KB 295
What is a phisher scam? How do I recognize one and avoid it?
Article:295 Created:2004-07-02 15:54:05 Categories: E-mail Security
Question or Symptom
What is a phisher scam? How do I recognize one and avoid it?
Resolution
A phisher scam is when someone tries to get you to give them important details about yourself (passwords, credit card numbers, ATM PINs) through some form of deception. They have been around for a long time, but have become a huge problem in 2004. They have become much more sophisticated and difficult to detect and avoid.
The typical phisher scam comes to you in email. You may receive a message which claims to be from Citibank, Ebay, Bank of America, Paypal, or some other financial institution. The message usually says you need to visit a web site to "verify your information", and provides a link. The link will appear in your browser with the name of the company they are pretending to be (Citibank, etc.) But "under the hood", the link actually leads to a machine controlled by the scammer.
If you click the link, you will see a web page which asks for various account information. The page will probably look just like the web site for the company they are spoofing. They will use the company logos and may even copy text from their pages to give it the appearance of authenticity.
But when you enter data on this page, it is not sent to your bank! Instead it is harvested by the criminal who sent you the email message. The perpetrator is rarely in the US, and the data is almost always sent to a computer outside the US. Once they have your information, they can go on a shopping spree with your credit card, or worse. If you have ever had a problem with identity theft, or known someone who has gone through it, you know that it can take months to get your credit rating restored and get your life back to normal.
These scams are usually shut down pretty quickly. But, since the perpetrators are not in the US, and are very good at hiding their trails, they are rarely caught and usually set up shop with a new phisher scam within a few hours. One web site provider reports that each phisher scam they find has reeled in thousands of credit card numbers in just a few hours. By the time it is shut down, all the damage is done. The only way to protect yourself is to avoid falling for the scam in the first place.
There are a few things you can do to protect yourself from these scams:
1. Don't follow links in email to give anyone personal information. Citibank and Paypal will never send you an email saying that they lost your credit card number and need you to re-enter it. If you do receive a message from your bank and think it might be legitimate, don't click on the link in email. Instead, type the address of your bank in the location field of your browser to go to their web site. If you don't know what it is, call them on the phone. If they really did need to confirm anything with you, they can certainly do it on the phone. Don't call a number listed in the email! Look up the number in the phone book or on a recent statement. 2. Don't use Internet Explorer as your browser. Steven J. Vaughan-Nichols says in a recent eWeek article, "Internet Explorer, like Outlook, has finally become, to my mind, a permanent security hole that masquerades as a useful application." You can download Mozilla Firefox from http://www.mozilla.org/ Firefox is a very full-featured browser which has some useful utilities like pop-up blocking built right in. 3. Don't use HTML email. Yes, it's nice to have email with color changes and different fonts, but it has become too dangerous. Many Internet Explorer and Outlook security holes result from tricks that can be done in HTML to hide what's really going on. When you use HTML email, you're allowing any stranger in the world to possibly use YOUR own computer against you! 4. If you use Firefox, there is a useful "extension" available which can help protect against spoofing. It's called Spoofstick. When installed it displays the name of the web site you are visiting in a separate bar below the location field. If you click on a link that says "www.citibank.com" and SpoofStick says "You're on 207.199.66.12", you know something phishy is going on. To install it, visit http://update.mozilla.org/extensions in Firefox, click the "Privacy" category link on the left, scroll down to SpoofStick and click the "Install" link. It's automatic and fast. Restart Firefox, and you should immediately see the "You're on ..." text.
If you want to report a phisher scam email, the Federal Trade Commission will take the complaint at www.ftc.gov (the "File a Complaint" link at the top of the page). Also see the FTC's Phishing Alert in the URL section below.
Related URLS
http://www.mozilla.org/firefox/ http://update.mozilla.org/extensions/ http://www.ftc.gov/ http://story.news.yahoo.com/news?tmpl=story2&u=/zd/20040628/tc_zd/130396 http://www.ftc.gov/bcp/conline/pubs/alerts/phishingalrt.htm