ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security management Toolkit

Toxic phishers scam the unwary

David Berlind ZDNet.com

Published: 12 Jan 2004 15:55 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

However, the financial risk that's connected with each credit card transaction isn't the only hard dollar cost to corporations. "In most cases so far, as a matter of good customer relations," said Jevans, "where a customer has experienced a loss as a result of phishing, the spoofed institution has [reimbursed them] even if their policies don't expressly guarantee that treatment. As evidence of how this cost is hitting the bottom line, several Australian banks have set aside a $2m fund just to cover any losses associated with phishing."

Jevans cited other areas of loss as well. "When NatWest had to shut its site down, it incurred the added expense of setting up and manning a phone number that customers could call. In situations like that, dissatisfied customers that have to wait a long time on jammed phone lines might take their business elsewhere," Jevans said.

According to Jevans, another unexpected cost could arise after a large number of accounts are successfully phished. Jevans said the cost to issue new credit cards, accounts and passwords is about $50 to $60 per user. "You can see how the costs can quickly escalate if 2000 accounts are compromised. Not only that, once a phisher has succeeded with a particular institution, the trust chain -- especially in email -- is broken. So, it makes it much more difficult for the institution to maintain a relationship via email with its customers."

Liability is yet another area of concern for organisations that are spoofed. Jevans said that one of the Anti-Phishing Working Group's members is being sued by customers whose accounts were successfully phished. Whether the plaintiffs will get anywhere could be the topic for an entire column, but regardless of whether a company wins or loses such a case against its customers, it still must bear the legal costs. The spoofee may not be the only target of such a lawsuit. In an effort to cover their tracks, many phishers will publish their web pages on Web servers that they've hacked into, unbeknownst to the operators of those Web servers. Under these circumstances, it's entirely possible that the operator of the hacked Web server could be sued on the grounds of negligence through lax security as well.

While businesses everywhere are staring down the barrels of phishers' shotguns, they're also trying to figure out how to put a stop to it. As with spam, the solutions are primarily technological, legal, and social. The biggest priority currently is to deal with the major phishing attempts as reports of them surface. Obviously, the first order of business is to disable the offending page. "Depending on the situation," Jevan said, "this could require any number of techniques. For example, if the phisher published the page by hacking into a legitimate server, you can't just go and shut that server down or have all the paths to it cut off by the ISPs. In some situations, that's what you need to do, but in others you have to work with the operator of the server to remove the offending page."

Jevans warns that even the most proactive of responses to a phishing report may not be sufficient. "It can take anywhere from 19 hours to 6 ˝ days before a site or a Web page is cut off," said Jevans. "It takes longer when the sites are located overseas and increasingly, more and more of these sites are showing up in Eastern Europe and Asia. Quite often, by the time something is shut down the damage is done." Jevans noted that pilfered funds pass through temporary accounts and are eventually electronically shuffled to offshore accounts in a way that makes the money trail almost impossible to follow. "Regrettably, no phishers have been caught yet," Jevans said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
226 out of 425 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:



Sentry Posts Blog

Virtual Teams: Small Business Innovati...

Virtual Teams: Small Business Innovation Author: Eric Everson, Founder – MyMobiSafe.com As the founder of MyMobiSafe.com, I’ve found that because of our presence in the industry... More

Post a comment

Mobile Security and Innovation: An Ope...

Mobile Security and Innovation: An Open Case Author: Eric Everson, Founder MyMobiSafe.com The times are changing in the mobile industry as “big wireless” in the US Markets are calling... More

Post a comment

Government launches new e-crime unit

Ok, so this is outside of my main area of focus of sustainable and green tech but I do track some security issues too. I was at a meeting last week with Microsoft's security advisor... More

Post a comment

Featured Talkback

In association with Intel
It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link

DOWNLOAD

Security Essentials

Security Downloads

There are masses of security suites out there for small businesses. Here's a selection to get you started

Editor’s Rating
1 Norton 360™
2 AVG Anti-Virus Free Edition Rating: 10
3 PC Tools AntiVirus Free Edition
4 Kaspersky Internet Security

See All Software

In association with Symantec