ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Companies warned over corporate identity theft

Munir Kotadia ZDNet.co.uk

Published: 28 Oct 2003 17:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Police say companies need to be more aware of the growing risk of corporate identity theft, following a recent spate of frauds that targeted customers of several high street banks.

Over the past month, Internet banking customers of NatWest, Lloyds TSB, Barclays, Citibank and Halifax have received emails that appear to be from their bank. The emails contain a link that redirects the user to a replica of the bank's official Web site, which has been set up in order to extract the customers' usernames and passwords.

The National Criminal Intelligence Service (NCIS), which works with the UK's law enforcement agencies to fight organised crime, is concerned about this growing phenomenon because the general population is often not computer-literate enough to tell the difference between a spoof email or Web site and a genuine one. According to the NCIS, this lack of education makes it relatively simple for organised criminals to target online banking customers in an attempt to gain access to their accounts.

A spokesman for the NCIS, who requested anonymity so his name would not be used in future email scams, said companies should work towards reducing the risk of their corporate identity being abused.

Basic precautions could start with a company ensuring it owns all the different permutations of its name. For example, if a customer received an email from or was redirected to a Web site using the "barclays-banking.com" domain, they might believe it to be genuine, but Barclays does not own that address; at the time of writing, it is available for anyone to buy. Similarly, although Lloyds TSB owns "lloydstsb.co.uk", it does not own "lloydstsb-bank.co.uk", which could easily be used in a future 'phishing' trip.

The NCIS spokesman told ZDNet UK that people need to get to know the email systems as well as they know the traditional postal system. "People know that stamps are perforated, business envelopes look a certain way and if they get a handwritten envelope from a business, they think 'that's a bit strange'. But with email, although those indicators are present, people have not yet learned to look for them," he said.

Nigel Miller, commerce and technology partner at law firm Fox Williams, said banks are in a tricky position because on one hand they encourage customers to migrate to online banking services and try to convince them they are safe, but with the other hand they have to warn them of the risks. "What is the responsibility of the bank to educate their customers? It doesn't sound very good when you are trying to sell them a service, but have to tell them how risky it is," he said.

One as yet unanswered question is where the lists of customer email addresses used by the attackers came from. According to Miller, if evidence could be found that the lists were leaked from the banks themselves, they could face serious criminal charges for breach of the Data Protection Act: "If there has been a leak, it could give rise to compensation claims or criminal liability under the Data Protection Act," he said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
76 out of 150 people found this useful



Company/Topic Alerts

Create a new alert from the list below:














Related Jobs

C#.NET DEVELOPER / 12 MONTH CONTRACT / I PAY MORE THAN OTHERS AGENCIES

I WILL pay more than the other agencies working on this. If you answer yes to these questions then you MUST send me your CV. Do you want to work for ...

Resource Manager

The Identity & Passport Service needs proven resource planning and delivery expertise to ensure the success of one of the largest initiatives of its ...

Project Manager Financial Services

Citigroup, Friends Provident and Lloyds TSB to name a few. Project Manager Financial Services Location: Reading, Berkshire, South East. Salary: ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation