CompUSA
Showing posts with label email. Show all posts
Showing posts with label email. Show all posts

Monday, February 14, 2011

Internet Crime Complaint Center's (IC3) Scam Alerts

This report, which is based upon information from law enforcement and complaints
submitted to the IC3, details recent cyber crime trends and new twists to previously-existing
cyber scams.

Social Network Misspelling Scam

During December 2010, the IC3 discovered misspellings of a social network site being
used as a social engineering ploy. Misspelling the domain name of this site would
redirect users to websites coded to look similar to the actual website. The website
users were redirected to answer three or four simple survey questions. Upon answering
those questions, users were offered a choice of three free gifts. Multiple brands
were observed as being offered as gifts, including gift cards to retail stores and
various brands of laptops.

After clicking on one of the gifts, users were further redirected to other websites
claiming to give free gifts for completing surveys. The surveys typically asked
for name, address, phone number, and e-mail address. A user could spend hours filling
out multiple surveys and never receive any of the gifts advertised.

Fake Online Receipt Generator Targets Unsuspecting Online Marketplace Merchant

A new scam aims to swindle online marketplace sellers by generating fake receipts.
This Receipt Generator is an executable file that has been circulating on hacking
forums recently. This is a particularly interesting scam - because it does not target
regular PC users, it targets the sellers on online marketplace websites. This is
what the would-be social engineer sees when running the program:



The social engineer can fill in a variety of information, including item name, price,
and the date the order was taken. Additionally, it allows them to choose between
the .com, .co.uk, .fr, and .ca marketplace portals. When they hit "Generate," an
HTML file is created in the program folder which looks like this:




The program produces what appears to be a genuine marketplace receipt and a copy
of the "Printable Order Summary," similar to the documents resulting from legitimate
marketplace purchases. Note the small details, such as "Total before tax," "Sales
tax," and other particulars that make the receipt convincing.

Many sellers on these markets will ask the buyer to send them a copy of the receipt
should the buyer run into trouble, have orders go missing, lose the license key
for a piece of software, and so on. The scammer relies on the seller to accept the
printout at face value without checking the details. After all, how many sellers
would be aware someone went to the trouble of creating a fake receipt generator?

Sellers must remain ever vigilant about this scam, which has been a popular topic
in recent hacker forums. The VirusTotal detection rate is currently 1/43 – detected as Hacktool.Win32.Amagen.A.

Malicious Code In .gov E-mail

A recent malware campaign, disguised as a holiday greeting from the White House,
targeted government employees. The recipient received the below e-mail with links
to what masqueraded as a greeting card, but when they clicked on the link, it attempted
to download a file named "card.exe." The executable program proved to be an information-stealing
Trojan, which would disable the recipient’s computer security notifications, software
updates, and firewall settings. The malware also installed itself into the computer’s
registry, enabling the code to be executed every time the computer was rebooted.
At the time of review, this particular malicious code sample had a low antivirus
detection rate of 20%, with only 9 out of 43 antivirus companies reporting detection.

From: sender@whitehouse.gov [mailto: sender@whitehouse.gov]
Sent: Wednesday, December 22, 2010 10:33 PM
To: recipient's name
Subject: Merry Christmas, recipient's name

Recipient’s name here,
    
    As you and your families gather to celebrate the holidays, we wanted to take a moment
    to send you our greetings. Be sure that we're profoundly grateful for your dedication
    to duty and wish you inspiration and success in fulfillment of our core mission.
    
    Greeting card:
    
     hxxp://xtremedefenceforce.com/card/
     hxxp://elvis.com.au/card/
    
    
    Merry Christmas!
    
    ___________________________________________

 Executive Office of the President of the United States
The White House
1600 Pennsylvania Avenue NW
Washington, DC 20500





    
 Source: FBI, February 2011   


 -----
Community News You Can Use
Click to read MORE news:
www.GeorgiaFrontPage.com
Twitter: @gafrontpage & @TheGATable @HookedonHistory
www.ArtsAcrossGeorgia.com
Twitter: @artsacrossga, @softnblue, @RimbomboAAG @FayetteFP

Thursday, October 7, 2010

Fake iTunes Bill Can Drain Your Bank Account

The following article is from Eastman's Online Genealogy Newsletter and is copyright by Richard W. Eastman. It is re-published here with the permission of the author. Information about the newsletter is available at http://www.eogn.com. 


