Advertisement
Promo

Security threats Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Microsoft: Phishing is going out of fashion

Tom Espiner ZDNet.co.uk

Published: 13 Dec 2006 13:46 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Organised criminals are losing interest in harvesting consumer banking details, according to Microsoft UK chief security adviser Ed Gibson.

Speaking to ZDNet UK this week, Gibson said that powerful cybercriminals would not waste time trying to harvest individual banking details, but instead concentrate on acquiring networks of compromised PCs — botnets — to launch attacks against companies.

"Organised criminals are not really interested in bank details — criminals want bandwidth to attack companies," said Gibson. "Who's grabbing the details is changing."

The practice of phishing for bank details, in which fake emails claim to come from a legitimate financial institution and try to elicit account details, is traditionally associated with highly organised criminal networks. Gibson, though, claims it is moving further down the criminal food chain and being perpetrated by malicious individuals.

Now, serious cybercriminals are concentrating their efforts on gaining access to botnets, which are large networks of hijacked computers. They use botnets to attempt to extort money, by launching distributed denial of service (DDoS) attacks against an organisation's systems with information, causing it to crash. This can deprive an e-commerce site of visitors, and ultimately cost it money.

Gibson said that it was difficult for law enforcement to track phishing attacks because of the speed that hackers change the IP addresses and machines they use to launch attacks.

"These guys are box hopping every 90 seconds. You can identify an IP address in the UK, but in between it's gone to the US, Korea, Germany — how does law enforcement tackle that?" said Gibson.

Rather than law enforcement dealing with the problem, Gibson said that systems should be made more resilient to make such DDoS attacks less of a threat.

"I liken it to the same way a consortium of online gambling companies hardened their systems — now you don't hear much about the gambling companies being breached or extorted," said Gibson.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
276 out of 352 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Nasa hacker petition presented to Numb...

Sting's wife Trudie Styler and Janis Sharp have presented a petition to Number 10 calling for Nasa hacker Gary McKinnon not to be extradited to the US. Styler, and Sharp, who is... More

Post a comment

UK to appoint cyber-sec tsar?

The UK is to appoint a cyber security tsar along the lines of the US, according to a story in the Telegraph this morning. The story is similar to one that appeared in the Guardian... More

Post a comment

Nokia Siemens denies Iran web snoop

Nokia Siemens has denied providing deep packet inspection capabilities to the Iranian authorities, following an article in the Wall Street Journal on Monday. The WSJ published the... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters