Friday | 5 September, 2008
Computerworld
Reports of phishing attacks up, again, in May
Paul Roberts (IDG News Service) 25/06/2004 08:03:02

Computerworld Buyer's Guide - Vendors Matched to this Article
Related Features
  • +

    Your World. . . Hacked 02/10/2007 10:51:23

    As your business becomes more collaborative and global, the risks to your company’s trade secrets rise proportionally. Fortunately, there are new strategies to protect the data that allows you to compete
    The call to Bob Bailey, an IT executive with a major US government contractor, came on an otherwise ordinary day in October 2003. "Why are you attacking us?" demanded the caller, an IT leader with a Silicon Valley manufacturer. He wanted to know why Bailey's company had launched a denial-of-service attack against his network
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

Incidents of phishing, a type of online identity theft, were up slightly in May, after surging in March and April, according to a report from an industry group.

The number of unique phishing attacks reported to the Anti-Phishing Working Group increased 6 percent in May to 1,197, with an average of 38.6 reports each day, slightly higher than in April.

Phishing scams are a form of online crime in which unsolicited commercial ("spam") e-mail is used to direct Internet users to Web sites controlled by the thieves, but designed to look like legitimate e-commerce sites. Users are asked to provide sensitive information such as a password, social security number, bank account or credit card number, often under the guise of updating account information.

Financial services companies continued to be the primary target of the scams, and Citibank Inc. customers were the most frequent target of phishers. Scams using the names of eBay and Paypal, an eBay company, were also rampant in May, said the group, which is sponsored by Microsoft, VeriSign and antispam company Tumbleweed Communications, among others.

Phishing scams have surged in recent months to 1,100 in April, a 178 percent increase from March, according to figures from the Anti-Phishing Working Group's April report. In May, the group received reports of over 300 attacks a week, with a big drop-off the week of May 29, possibly due to the Labor Day holiday, the report said.

Faked sender, or "from" addresses on e-mail messages continued to be a popular tool of scam artists. At least 95 percent of e-mail messages submitted to the Anti-Phishing Working Group used such addresses.

The spoofed addresses are frequently identical to legitimate addresses at the companies being targeted by the phishers, for example: support@citibank.com and billing@aol.com were common spoofed addresses. The remainder of phisher e-mails submitted to the group came from so-called "social engineering addresses" -- online mailboxes at domains run by the scam artists that resemble actual e-commerce sites. The domains, such eBay.billing.com, instead of ebay.com, or verify-visa.net, as opposed to visa.com, are designed to fool customers, the report said.

The phishing problem has received increased attention from the private sector and governments in recent months, as online criminals have seized on the scams as a lucrative and relatively simple way to make money.

On Tuesday, credit card company MasterCard International said it was partnering with NameProtect, an online brand protection service, to combat online identity theft and a black market in stolen credit card numbers. The two companies plan to aggressively pursue those behind phishing scams and work with law enforcement to shut down Internet sites and tools used by the identity thieves, the companies said in a statement.

Also, on June 16, a consortium of companies from across industries announced a new group that will tackle phishing. The Trusted Electronic Communications Forum (TECF) has representatives from leading retail, telecommunications, financial services and technology companies, including Best Buy, AT&T, Charles Schwab, Fidelity Investments and IBM.

The TECF will work with the U.S. and other governments, as well as standards organizations and companies to fix problems such as e-mail and Web-site spoofing, which contribute to a fast-growing online identity theft problem, the group said.

Computerworld Buyer's Guide - Vendors Matched to this Article
Market Place

Computerworld Member Login


 

Prioritizing Services with IT Service Management (ITSM)

Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)

To be repeated on:

Thursday 4th, September 2008
11:00am EST (Sydney Australia)

Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.

Attend and discover:

  • How to deliver value to your business through ITSM
  • Best practice ITSM implementation
  • Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
  • If service-oriented ITSM is best for your business
Whitepaper

SOA and Agility

Organizations need agility to maintain strategic advantages in businesses operating on faster and faster time-scales. The difference between gaining and losing market share may very well depend on the ability of organizations to deploy updated or new applications before their competitors. Read on to discover how SOA-based application development can meet the promise of reduced application development and maintenance costs through service reuse.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links