Publicité

Big-game phishing !

30 novembre 2004, 00:00

Par

Partager cet article

Facebook X WhatsApp

lexpress.mu | Toute l'actualité de l'île Maurice en temps réel.

First of all, do not rush to your Oxford concise dictionary to look up the word phishing. It has not been included yet, at least not in the ninth edition currently in my possession. But, given the impact this phenomenon is currently having on our lives, you can be sure it will soon be in it.

Phishing stands for password harvesting fishing and it is the latest trend in the long list of scams plaguing the Internet. The FBI called phishing the "hottest, and most troubling, new scam on the Internet." If you have been using email lately, chances are good that you have seen some of its hooks dangling in front of you. According to a May 2004 report by research analyst firm Gartner, phishing attacks by hackers on online consumers have become so widespread that an estimated 57 million Americans have received these fraudulent e-mails. Direct losses from identity theft fraud against these phishing attack victims cost US banks and credit card issuers $1.2 billion last year.

Overall, the concept of phishing is rather simple. Criminals phish for personal information by setting out hooks and hoping that some recipients of their fraudulent emails will take the bait. It begins with an e-mail that reads like an authentic message from a bank, store, Internet-service provider or online business - complete with corporate logos. These emails usually have as subject matter enticing or alarming wordings like ‘CONGRATULATIONS YOU WIN!!!’, ‘eBay Notification (Your account can be suspended)’, ‘important bank mail’, ‘Verify your details with XXX Bank’ etc. that will prompt the user to take action.

The user is provided with a convenient link in the same email that takes the email recipient to a fake webpage looking like that of a trustworthy company. Once on that page, the user enters his/her personal information, which is then captured by the fraudster. The latest one I received in my mail box concerned the US Bank with the following line as subject: "Attention to all US bank clients". The email contained a perfectly legal link but, once you click on it, you are redirected to the fake page and prompted to enter username, password, pin code, credit card numbers and social security number. Given that all this information confers you an identity in the cyberworld, once a fraudster gets this, you can be sure that your cyber identity will be stolen and used for illegal purposes. This is why phishing is also known as identity theft.

Illegal use of this information includes use of the victims' credit/debit card to open online accounts and hijacking of online accounts to steal money. For instance, eBay users have had their accounts hijacked in this manner while scammers use the accounts to list high-value items, receive payments from hopeful buyers but never send the goods. Other victims have had their credit rating and financial livelihood destroyed when their identity has been used to raise finance, while others have seen their credit/debit cards used to buy goods online. On one occasion there was a bug in Microsoft’s Internet Explorer bowsers that allowed a fake URL to be shown in the browser's address bar while a forged page was being viewed. Scammers had rich pickings until Microsoft issued a patch in February 2003.

In order not to get phished by phishermen, there are basic rules that must be followed:

● First of all, treat all emails with suspicion - What you see in the email body can be forged, the sender's address or return address can be forged and the email header can also be manipulated to disguise its true origin.

● Never use a link in an email to get to any web page. If you must go there, type the URL directly into your browser's address bar.

● Never send personal or financial information to anyone via email.

● Regularly log into your online accounts - don't leave it for more than a month before you check each account.

● Scrutinize your bank, credit and debit card statements and ensure that all transactions are legitimate. If anything is suspicious, contact your bank and all card issuers.

● Ensure that all your software is up-to-date - for instance, if you use Microsoft's Windows®, run Windows Update every day when you first connect to the Internet. If you use other operating systems or browsers, then check daily for patches or updates. Security loop holes are regularly discovered in software and many scams have utilized vulnerabilities in Internet Explorer as explained above.

The Internet is a great tool and nowadays everything is becoming Internet-based. Online banking, online shopping, online bill paying. You do everything in the comfort of your home. But the adverse side is that you can also get robbed still in the comfort of your home. As, among the great maze of information, lie prowling scammers and fraudsters ready to get your money once you give them the slightest opportunity. And here also, as usual, prevention is better than cure: Be good, be careful and be aware and you will never get hooked.

<B>Ukesh Ramjutton</B>

Publicité