In Brief

ID Theft: Gone Phishing

Phishing is the latest scam for identity theft

By Sarah D. Scalet

March 01, 2004CSO — "Recently our customers have reported receiving fraudulent e-mails that appear to be from Bank One," begins an e-mail that appears to be from Bank One. "Please log in and learn more about what's happening and how to protect yourself."

It sounds convincing enough. But recipients who followed the link are taken not to Bank One's website but to a bogus one set up to gather user names and passwords. It's the latest kind of Internet scam—one that's known as "phishing," explains Dave Jevans, chairman of the newly formed Anti-Phishing Working Group and a marketing senior vice president for Tumbleweed Communications, noting that the hacking community has been using "ph" instead of "f" since the days of "phone phreaking" in the 1970s. "They're out there casting a wide net and pulling in a smaller number of fish."

While some scams are easily spotted by misspelled words and bizarre claims, others are becoming increasingly sophisticated, copying graphics and text from legitimate e-mails and websites.

Even the bogus URLs are getting harder to spot. Phishers trick users with links to websites that were similar to legitimate oneswww.paypa1.com (spelled with a "1" instead of an L) for instance. And a bug in Microsoft Internet Explorer allows phishers to blank out portions of Web addresses, making URLs appear legitimate, Jevans says. In another approach, a link opens a pop-up window for account log-on, then redirects the user to the legitimate website. "The only way you can tell is by looking at the JavaScript or HTML source," says Jevans, whose working group documents new scams at www.anti-phishing.org.

"The majority of phishing e-mails are looking to steal your information or online user ID, as opposed to trying to assume your identity," says Howard Schmidt, former vice chairman of the president's Critical Infrastructure Protection Board and eBay CISO. "But the results are not much different. You still have to go back and clear your credit record and show that wasn't you."

Other stories by Sarah D. Scalet

$firstKeyword

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors