browser). Also make sure it is a reputable website that
you have located for yourself, not one you've reached by
clicking an email link.
A newer form of phishing email involves mimicking well
known stores, and including links to "buy" certain items
that are on special. So, for instance, you might receive
an email from a department store, with a massive
discount on something you'd like to buy. Even if the URL
looks legitimate, don't be fooled. Many sophisticated
phishing emails will incorporate URLs that are almost
exactly the same as the legitimate ones, with just a
letter or two changed. Rather than clicking on the email
link, find the URL for that store, type it into the
browser and go directly to the store that way. Don't go
through the email link. If you can't find the special on
the legitimate website, you can always telephone the
store and ask if it was a genuine offer, and where to
find it.
If you do receive a phishing email, always do your best
to report it to the company concerned. Many banks and
businesses have an email address such as postmaster@theirURL
and you can forward a copy of the email there. This
helps companies to warn other customers who may fall
victim to the phishing scam. For PayPal, you can use
spoof@paypal.com.
Finally, if you receive a phishing email that really
bothers you, perhaps because it's such a good rip-off,
or it seems very threatening, then you can report it to
the Internet Crime Complain Center. This is a government
agency involving both the FBI and the National White
Collar Crime Centre that attempts to shut down the
criminals who instigate phishing scams. Remember, the
more vigilant we all are both in recognizing phishing
emails and reporting them, the more difficult the
criminals will find it to be successful. At some point
it may even stop being worthwhile for criminals to
continue their phishing scams. I certainly hope so.
|
|
|
|
|
Review Our Directory for Defenses Phishing And Vishing
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Our Best Web Links For Defenses Phishing And Vishing
|
1. UGN Info Manager Lynn Wegley ... July 17, 2006 This week's Info includes: Phishing, Vishing & the latest defenses * MacBook: "Hot enough to fry an egg..." * Gabby and/or Voice Activated iPod? * UGN Salutes: EMug * Macintosh OS ...
http://www.user-groups.net/2/2.html |
2. SecuriTeam Blogs » Culture ... multiple votes from the same IP address. Their defenses are client-based, so one does not even have ... ... in recycling bins?) Vishing: Santa Barbara Trust (Voice or Phone Phishing) gadi - June 23, 2006 ...
http://blogs.securiteam.c ...egory/culture/page/2/ |
3. Rspam.com Everything you need to know about spam
http://www.rspam.com |
4. What's New! ... prevention and awareness are your best defenses. Here are some articles you may find helpful: Reporting Identity Theft Warning: Phishing Scams What is Vishing? International Lottery Scams Reporting ...
http://www.uspsfcu.org/security_alerts.asp |
5. Security Resources - Links - Security RC - CIO ... get it? (December 1, 2000 - Darwin) Test Your Defenses It isn't easy to bare your network to ... ... Your Data A New World of Risk First Phishing, Now Vishing Movers & Shakers CIO News Alerts Kochs ...
http://www.cio.com/security/security/links.html |
6. PC World - PC World Downloads - Secure IE ... heavy browser add-in that fortifies your defenses by blocking unauthorized ActiveX Controls ... ... Leap Check your SNMP security Forget phishing, first 'vishing' atta... RSS Feeds Our latest content ...
http://www.pcworld.com/do ...on/0,fid,22719,00.asp |
7. Complete COMPUTER SECURITY Information - DAVID WOODSMALL ... SONY's USE OF ROOT-KITS | SPAM | Spear-Phishing | SPYWARE | Storage Security | SYMBIAN ... ... USB Security | VANDALS | VIRUS INFO ** | Vishing | VULNERABILITIES | WAP | WEP | WEB BUGS | WEB ...
http://home.nc.rr.com/woodsmall/security.htm |
8. Dark Reading - The Business of IT Security ... Warns of Vishing July 10, 2006 : Secure Computing warns of new VOIP-based phishing scam Dark ... ... exploit from detection by signature-based defenses, Symantec warned Tuesday Firewalled: Jelly ...
http://www.darkreading.com/topics.asp?node_id=1716 |
9. PCSecurityPost.com - The Online Resource for Computer Security and Virus Inf... ... battlefield of computer security exploits and defenses ... current real-world computer security ... ... Cleaners Pharmers Phishing Research Security Scanners Spyware Vishing Did You Know? Threats to ...
http://www.pcsecuritypost ...ity+security+scanners |
10. Whitedust Security Portal - Mobile ... few days with his take on SIP Worms and Vishing (VoIP Phishing). UK firms ignore mobile email ... ... have proved that hackers can breach the defenses of these Gen. 1 tags using cheap, readily ...
http://www.whitedust.net/section.php?SectionID=12 |
11. News | SecGuru ... Flaws Undermine IT Defenses 1 Point , 37 views Read More ... Think it's easy to launch a phishing scam? It's not. Scams Target ... distinguish it from the crowd. Vishing is the new Phishing 1 Point ...
http://www.secguru.com/tag/news |
12. SANS - Internet Storm Center - Cooperative Cyber Threat Monitor And Alert System ... approach that when compared to medieval defenses is the equivalent of not trying to build a ... ... out daily in volume. * Voice-over-IP Phishing (Vishing ) Somebody had to come up with another ...
http://www.isc.sans.org/diary.php?date=2005-12-31 |
13. Secure Computing Resource Center ... A new variation of phishing: Vishing Spammer in the Slammer ... more protection Mutant Phishing scams morph into Pharming ... G2 v6.1 and Application Defenses, in Q1 2004 SafeWord tokens ...
http://www.searchopolis.c ...eid=9&filter_pathid=1 |
|
|
|