I received one of these email messages a few days ago. Luckily, Gmail placed it in my spam folder so I didn't see it until today when I went looking for it. You have to hand it to these scam artists: they certainly are clever at devising methods of stealing your money.

I wrote a couple of days ago at http://goo.gl/nvl9 about a "trojan" email message that steals your user IDs and passwords to your online banking account. This new scam is a different Trojan message with a very clever delivery method.


The new scam sends a fake "iTunes receipt" email message to millions of people. The message appears to be completely authentic, except for the price shown in your bill. The message I received was for nearly $1,000. That's part of the trap.

Most people are likely to take action when seeing an "incorrect amount" appear on their bill. (I didn't do that because I never saw the "bill" in my spam folder until I went looking for it later, after reading about the new scam.)  Most people will click on the "report a problem" link that is included in the email message. However, that link takes you to a rogue web page that downloads the same Zeus trojan malware as described in the earlier article to your Windows computer. (Linux and Macintosh computers will not be affected.)

The program then waits for the user to log onto a list of targeted banks and financial institutions, and then steals login credentials and other data which are immediately sent to a remote server hosted by cybercriminals. It can also modify, in a user’s browser, the genuine web pages from a bank’s web servers to ask for personal information such as payment card number and PIN, one time passwords, etc.

Panda Labs released a statement explaining the infection process:
"After clicking the link, the victim is asked to download a fake PDF reader. Once installation is complete, the user is redirected to an infected web page containing the Zeus Trojan, which is specifically designed to steal personal data."
Here is the full announcement from Panda Labs:
Massive Phishing Attack Uses iTunes as Lure to Steal Bank Details, Reports PandaLabs

ORLANDO, Fla., Oct. 4 -- PandaLabs, Panda Security's antimalware laboratory, has discovered that Apple's popular iTunes platform has become a major target for hackers looking to steal credit card data from the service's millions of users. 

Victims receive a cleverly-crafted email informing them that they have made an expensive purchase on iTunes. The user, having never made the purchase to begin with, is concerned by the email and naturally tries to resolve the problem – in this case by clicking on the proffered (fake) link. An example of this fraudulent iTunes receipt can be seen here:  http://www.flickr.com/photos/panda_security/5050360091/

After clicking the link, the victim is asked to download a fake PDF reader. Once installation is complete, the user is redirected to an infected Web page containing the Zeus Trojan, which is specifically designed to steal personal data. This phishing attack was uncovered shortly after a similar phishing attack targeting LinkedIn users appeared last week, which appears to have originated in Russia.

"Phishing is nothing new," said Luis Corrons, Technical Director of PandaLabs. "What never ceases to surprise us is that the techniques used to trick victims continue to be so simple, but the design and content is so very well-orchestrated. It's very easy to fall into the trap. When using services such as iTunes, it is absolutely crucial that users never go to the website via email, but rather from the platform itself where they can verify their account status." 

This technique has been reported to the Anti-Phishing Working Group, which has started to block some of the Web addresses linked to in the fake email. 

PandaLabs advises all users to be wary of any emails related to iTunes, regardless of how genuine they seem. Users who think they may have been affected are urged to scan their computers thoroughly to locate and remove any possible active threats. [Windows] Users who do not have an antivirus installed can use Panda Cloud Antivirus, a free security service available at www.cloudantivirus.com.

More information is available in the PandaLabs Blog.

About PandaLabs

Since 1990, its mission has been to detect and eliminate new threats as rapidly as possible to offer our clients maximum security. To do so, PandaLabs has an innovative automated system that analyzes and classifies thousands of new samples a day and returns automatic verdicts (malware or goodware). This system is the basis of collective intelligence, Panda Security's new security model which can even detect malware that has evaded other security solutions.

