Phishing
Edwin Parcero
Phishing is the act or the attempt to acquire sensitive personal information (ie, passwords, bank info) through the use of email, instant messaging, etc.
Today, online criminals put phishing to more profitable uses. Popular targets are users who do financial transactions online, such as users of online banking services, eBay and PayPal. Phishers usually work by sending out e-mail Spam to a large number of potential victims.
Let's see what a typical phishing email looks like. (Warning: parts of the emails are from an actual email spam.)
The email will appear to come from a well-known company and will contain a subject line regarding the customer's account.
> From : Bank One Support Team <support-team@bankone.com>
> Subject : Important information for BankOne Customers
> Date : 5/4/2005 1:32 PM
The user is then provided a link in the same page that goes to the fake website. Once the recipient has clicked on the link within the email, they will be directed to what appears to be their online bank, but in fact, it's a fake site created to capture their account information.
> Dear Bank One(R) member,
>
> You are requested to confirm account information through Bank
> One's update site at http://confirmation- firstusa.com.
A common approach is to tell the recipient that his account will be deactivated unless action is taken.
> If you don't follow these instructions your account is going to
> be suspended in 48 hours.
And just to make it look official, they put these at the end
of the email.
> (c) 2005 BankOne Card member Services, Inc. Bank One is a
> federally registered service mark. All rights reserved.
>
> Your BankOne ID number is: [847b7c---]
It is best to just get rid of these types of emails right away and call your bank if you do have an account with them. It is highly unlikely that they'll let you send out sensitive information through email.
Articles regarding phishing can be found at
Anti-Phishing Work Group (http://www.anti-phishing.org).
"How to Avoid Phishing Scams"
http://www.windowsecurity.com/articles/Avoid-Phishing.html
|