Friday | 10 July, 2009
CSO
Phishy Business
Paul Roberts (CSO (US)) 16/10/2003 10:44:51

Some customers of the popular PayPal online payment service were swindled recently after identity thieves used spam and phony Web sites to swipe their personal billing data and credit card numbers.

The PayPal scams and others like it point to the growing problem of identity theft on the Internet. The US Federal Trade Commission reports that identity theft has been the top complaint registered in its Consumer Sentinel database for the past three years. And in July, Gartner said that in a survey of approximately 2,400 households, 3.4 percent of US consumers had been victims of identity theft. Translation: More than 7 million consumers were victims of identity theft from June 2002 to June 2003.

The increased identity theft activity prompted the FTC, FBI, the National Consumers League and ISP EarthLink to publicly warn Internet users about the dangers of online identity theft scams. In particular, the groups pointed to the growing numbers of so-called "phisher" Web sites, which are designed to look exactly like legitimate Web addresses, such as Amazon.com, BestBuy.com and PayPal.com.

Customers of those sites are often lured by spam purporting to come from a customer support rep at the company. The e-mail messages provide Web links to the phisher sites and ask customers to update their account information, often threatening to cut off their accounts if they don't.

When victims enter their information into forms provided on the phoney sites, that information is sent to servers owned by the thieves, which are often located outside the United States.

Since the beginning of 2003, a number of high-profile companies have had their good names sullied by phisher e-mail scams, including Citibank NA and Best Buy.

CSOs can take steps to educate employees about such dangers. The FBI suggests the following tips:

— Exercise extreme caution when responding to unsolicited e-mail messages that ask you for personal, financial or identifying information, such as a Social Security number, account password or credit card number.

— Navigate to a company's Web site yourself if you need to update account information, rather than following links to a site from an e-mail message or another Web site.

— Beware of sites that have long or odd-sounding domain names. Phisher sites often use legitimate-looking Internet addresses. For example: www.paypal-billingnetwork.net was the address of a recent phisher site targeting PayPal (www.paypal.com) customers.

— Report suspicious e-mail messages to your ISP, and contact the company in question if you have concerns about an e-mail message that you received.

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Additional Resources
Newsletter Subscription
Sign up for our CSO Online newsletters!
RSS Feeds
Syndicate content
 
Whitepaper

LANPlanner | Ensuring High Performance WLAN Networks

Learn how the Motorola LANPlanner facilitates prompt and precise planning and the design and measurement of robust 802.11a/b/g/n networks. Download this paper now to discover how to take wireless network performance to the next level.

Sponsored Links