CompUSA
Showing posts with label personal data. Show all posts
Showing posts with label personal data. Show all posts

Wednesday, April 1, 2009

Spear Phishers

Customers of a telecommunications firm received an e-mail recently explaining a problem with their latest order. They were asked to go to the company website, via a link in the e-mail, to provide personal information—like their birthdates and Social Security numbers. But both the e-mail and the website were bogus.

It’s a real-life, classic case of “phishing”—a virtual trap set by cyber thieves that uses official-looking e-mails to lure you to fake websites and trick you into revealing your personal information.

It’s also an example of an even more mischievous type of phishing known as “spear phishing”—a rising cyber threat that you need to know about.

Instead of casting out thousands of e-mails randomly hoping a few victims will bite, spear phishers target select groups of people with something in common—they work at the same company, bank at the same financial institution, attend the same college, order merchandise from the same website, etc. The e-mails are ostensibly sent from organizations or individuals the potential victims would normally get e-mails from, making them even more deceptive.

How spear phishing works. First, criminals need some inside information on their targets to convince them the e-mails are legitimate. They often obtain it by hacking into an organization’s computer network (which is what happened in the above case) or sometimes by combing through other websites, blogs, and social networking sites.

Then, they send e-mails that look like the real thing to targeted victims, offering all sorts of urgent and legitimate-sounding explanations as to why they need your personal data.

Finally, the victims are asked to click on a link inside the e-mail that takes them to a phony but realistic-looking website, where they are asked to provide passwords, account numbers, user IDs, access codes, PINs, etc.

Criminal gain, your loss. Once criminals have your personal data, they can access your bank account, use your credit cards, and create a whole new identity using your information.

Spear phishing can also trick you into downloading malicious codes or malware after you click on a link embedded in the e-mail…an especially useful tool in crimes like economic espionage where sensitive internal communications can be accessed and trade secrets stolen. Malware can also hijack your computer, and hijacked computers can be organized into enormous networks called botnets that can be used for denial of service attacks.

How to avoid becoming a spear phishing victim. Law enforcement takes this kind of crime seriously, and we in the FBI work cyber investigations with our partners, including the U.S. Secret Service and investigative agencies within the Department of Defense. But what can you do to make sure you don’t end up a victim in one of our cases?

* Keep in mind that most companies, banks, agencies, etc., don’t request personal information via e-mail. If in doubt, give them a call (but don’t use the phone number contained in the e-mail—that’s usually phony as well).
* Use a phishing filter…many of the latest web browsers have them built in or offer them as plug-ins.
* Never follow a link to a secure site from an e-mail—always enter the URL manually.
* Don't be fooled (especially today) by the latest scams. Visit the Internet Crime Complaint Center (IC3) and "LooksTooGoodToBeTrue" websites for tips and information.

-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page

Sunday, December 21, 2008

Consumer Group Calls on Google to Offer Zero Personal Data Retention Policy; Seeks Meeting With Chairman Eric Schmidt About Privacy Concerns

/PRNewswire-USNewswire/ -- Google should offer users of its search engine the ability to leave no personal data on the Internet giant's servers, the nonpartisan, nonprofit Consumer Watchdog said today and asked for a meeting with Google's chairman to discuss the group's privacy concerns.

In a letter to Google Chairman Eric Schmidt, Consumer Watchdog President Jamie Court and Policy Advocate John M. Simpson noted that the search engine Ask.Com offers the ability for users' personal data to be removed almost immediately from its servers with its AskEraser service. "We call on you to offer Google's users such a clearly identifiable 'opt out' function on its search engine that is essentially a zero personal data retention policy."

During a question and answer period at a New America Foundation speech in Washington, DC, Schmidt told Simpson that he was "sympathetic" to the group's privacy concerns and told him to arrange a meeting "off line" rather than in front of 200 people. See a video of that exchange here:

http://www.youtube.com/watch?v=NKybBlEjSyk&eurl

The letter to Google came after the announcement this week by its rival Yahoo! that it will anonymize personal data it retains after only 90 days. Google currently keeps the data for nine months. European privacy officials have suggested a six-month standard, a limit that Microsoft said it would adopt if all search engine companies adopt the standard.

"This is really about choice," said Simpson. "People should have the right to choose what they do with their personal data and if they provide it all."

Consumer Watchdog's letter requests a meeting with Schmidt to discuss the consumer group's privacy concerns and follows an Oct. 13 letter to Google. Read that letter here: http://www.consumerwatchdog.org/resources/LtrGoogle10-13-08.pdf. Read Google's Nov. 26 response here:

http://www.consumerwatchdog.org/resources/Googleresponse112608.pdf. Read today's letter to Schmidt here: http://www.consumerwatchdog.org/resources/LtrGoogle121908.pdf.

"Google, because of its dominance on the Internet, stands alone as the entity most able to set and maintain a gold standard for protecting privacy," the letter said. "Conversely, it could also be the company that sounds the death knell for privacy protections on the Internet."

To guarantee privacy, Consumer Watchdog said, users need: 1) control over their private data; 2) transparency about how their data is gathered and used; and 3) the right to give informed consent through "opt in" functions, rather than having to sift through pages in order to even locate the "opt out" function, or in its absence, a clearly identifiable and accessible "opt out."

View videos that demonstrate how users are in an unnoticed conversation with Google when they use its services at http://www.consumerwatchdog.org/google.

-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page