KB 295: Difference between revisions

From SWCP Support Wiki
Jump to navigationJump to search
New page: ===What is a phisher scam? How do I recognize one and avoid it?=== Article:295 Created:2004-07-02 15:54:05 Categories: E-mail Security ====Question or Symptom==== What is a phish...
 
 
Line 91: Line 91:
   http://update.mozilla.org/extensions/
   http://update.mozilla.org/extensions/
   http://www.ftc.gov/
   http://www.ftc.gov/
  http://story.news.yahoo.com/news?tmpl=story2&u=/zd/20040628/tc_zd/130396
  http://www.ftc.gov/bcp/conline/pubs/alerts/phishingalrt.htm

Latest revision as of 16:41, 4 June 2008

What is a phisher scam? How do I recognize one and avoid it?

Article:295
Created:2004-07-02 15:54:05
Categories:
  E-mail
  Security

Question or Symptom

What is a phisher scam? How do I recognize one and avoid it?


Resolution

A phisher scam is when someone tries to get you to give them important details about yourself (passwords, credit card numbers, ATM PINs) through some form of deception. They have been around for a long time, but have become a huge problem in 2004. They have become much more sophisticated and difficult to detect and avoid.

The typical phisher scam comes to you in email. You may receive a message which claims to be from Citibank, Ebay, Bank of America, Paypal, or some other financial institution. The message usually says you need to visit a web site to "verify your information", and provides a link. The link will appear in your browser with the name of the company they are pretending to be (Citibank, etc.) But "under the hood", the link actually leads to a machine controlled by the scammer.

If you click the link, you will see a web page which asks for various account information. The page will probably look just like the web site for the company they are spoofing. They will use the company logos and may even copy text from their pages to give it the appearance of authenticity.

But when you enter data on this page, it is not sent to your bank! Instead it is harvested by the criminal who sent you the email message. The perpetrator is rarely in the US, and the data is almost always sent to a computer outside the US. Once they have your information, they can go on a shopping spree with your credit card, or worse. If you have ever had a problem with identity theft, or known someone who has gone through it, you know that it can take months to get your credit rating restored and get your life back to normal.

These scams are usually shut down pretty quickly. But, since the perpetrators are not in the US, and are very good at hiding their trails, they are rarely caught and usually set up shop with a new phisher scam within a few hours. One web site provider reports that each phisher scam they find has reeled in thousands of credit card numbers in just a few hours. By the time it is shut down, all the damage is done. The only way to protect yourself is to avoid falling for the scam in the first place.


There are a few things you can do to protect yourself from these scams:

1. Don't follow links in email to give anyone personal information.  Citibank
  and Paypal will never send you an email saying that they lost your credit
  card number and need you to re-enter it.  If you do receive a message from
  your bank and think it might be legitimate, don't click on the link in
  email.  Instead, type the address of your bank in the location field of
  your browser to go to their web site.  If you don't know what it is, call
  them on the phone.  If they really did need to confirm anything with you,
  they can certainly do it on the phone.  Don't call a number listed in the
  email!  Look up the number in the phone book or on a recent statement.
 
2. Don't use Internet Explorer as your browser.  Steven J. Vaughan-Nichols
  says in a recent eWeek article, "Internet Explorer, like Outlook, has
  finally become, to my mind, a permanent security hole that masquerades as a
  useful application."  You can download Mozilla Firefox from
  http://www.mozilla.org/   Firefox is a very full-featured browser which has
  some useful utilities like pop-up blocking built right in.
 
3. Don't use HTML email.  Yes, it's nice to have email with color changes and
  different fonts, but it has become too dangerous.  Many Internet Explorer
  and Outlook security holes result from tricks that can be done in HTML to
  hide what's really going on.  When you use HTML email, you're allowing any
  stranger in the world to possibly use YOUR own computer against you!
 
4. If you use Firefox, there is a useful "extension" available which can help
  protect against spoofing.  It's called Spoofstick.  When installed it
  displays the name of the web site you are visiting in a separate bar below
  the location field.  If you click on a link that says "www.citibank.com"
  and SpoofStick says "You're on 207.199.66.12", you know something phishy is
  going on.  To install it, visit http://update.mozilla.org/extensions in
  Firefox, click the "Privacy" category link on the left, scroll down to
  SpoofStick and click the "Install" link.  It's automatic and fast.  Restart
  Firefox, and you should immediately see the "You're on ..." text.
 

If you want to report a phisher scam email, the Federal Trade Commission will take the complaint at www.ftc.gov (the "File a Complaint" link at the top of the page). Also see the FTC's Phishing Alert in the URL section below.

 http://www.mozilla.org/firefox/
 http://update.mozilla.org/extensions/
 http://www.ftc.gov/