Currently, 99.4 percent of malware detected by PandaLabs is analyzed through this system of collective intelligence. This is complemented through the work of several teams, each specialized in a specific type of malware (viruses, worms, Trojans, spyware, phishing, spam, etc.), who work 24/7 to provide global coverage. This translates into more secure, simpler and more resource-friendly solutions for clients.

More information is available in the PandaLabs blog: http://www.pandalabs.com.



-----
Community News You Can Use
Click to read MORE news:
www.GeorgiaFrontPage.com
Twitter: @gafrontpage & @TheGATable @HookedonHistory
www.ArtsAcrossGeorgia.com
Twitter: @artsacrossga, @softnblue, @RimbomboAAG
www.FayetteFrontPage.com
Twitter: @FayetteFP

Sunday, July 4, 2010

Evaluate Appeals for Help from Friends Traveling Abroad with Caution

The Internet Crime Complaint Center continues to receive reports of individuals’ e-mail or social networking accounts being compromised and used in a social engineering scam to swindle consumers out of thousands of dollars.

Here’s how it works: Hackers infiltrate your social networking page, claim to be you, and write your contacts/friends. They portray themselves as “victims” who were robbed while traveling abroad and state they need money immediately because they don’t have a passport, money, credit cards, or cell phone and are stranded.

Some claim they only have a few days to pay their hotel bill and promise to reimburse costs upon their return home. Recipients may be tempted to respond to these appeals because they appear to be from a friend and there’s a sense of urgency to help.

If you receive a similar notice and aren’t sure if it is a scam, you should always verify the information before sending any money. If you have been a victim of this type of scam or any other cyber crime, report it to the IC3 website at www.IC3.gov.

The IC3’s database links complaints for potential referral to the appropriate law enforcement agency for case consideration. Complaint information is also used to identity emerging trends and patterns.

-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter:  @GAFrontPage

Wednesday, May 12, 2010

Remington Financial Group Chairman Issues 'Email Fraud Warning,' Alerts FBI

/PRNewswire/ -- Chairman and founder of Remington Financial Group, Andy Bogdanoff, has alerted the FBI and other law enforcement agencies that an email scam is falsely using Remington's name to gain private information that may be used in identity theft.

In making the announcement, Bogdanoff emphasized that none of Remington's customer data had been breached by what appears to be a 'copycat email' scam similar to those that attempted to victimize bank and credit card customers in the past.

Remington is a national financial services company, specializing in providing commercial real estate owners and developers with access to needed capital. Since 1993, Remington has arranged more than $5 billion in financing for all types of commercial property.

Remington uncovered the "phishing" scheme through routine monitoring of the Internet for potential fraud activity. "In keeping with Remington's fraud policy," Bogdanoff said, "we referred the data we collected to the appropriate law enforcement agencies, including the Federal Bureau of Investigation and appropriate state and local authorities."

Earlier in the year, Remington implemented what is believed to be the most comprehensive and stringent fraud policy in the financial services industry. At the time, Bogdanoff called on others in the industry to "shore up" their fraud policies and to rectify any deficiencies. "By doing so," Bogdanoff said, "the financial services industry can help regain public confidence and trust, which has been sorely tested by recent scandals."

The Remington Financial Group Fraud Policy includes strict monitoring controls and rigorous due diligence procedures designed to protect the integrity of the company and the interests of every person and entity involved in Remington activities.

"My hope is that Remington's Fraud Policy will become the 'gold standard' throughout the industry," Bogdanoff said. "At Remington, our goal is clear: To be super-vigilant against even the hint of fraudulent or other inappropriate activity by any employee, customer or lender associated with Remington. Any such behavior will not be tolerated. And any violation of this policy will be met with swift and appropriate disciplinary or legal action," Bogdanoff said.

-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter:  @GAFrontPage

Friday, March 12, 2010

National Center for Disaster Fraud to Coordinate Haitian and Chilean Fraud Complaints

Shortly after the earthquake in Haiti last January, the FBI and the National Center for Disaster Fraud (NCDF) established a telephone hotline to report suspected fraud associated with relief efforts. That number, (866) 720-5721, was initially staffed for the purpose of reporting suspected scams being perpetrated by criminals in the aftermath of the Haitian earthquake.

Since then with the recent earthquake in Chile our efforts have expanded to identify similar fraud activity coming out of that disaster. Therefore the public is encouraged to call this same number (866) 720-5721 to report suspected fraud from either disaster. The telephone line is staffed by a live operator 24 hours a day, seven days a week. Additionally, e-mail information can be directly sent to disaster@leo.gov.

The National Center for Disaster Fraud was originally established by the Department of Justice to investigate, prosecute, and deter fraud in the wake of Hurricane Katrina, when billions of dollars in federal disaster relief poured into the Gulf Coast Region. Now, its mission has expanded to include suspected fraud from any natural or manmade disaster. More than 20 federal agencies, including the
FBI, participate in the NCDF, allowing the center to act as a centralized clearinghouse of information related to Haitian or Chilean Relief Fraud.

The FBI continues to remind the public to apply a critical eye and do their due diligence before giving contributions to anyone soliciting donations on behalf of Haitian or Chilean victims. Solicitations can originate from e-mails, websites, door-to-door collections, mailings and telephone calls, and similar methods.

Therefore, before making a donation of any kind, consumers should adhere to certain guidelines, including the following:

* Do not respond to unsolicited (spam) incoming e-mails, including clicking links
contained within those messages because they may contain computer viruses.
* Be skeptical of individuals representing themselves as surviving victims or officials
asking for donations via e-mail or social networking sites.
* Beware of organizations with copy-cat names similar to but not exactly the same
as those of reputable charities.
* Rather than following a purported link to a website, verify the legitimacy of non-profit
organizations by utilizing various Internet-based resources that may assist in confirming
the group's existence and its non-profit status.
* Be cautious of e-mails that claim to show pictures of the disaster areas in attached
files because the files may contain viruses. Only open attachments from known senders.
* To ensure contributions are received and used for intended purposes, make contributions
directly to known organizations rather than relying on others to make the donation
on your behalf.
* Do not be pressured into making contributions, as reputable charities do not use
such tactics.
* Do not give your personal or financial information to anyone who solicits contributions.
Providing such information may compromise your identity and make you vulnerable
to identity theft.
* Avoid cash donations if possible. Pay by debit or credit card, or write a check
directly to the charity. Do not make checks payable to individuals.
* Legitimate charities do not normally solicit donations via money transfer services.
* Most legitimate charities websites end in .org rather than .com.
* There are scams targeting Haitian immigrants and their families offering assistance
in getting family members and friends out of Haiti. These individuals charge a fee
and then claim they will provide the necessary immigration paperwork or an airline
ticket for disaster victims to leave Haiti. For official information pertaining
to immigration from Haiti to the U.S., visit the U.S. Citizenship and Immigration
Services (USCIS) website at www.USCIS.gov.

If you believe you have been a victim of fraud from someone or an organization soliciting
relief on behalf of Haitian or Chilean earthquake victims, contact the National Center for Disaster Fraud at (866) 720-5721. You can also fax information to fax (225) 334-4707 or e-mail it to disaster@leo.gov.

You can also report suspicious e-mail solicitations or fraudulent websites to the FBI's Internet Crime Complaint Center at www.ic3.gov.

------
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter:  @GAFrontPage

Wednesday, November 18, 2009

Spear Phishing E-mails Target U.S. Law Firms and Public Relations Firms

The FBI assesses with high confidence that hackers are using spear phishing e-mails with malicious payloads to exploit U.S. law firms and public relations firms. During the course of ongoing investigations, the FBI identified noticeable increases in computer exploitation attempts against these entities.

The specific intrusion vector used against the firms is a spear phishing or targeted socially engineered e-mail designed to compromise a network by bypassing technological network defenses and exploiting the person at the keyboard. Hackers exploit the ability of end users to launch the malicious payloads from within the network by attaching a file to the message or including a link to the domain housing the file and enticing users to click the attachment or link.

Network defense against these attacks is difficult as the subject lines are spoofed, or crafted, in such a way to uniquely engage recipients with content appropriate to their specific business interests. In addition to appearing to originate from a trusted source based on the relevance of the subject line, the attachment name and message body are also crafted to associate with the same specific business interests. Opening a message will not directly compromise the system or network because the malicious payload lies in the attachment or linked domain. Infection occurs once someone opens the attachment or clicks the link, which launches a self-executing file and, through a variety of malicious processes, attempts to download another file.

Indicators are unreliable to flag in-bound messages; however, indicators are available to determine an existing compromise. Once executed, the malicious payload will attempt to download and execute the file ‘srhost.exe’ from the domain ‘http://d.ueopen.com’; e.g. http://d.ueopen.com/srhost.exe. Any traffic associated with ‘ueopen.com’ should be considered as an indication of an existing network compromise and addressed appropriately.

The malicious file does not necessarily appear as an ‘exe’ file in each incident. On occasion, the self-executing file has appeared as other file types, e.g., ‘.zip’, ‘.jpeg’, etc.

Please contact your local field office if you experience this network activity and direct incident response notifications to DHS and U.S. CERT.

-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page

Tuesday, November 3, 2009

Fraudulent Automated Clearing House (ACH) Transfers Connected To Malware And Work-At-Home Scams

Within the last several months, the FBI has seen a significant increase in fraud involving the exploitation of valid online banking credentials belonging to small and medium businesses, municipal governments, and school districts. In a typical scenario, the targeted
entity receives a "spear phishing" email which either contains an infected attachment, or directs the recipient to an infected web site. Once the recipient opens the attachment or visits the web site, malware is installed on their computer. The malware contains a key logger which will harvest the recipients business or corporate bank account log-in information. Shortly thereafter, the perpetrator either creates another user account with the stolen log-in information, or directly initiates funds transfers by masquerading as the legitimate user. These transfers have occurred as both traditional wire transfers and as ACH transfers.

Further reporting has shown that the transfers are directed to the bank accounts of willing or unwitting individuals within the United States. Most of these individuals have been recruited via work-at-home advertisements, or have been contacted after placing resumes on well-known job search web sites. These persons are often hired to "process payments", or "transfer funds". They are told they will receive wire transfers into their bank accounts. Shortly after funds are received, they are directed to immediately forward most of the money overseas via wire transfer services such as Western Union and Moneygram.

Customers who use online banking services are advised to contact their financial institution to ensure they are employing all the appropriate security and fraud prevention services their institution offers.

The United States Computer Emergency Readiness Team (US-CERT) has made information on banking securely online available at
http://www.us-cert.gov/reading_room/Banking_Securely_Online07102006.pdf.

Protecting your computer against malicious software is an ongoing activity and, at minimum, all computer systems need to be regularly patched, have up to date anti-virus software, and a personal firewall installed. Further information is available at
http://www.us-cert.gov/nav/nt01/.

If you have experienced unauthorized funds transfers from your bank accounts, or if you have been recruited via a work-at-home opportunity to receive transfers and forward money overseas, please notify the IC3 by filing a complaint at www.IC3.gov.

-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
www.artsacrossgeorgia.com
Arts Across Georgia

Monday, October 5, 2009

Fraudulent e-mail claiming to contain an FBI Intelligence Bulletin from the Weapons of Mass Destruction Directorate

A fraudulent e-mail, initially appearing around June 16, 2009, claims to contain a confidential FBI report from the FBI "Weapons of Mass Destruction Directorate." The subject line of the email is "RE: Weapons of Mass Destruction Directorate," and contains an attachment "reports.exe". This message and similar messages may contain a file related to the "W32.Waledac" trojan software, which is designed to steal user authentication credentials or send spam messages.

Do not click on any links associated with this e-mail or similar e-mails, it is a hoax.

The FBI does not send unsolicited e-mails or e-mail official reports. Consumers should not respond to any unsolicited e-mails or click on any embedded links, as they may contain viruses or malicious software.

Below is an example of the fraudulent e-mail message:

CLASSIFIED
FEDERAL BUREAU OF INVESTIGATION
INTELLIGENCE BULLETIN

Weapons of Mass Destruction Directorate

HANDLING NOTICE: Recipients are reminded that FBI Intelligence Bulletins contain sensitive terrorism and counterterrorism information meant for use primarily within the law enforcement and homeland security communities. Such bulletins shall not be released, either in written or oral form, to the media, the general public, or other personnel who do not have a valid need-to-know without prior approval from an authorized FBI official, as such release could jeopardize national security.

Link to malicious software (report.exe)


If you have been a victim of Internet crime, please file a complaint at www.IC3.gov.

-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page

Thursday, April 30, 2009

Is Your Computer Safe From the Swine Flu?

There have been numerous reports of scam artists attacking computers using the swine flu as bait. Below is the story released yesterday by the Consumer Affairs on the subject.


Watch Out For Swine Flu Scams
Con artists quick to exploit new situation
April 29, 2009

It didn’t take scammers long to latch on to the latest hot button topic to try and make a quick buck. Scams built around fears of swine flu are proliferating quickly across the Internet.

The U.S. Computer Emergency Readiness Team issued an alert this week, warning.....http://www.consumeraffairs.com/news04/2009/04/swineflu09.html

-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Twitter @GAFrontPage

Monday, April 27, 2009

Circulation of Fraudulent E-mail Claiming To Be From U.S. Customs and Border Protection (CBP)

A spam e-mail claiming to be from former CBP Assistant Commissioner, Thomas S. Winkowski, is currently being circulated. This attempt to defraud is the typical e-mail scam using the name and reputation of a federal government official to create an air of authenticity.

The spam e-mail indicates the CBP has stopped a Diplomat who is carrying a consignment
to be delivered to the recipient's residence. This consignment allegedly contains millions of dollars, which is revealed to be an inheritance for the e-mail recipient.

As with many other scams, this e-mail advises the recipient they will be permitted to access this inheritance once the recipient has given the sender of the e-mail their personal information.

This e-mail is a hoax. Do not respond.

The U.S. CBP does not send unsolicited e-mails. Consumers should not respond to unsolicited e-mails or click on any embedded links, as they may contain viruses or malware.

It is imperative consumers guard their personally identifiable information (PII). Examples of a person's PII include, but are not limited to: date of birth; social security number; and
bank account numbers. Providing your PII will compromise your identity.

If you have received this e-mail, or a similar e-mail, please file a complaint at www.IC3.gov.

-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage

Thursday, October 16, 2008

Fraudulent Spam E-mail Purported From FBI Deputy Director John S. Pistole

A spam e-mail claiming to be from FBI Deputy Director John S. Pistole is currently being circulated. This attempt to defraud is the typical e-mail scam using the name and reputation
of an FBI official to create an air of authenticity.

As with many scams, the e-mail advises the recipient that they are the beneficiary of a large sum of money which they will be permitted to access once fees are paid and personal banking information is provided. The appearance of the e-mail leads the reader to believe that it is from FBI Deputy Director John S. Pistole.

This e-mail is a hoax. Do not respond.

The IC3 continues to receive and develop intelligence regarding fraud schemes misrepresenting
the FBI and/or FBI officials. The scam e-mails give the appearance of legitimacy through the use of pictures of FBI officials, seal, letter head, and/or banners.

These fraud schemes claim to be from domestic as well as international FBI offices. The typical types of schemes utilizing the names of FBI officials and/or the FBI are lottery endorsements and inheritance notifications but can cover a range of scams from threats and malicious computer program attachments (malware) to online auction scams.

These scams use the social engineering technique of employing the FBI's name to intimidate and convince the recipient the e-mail is legitimate.

Please be cautious of any unsolicited e-mail referencing the FBI, Director Mueller, Deputy Director Pistole or any other FBI official claiming that the FBI is endorsing any type of Internet activity.

Always be cautious when responding to requests or special offers delivered through
unsolicited e-mail:

* Guard your personal information as well as your account information carefully.
* You should never give any personal, credit, or banking information in response to
unsolicited e-mails.

Consumers always need to be alert to unsolicited e-mails. Do not open unsolicited e-mails or click on any embedded links, as they may contain viruses or malware. Providing your PII will compromise your identity!

If you have received this e-mail, or a similar e-mail, please file a complaint at www.IC3.gov.

-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page

Teaching Consumers On-Line Safety Easiest When They Take the Bait

(BUSINESS WIRE)--The Anti-Phishing Working Group (APWG) and Carnegie Mellon University’s Supporting Trust Decisions Project have established a phishing page redirect initiative that protects global online consumers who have been tricked into clicking links in scam emails by delivering them to Web pages that instruct them on the dangers of phishing – and how to avoid them. The program was announced today at the APWG conference in Atlanta.

The AWPG/Carnegie Mellon Phishing Education Landing Page program builds on the philosophy of using the “teachable moment” to warn users immediately after they’ve fallen for a phishing lure and then give them on-line safety instruction precisely at a time when they are receptive to it. Phishing sites are designed to resemble Web sites of legitimate businesses, such as banks and online retailers, to trick people into revealing credit card numbers, bank accounts or login names and passwords. Actionable messaging will help consumers to avoid falling victim to these scams a second time.

“We are excited about the opportunity to educate consumers as they are falling victim to a phishing site,” said Dr. Laura Mather, Managing Director of Operational Policy for the APWG and CEO of Silver Tail Systems. “We see this initiative as having real impact in helping people understand when they have received a phishing communication so that they can protect themselves going forward.”

This education-at-time-of-action is accomplished by leveraging the URLs of the phishing sites themselves after anti-phishing investigators have identified the sites and shut them down. Instead of leaving the URL file blank, returning a ‘PAGE NOT FOUND’ message to consumers following phishing links, they will be served a page of instruction on how to avoid phishing and reduce the risk of falling victim to electronic crime. (Redirect scripts placed at the sanitized phishing URL will automatically forward the advisory content.)

“Our research has shown that most Internet users don’t know very much about online scams and don’t realize that there are some simple things they can do to protect themselves,” said Dr. Lorrie Cranor, an associate professor of computer science and engineering & public policy at Carnegie Mellon and director of the Supporting Trust Decisions Project.

Ponnurangam Kumaraguru, a computer science Ph.D. student who is leading the effort to design and evaluate anti-phishing training materials at Carnegie Mellon added, “Nobody wants to spend their time taking on-line safety courses. But we’ve demonstrated that users are receptive to on-line safety instruction immediately after they fall for a phishing attack and they tend to remember this instruction."

The phishing education landing page developed by APWG and Carnegie Mellon teaches would-be victims not to give out personal information upon email request and to use a skeptical eye in judging online communications.

The implementation of the program depends on the participation of both takedown service providers and the ISPs and other companies whose servers have been co-opted to host phishing sites. The APWG is already successfully recruiting companies that perform phishing site takedowns, victimized brandholders and trade associations to encourage ISPs and other organizations that remove phish sites to use the APWG’s education landing page program.

The program is based on a similar program initiated by Bank of America in 2007. The APWG/Carnegie Mellon program builds on Bank of America’s ideas by creating a page that can be used for phishing site against any brand. Bank of America has already implemented the APWG/Carnegie Mellon program.

“Bank of America is committed to providing its customers with industry leading security tools and advice to protect them and enhance their overall customer experience. Educating our customers about the risks of identity theft and fraud is critical,” says David Shroyer, SVP for eCommerce Online Security at Bank of America.

"We know from experience that an educated customer is the best defense against fraud, and with this program we are educating our customers at the point of incidence, and letting customers know that we are working to protect them,” Mr. Shroyer said.

The APWG/Carnegie Mellon scheme will augment the usual procedure for communicating to the hosting organization about phishing sites. Instead of asking that the site be disabled and file content associated with the phishing URL removed, the takedown provider or victimized brandholder would request that the URL be preserved and a redirect script send the duped user to a webpage hosted by the APWG.

The education landing page will automatically determine whether the user is using a PC or laptop or handheld device and vend the device-appropriate page. Users of PDAs and Web-enabled cell phones will receive a page exclusively of text. People using PCs and laptops will receive an enhanced page of text, graphics and a number of links to online resources.

The APWG/Carnegie Mellon scheme will augment the usual procedure for communicating to the hosting organization about phishing sites. Instead of asking that the site be disabled and file content associated with the phishing URL removed, the takedown provider or victimized brandholder would request that the URL be preserved and a redirect script send the duped user to a webpage hosted by the APWG.

The APWG page will automatically determine whether the user is using a PC or laptop or handheld device and vend the device-appropriate page. Users of PDAs and Web-enabled cell phones will receive a page exclusively of text. People using PCs and laptops will receive an enhanced page of text, graphics and a number of links to online resources.

“This initiative gives takedown teams, ISPs, registrars, and registries the opportunity to take one more step in protecting consumers against identity theft and the other crimes perpetrated by Phishers,” said Dr. Mather.

As a next step, the APWG will organize the translation of the pages into various languages to serve the larger international community of consumers, brandholders and ISPs who are confronting the threats of electronic crime and engaging questions of efficacious consumer education.

Links:

Redirect education page: http://education.apwg.org/r/en/

Text only redirect education page: http://education.apwg.org/r/index.html

About the redirect education page initiative: http://education.apwg.org/r/about.html

About the APWG: The APWG is an industry, founded as the Anti-Phishing Working Group in 2003, is an industry, law enforcement and government coalition focused on eliminating the identity theft and fraud that result from the growing problem of phishing, email spoofing, and crimeware. Membership is open to qualified financial institutions, online retailers, ISPs, the law enforcement community and solutions providers. There are more than 1,800 companies and government agencies worldwide participating in the APWG and more than 3,200 members. The APWG's Web site (www.antiphishing.org) offers the public and industry information about phishing and email fraud, including identification and promotion of pragmatic technical solutions that provide immediate protection. APWG's corporate sponsors include: 8e6 Technologies, AT&T (T), Able NV, Afilias Ltd., AhnLab, BillMeLater, BBN Technologies, BlueStreak, BrandMail, BrandProtect, Bsecure Technologies, Cisco (CSCO), Clear Search, Cloudmark, Cydelity, Cyveillance, DigiCert, DigitalEnvoy, DigitalResolve, Digital River, Earthlink (ELNK), eBay/PayPal (EBAY), Entrust (ENTU), Experian, eEye, Fortinet, FraudWatch International, FrontPorch, F-Secure, Goodmail Systems, Grisoft, GeoTrust, GlobalSign, GoDaddy, Goodmail Systems, GuardID Systems, HomeAway, IronPort, HitachiJoHo, ING Bank, Iconix, Internet Identity, Internet Security Systems, IOvation, IS3, IT Matrix, Kaspersky Labs, Lenos Software, LightSpeed Systems, MailFrontier, MailShell, MarkMonitor, McAfee (MFE), MasterCard, MessageLevel, Microsoft (MSFT), MicroWorld, Mirapoint, MySpace (NWS), MyPW, MX Logic, NameProtect, National Australia Bank (ASX: NAB) Netcraft, NetStar, Network Solutions, Panda Software, Phoenix Technologies Inc. (PTEC), Phorm, SalesForce, Radialpoint, RSA Security (EMC), SecureBrain, Secure Computing (SCUR), S21sec, Sigaba, SoftForum, SOPHOS, SquareTrade, SurfControl, Symantec (SYMC), TDS Telecom, Telefonica (TEF), Trend Micro (TMIC), Tricerion, TriCipher, TrustedID, Tumbleweed Communications (TMWD), SurfControl (SRF.L), Vasco (VDSI), VeriSign (VRSN), Visa, Websense Inc. (WBSN) and Yahoo! (YHOO)

About the Carnegie Mellon Supporting Trust Decisions Project. The Supporting Trust Decisions Project (http://cups.cs.cmu.edu/trust) is a research project affiliated with Carnegie Mellon University’s CyLab and the CMU Usable Privacy and Security Laboratory. The project has developed a number of approaches to end-user security education as well as automated tools for detecting phishing attacks. These user education tools and phishing filters are being commercialized by Wombat Security Technologies, Inc. This project is sponsored by the US National Science Foundation, Fundação para a Ciência e Tecnologia Portugal under a grant from the Information and Communications Technology Institute at Carnegie Mellon, and by the Army Research Office.

-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page

News to Use in Fayetteville, Atlanta, Macon, Peachtree City and all of Georgia