ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Phishers get smarter

Matt Loney ZDNet.co.uk

Published: 06 Jun 2005 13:20 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Phishers are becoming increasingly sophisticated in their attempts to grab user names, passwords and other personal data from users of commercial websites, according to latest industry research.

April's report from the Anti-Phishing Working Group, published on Monday, indicates an 11 percent drop in the number of reported attacks using simple IP address domains. The overall number of reports continued their upward trend to reach 14,441 for the month, said the APWG, which compiles its report with the help of WebSense.

The decline in the number of IP-only attacks, in which users are misdirected to a site that just has an IP address and so is less likely than one showing a domain name to deceive them, means phishers are getting better at disguising their scam attempts.

"A lot of the recent phishing sites use hijacked servers where the scam is located on the domain of a legitimate enterprise," said the APWG, adding that this technique requires the phishers to get access to the servers, typically by hacking or installing malware.

"This tactic gives the scammers the advantage of having a link that leads to a legitimate domain that cannot be blacklisted. In fact, it is likely that such a phishing message would get through a spam filter that uses ‘whitelisting’."

The number of brands targeted stayed the same from March to April, though there was significant churn within this group, with 11 brands being replaced. "The visible trend is that there is a consistent set of favourite brands targetted by phishers combined with an ever-changing tail of brands in the broader market," said the APWG.

"Brands in the favourites list tend to remain for a long time -- most of the big names are here -- and the ones in the tail frequently change." This separation has its logic, said the group: while some of the scammers count on the popularity of some brands to generate more hits to the phishing site (the ones in the favourites list), others try to scam the customers of companies that had not experienced the phenomenon so far, and are presumably less experienced in exposing phishing.

Financial services companies continued to be by far the most targeted industry sector, accounting for 84 percent of reported phishing attacks in April. ISPs accounted for 11 percent, followed by retail companies.

The APWG also said it had recorded a rise in the 'main-in-the-middle' phishing attacks. This type of attack uses some knowledge on the way a given legitimate site processes logins. Given such knowledge, a scammer can build a site that acts as a 'front end' mask for the legitimate login site – it would return an error message when incorrect login data is passed, for example.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
72 out of 146 people found this useful


Full Talkback thread

1 comment

  1. SELF HELP MEASURES AND CYBERSPACE The problems as... PRAVEEN DALAL (PERRY)

Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

Enterprise Architect

With a broad portfolio of over 40 brands, including Carling, Grolsch and Coors Light, Molson Coors Brewing Company has over 11,000 employees ...

SAP MM SD Support Analyst - North Yorkshire - 40,000

Our client is a global leader in its market place and is listed on the FTSE100; with an impressive list of brands, products and many household names, ...

WebMaster opportunity - Worlds leading Sports and Media Company

Indeed their partners include many of the world's most famous brands, media companies and sports names. My client offers cutting-edge digital media, ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment