Intersting — and alarming — note on how phishers are getting more sophisticated. “Phishing” is an attempt, usually through e-mail, to get you to reveal confidential account information. The most…
Intersting — and alarming — note on how phishers are getting more sophisticated. “Phishing” is an attempt, usually through e-mail, to get you to reveal confidential account information. The most common manifestation of this is an e-mail saying, “Hey, you need to update your account info at [fill in the name of the financial institution]. Click here.”
These sorts of attacks used to be (and, sometimes, still are) crude frauds, with typos and bad writing and all sorts of other tells that it wasn’t, in fact, Citibank trying to contact you. But the phishers are getting more sophisticated.
Phishing attacks have reached 57 million U.S. adults and have compromised at least 122 well-known brands so far, according to several estimates. At the end of 2004, nearly half of those attacks contained some sort of spyware or other malicious code, Trudeau said.
One attack, first documented last month by the Danish security firm Secunia, misdirects Web surfers by modifying a little-known directory in Microsoft Windows machines called a host file. When an Internet user types a Web address into a browser, he is directed instead to a fraudulent site. This technique has shown up in attacks spoofing several South American banks, said Scott Chasin, chief technology officer at MX Logic Inc., a security firm in Denver. The convergence of all of these threats means “we can expect to see some large attacks in the near term,” he said.
Another more ambitious attack targets the domain name servers that act as virtual telephone books, matching domain names with numerical addresses given to each computer on the Internet. If one of those computers is compromised, Internet users who type in www.bankofamerica.com, for example, could be directed to a look-alike site run by identity thieves.
Domain name servers are thought to be tougher to crack, but hackers can find a way in by posing as a company’s tech-support department and asking new employees for their passwords, Trudeau said. Domain-name hijacking is suspected in incidents involving Google Inc., Amazon.com Inc., eBay Germany and HSBC Bank of Brazil, Chasin said.
As a general rule, I ignore (in fact, flag as spam) any messages that come in with a subject line that indicates I have account info that needs updating. That’s because legitimate financial institutions and the like are well aware of this problem, and don’t use such messages.
If such a message does come in from an institution that I actually do business with, I’ll look at it. Anything that requires me to click through in the message to go to a web site, I consider to be a scam.
That all said, there’s not a lot that folks can do about DNS spoofing like the above passage mentions (any more than there’s much you can do about someone who works at a credit card company stealing your data). Just be vigilent, check your statements, and be careful before you click through on anything.