Phishers' creative ways reap bounty

By Vivian Yeo, ZDNet Asia
Monday, October 02, 2006 04:24 PM

Phishers are resorting to various new tricks to harvest confidential, personal information from unsuspecting or careless users.

According to Symantec's latest Internet Security Threat Report, 157,477 unique phishing messages were identified in the first six months of 2006, representing an 81-percent jump over the second half of 2005 where over 86,900 messages were reported. Some 97,592 unique messages were recorded in the first half of 2005.

The biannual report also indicated that 1.3 billion phishing attempts were blocked in the first half of this year, down from 1.46 billion between July and December last year.

Similarly, the Anti-Phishing Work Group (APWG) reported that it detected 14,191 unique phishing Web sites in July. No figures are available yet for August or September.

In its most recent report, the APWG also noted that the number of unique phishing messages in July were the highest ever reported by the group. During that month, a total of 23,670 phishing reports were registered.

Yeong Chee Wai, Symantec's manager for pre-sales consulting, explained that the increase was driven by phishers who now create multiple messages with slight variances in order to bypass basic e-mail scanning programs.

"The bad guys are spending more time making their messages look like the real thing… They are becoming more discreet, and they are becoming more creative," Yeong said, during a media briefing in Singapore last week.

The security vendor reported that the financial services sector was the most heavily spoofed, where 84 percent of phishing sites masqueraded as financial services brands. About 8 percent of phishing sites targeted Internet service providers, while 5 percent were linked to the retail sector.

According to Symantec, "misleading applications" also accounted for 50 percent of total reports on the top 10 new security risks in the first half of 2006. Misleading applications use social engineering techniques to trick people into purchasing fake security software, through false or exaggerated reports that claim to have identified security threats on the victims' operating systems.

Yeong warned that such tactics are dangerous as the user's personal information such as credit card details, can be phished when he attempts to make the purchase. Not knowing that the transactions are fake, the user could also develop a false sense of protection from security threats, making him vulnerable to future attacks.

In Symantec's latest report, three of the top 10 new security risks found between January and June 2006 were labeled as "misleading applications".


WORTHWHILE?

0

0 votes
Blog

Talkback 1 comments

Phishers are getting more and more sophisticated in their attempts to get into your pocket-book. As their emails become indistinguishable from the real-deal from your bank, eBay or favourite department store -- we as a consuming public have to be more aware of these issues www.essentialsecurity.com...

Most places now have places to report your phising concerns - like these listed on the TechKnowBizzle: www.techknowbizzle.com...
Posted by Marilee Veniegas, Essential Security Software on Tuesday, October 03 2006 03:34 AM


Tech Jobs Now!

Search for your ideal tech job:

10 open source projects worth checking out

Open Source

The open source field is pretty crowded, but certain projects stand above the rest. Here are 10 tools and solutions you don't want to overlook.


Read more »



Will technology divide us further?

Blog thumbnail

So I finally watched 2012 over the weekend, but the film left me feeling extremely agitated.

The possibility that the world may meet its watery end in three years didn't..... by Eileen Yu

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web