ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Open season for phishing as attacks soar

Munir Kotadia ZDNet.co.uk

Published: 25 May 2004 13:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The quantity and quality of phishing attacks grew at an alarming rate in April, according to the Anti-Phishing Working Group.

Phishing is an Internet scam where official-looking emails attempt to fool users into disclosing online passwords, user names and other personal information. Victims are usually persuaded to click on a link in an email that directs them to a doctored version of an organisation's Web site. It is estimated that up to 5 percent of phishing emails persuade users to perform an action, such as clicking on a link, that could result in credit card fraud, identity theft or some other financial loss.

On Monday, the Anti-Phishing Working Group, which was formed last year to share information about phishing attacks targeting the financial sector, published its Phishing Attack Trends Report for April 2004 and revealed that attacks had increased by 180 percent since March and 4,000 percent since December, with an average monthly increase of 75 percent.

Dave Jevans, chairman of the Anti-Phishing Working Group said that hackers, identity thieves and virus writers were collaborating to produce ever more sophisticated attacks. Jevans said that in April his organisation discovered a new attack that is able to modify a browser's address bar to display an incorrect Web site address. This makes it more likely that even sophisticated users could be fooled into interacting with a fraudulent Web site.

"These attacks are increasing and becoming much more sophisticated -- to the point of being literally indistinguishable from legitimate email, even for technically savvy recipients," said Jevans.

James Kay, technical director at email-security firm Blackspider, said that phishing is fundamentally a spam problem so it can be addressed by analysing the contents of incoming messages and recognising certain patterns and peculiarities.

"When the filtering technology sees a Web address where the displayed link is completely different to the actual link, it is an indicator. These types of behaviours are can be coded into standard spam-detection tools," said Kay.

Kay said that he expects the volume of phishing attacks to continue growing. Until recently, he said, the majority of phishing attacks were attempts to obtain account details for e-commerce sites but now the focus has shifted to financial institutions. This was illustrated by the Anti-Phishing Working Group's report, which found that eBay has been superseded by Citibank as the company targeted most often by phishing scams.

"Ordering a bunch of books from Amazon is good but getting a load of money deposited into your Bulgarian bank account is far more interesting," Kay said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
87 out of 166 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Network Security Technician - North London 20 25K+BONUS:

This IT Security Specialist - focuses on Intrusion Prevention, Anti Virus URL & Email Filtering Are you a person that can build upon this companies ...

Systems Administrator/Server2003/ AD/London/ Exchange/TCP/IP/ DNS/DHCP

Systems Administrator/ MCSE/ Server2003/ Active Directory/ SW/London/ Exchange/Anti Virus/ Backups/ IIS/ XP Office/ BES/ TCP/IP/ DNS/ DHCP Worlds ...

Server Administrator-West Sussex- AD- Exchange- Server2003- 29k+ Bens

Server Administrator-West Sussex- Active directory- Exchange- Server2003- TCP/IP- Monitoring- Anti Virus- Backups- Storage- 29k plus shift- MCSA / ...

Sentry Posts Blog

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Google sponsors open source security p...

Google has announced it is to sponsor oCERT, an open source computer emergency response team. In a blog post on Monday, Google security engineer Will Drewry said that one of the... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation