Bank phishing fraudsters learn to spell

By Steve Ranger, Special to ZDNet Asia
Friday, April 24, 2009 10:48 AM

Phishers aiming to defraud banks have raised their game--and at the very least have learned to spell--according to the banking executives tasked with stopping them.

According to David Shroyer, Bank of America senior vice president of online security and enrollment, the attacks fraudsters are targeting at financial services organizations are continuing to develop. For example, fraudsters are now building phishing sites with malware embedded in them which means the unwary risk not only losing their bank details but also getting malware on their PCs if they are tricked into visiting such sites.

"People are still clicking on the links to see if they are real and those who aren't adequately protected are getting infected," he told a session at the RSA Conference in San Francisco.

"We've educated our customers as an industry but the fraudsters aren't standing still," he added.

The fraudsters have fixed some of their basic problems too.

"The bad guys have invested in a spell checker," he joked, a reference to the poorly spelt and designed phishing e-mails and Web sites which characterized phishing attempts a few years ago.

But as the fraudsters increase the sophistication of their attacks, educating customers becomes more difficult. "Now we are talking about a much harder topic, about customer protection on the PC and safe browsing habits and that's a hard message to convey," said Shroyer.

One response from the banks is that, upon finding a phishing site, instead of shutting it down they replace it with a warning explaining phishing. As a result, any customers that do click on the link in a phishing e-mail are alerted to the scam, rather than simply finding a broken link.

"We have an opportunity to educate customers, at that point we can say 'you got phished and this is how to prevent it in the future'," Shroyer said.

According to Stan Szwalbenest, remote channel risk director consumer risk management at JP Morgan Chase, there is an easy way to avoid most of the problems: "We have a simple message: have all the patches in place and antivirus up to date."

"Fraud is a loss to the bank but the impact on the customer is much greater and protecting the customer protects our brand," he added.

According to a report by analyst house Gartner, the average cost of a phishing attack to the US financial services industry was US$351 last year--a drop of 60 percent on the year before.

Steve Ranger of Silicon.com reported from London.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Configure Apache to support multiple SSL sites on a single IP address

Open Source

With Apache 2.2.12 and support for the Server Name Indication extension to the SSL protocol, you can configure name-based HTTPS sites, just as you can name-based HTTP sites.


Read more »



Amendments to empower Copyright Tribunal

Blog thumbnail

As a lawyer, I often inform my clients about the need to clear licenses with the various licensing societies whenever they use works belonging to other parties. This is especially..... by Bryan Tan

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web