Saturday | 6 September, 2008
Computerworld
Media releases are provided as is by companies and have not been edited or checked for accuracy. Any queries should be directed to the company itself.

Sophos Advises on Simple Steps to Avoid Being Phished
06/09/2004 13:36:34

Related Features
  • +

    Your World. . . Hacked 02/10/2007 10:51:23

    As your business becomes more collaborative and global, the risks to your company’s trade secrets rise proportionally. Fortunately, there are new strategies to protect the data that allows you to compete
    The call to Bob Bailey, an IT executive with a major US government contractor, came on an otherwise ordinary day in October 2003. "Why are you attacking us?" demanded the caller, an IT leader with a Silicon Valley manufacturer. He wanted to know why Bailey's company had launched a denial-of-service attack against his network
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

Sophos, a world leader in protecting businesses against spam and viruses, has released a set of guidelines to assist computer users to avoid becoming victims of phishing attacks.

Phishing is an increasingly common type of spam that can lead to theft of your personal details such as credit card numbers or online banking passwords.

Phishing attacks work by the scam artist sending ‘spoofed’ emails that appear to come from a legitimate website that you have online dealings with such as a bank, credit card company or ISP – any site which requires users to have a personal identity or account. The email may ask you to reply with your account details in order to ‘update security’ or for some other reason.

The phishing email may also direct you to a spoofed website or pop-up window which looks exactly like the real site, but has been set up for the sole purpose of stealing personal information. Unsuspecting people are then often fooled into handing over credit card numbers, passwords or other details.

According to the Anti-Phishing Working Group, phishers are able to convince up to five per cent of recipients to respond.

How to protect yourself:

1. Never respond to emails that request personal financial information: Banks or e-commerce companies generally personalise emails, while phishers do not. Phishers often include false but sensational messages (‘urgent - your account details may have been stolen’) in order to get an immediate reaction.

Reputable companies don't ask their customers for passwords or account details in an email. Even if you think the email may be legitimate, don't respond – contact the company by phone or by visiting their website.

Be cautious about opening attachments and downloading files from emails, no matter who they are from. Sophos uses SPF (Sender Protocol Framework). This is an anti-forgery solution which involves publishing a list detailing which servers are allowed to send Sophos emails.

2. Visit banks' websites by typing the URL into the address bar: Phishers often use links within emails to direct their victims to a spoofed site, usually to a similar address such as mybankonline.com instead of mybank.com. When clicked on, the URL shown in the address bar may look genuine, but there are several ways it can be faked, taking you to the spoofed site. If you suspect an email from your bank or online company is false, do not follow any links embedded within it.

3. Keep a regular check on your accounts: Regularly log into your online accounts, and check your statements. If you see any suspicious transactions report them to your bank or credit card provider.

4. Check the website you are visiting is secure: Before submitting your bank details or other sensitive information there are a couple of checks you can do to help ensure the site uses encryption to protect your personal data:

Check the web address in the address bar. If the website you are visiting is on a secure server it should start with ‘https://’ (‘s’ for security) rather than the usual ‘http://’.

Also look for a lock icon on the browser's status bar. You can check the level of encryption, expressed in bits, by hovering over the icon with your cursor.

5. Be cautious with emails and personal data: – Most banks have a security page on their website with information on carrying out safe transactions, as well as the usual advice relating to personal data: never let anyone know your PINS or passwords, do not write them down and do not use the same password for all your online accounts. – Avoid opening or replying to spam emails as this will give the sender confirmation they have reached a live address. – Use common sense when reading emails. If something seems implausible or too good to be true, then it probably is.

6. Keep your computer secure: Some phishing emails or other spam may contain software that can record information on your internet activities (spyware) or open a 'backdoor' to allow hackers access to your computer (trojans). Installing anti-virus software and keeping it up to date will help detect and disable malicious software, while using anti-spam software will stop phishing emails from reaching you.

It is also important, particularly for users with a broadband connection, to install a firewall. This will help keep the information on your computer secure while blocking communication from unwanted sources.

Make sure you keep up to date and download the latest security patches for your browser. If you don't have any patches installed, visit your browser's website, for example users of Internet Explorer should go to the Microsoft website.

7. Always report suspicious activity: If you receive an email you suspect isn't genuine, forward it to the spoofed organisation (many companies have a dedicated email address for reporting such abuse).

Remember not to follow any links in the email – type the web address directly into your browser.

You should also inform the authorities and contact the Internet Fraud Complaint Center (IFCC). This is a US-based organisation that works against phishing scammers and their sites worldwide.

news ends

Notes for Editors.

About Sophos. Sophos is a world leading specialist developer of anti-virus and anti-spam software. Sophos is headquartered in the UK and protects all types of organisations, including small- to medium-sized businesses, large corporations, banks, governments and educational institutions against viruses and spam. The company is acclaimed for delivering the highest level of customer satisfaction and protection in the industry. Sophos's products, backed by 24 hour support are sold and supported in more than 150 countries.

Sophos's regional head office for Australia and New Zealand is in Sydney and hosts one of the company's three Computer Virus Research and Development Laboratories to provide global support services.

http://www.sophos.com.au

FOR FURTHER INFORMATION: Rob Forsyth (rob.forsyth@sophos.com.au) is available for comment: +61 2 9409 9100 (tel) +61 2 9409 9191 (fax)

Sophos's press contact at Gotley Nix Evans is: Michael Henderson (sophos@gne.com.au) +61 2 9957 5555 (tel) +61 413 054 738 (mobile) +61 2 9957 5575 (fax)

Market Place

Computerworld Member Login


 

Prioritizing Services with IT Service Management (ITSM)

Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)

To be repeated on:

Thursday 4th, September 2008
11:00am EST (Sydney Australia)

Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.

Attend and discover:

  • How to deliver value to your business through ITSM
  • Best practice ITSM implementation
  • Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
  • If service-oriented ITSM is best for your business
Whitepaper

Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101

Email archiving is emerging as a critical new application for managing email. Learn how to reduce and manage online and offline email storage, add powerful tools for legal discovery and compliance and extend native exchange recovery capability by reading on.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links