The following article is from Eastman's Online Genealogy Newsletter and is copyright by Richard W. Eastman. It is re-published here with the permission of the author. Information about the newsletter is available at http://www.eogn.com.
I received one of these email messages a few days ago. Luckily, Gmail placed it in my spam folder so I didn't see it until today when I went looking for it. You have to hand it to these scam artists: they certainly are clever at devising methods of stealing your money.
I wrote a couple of days ago at http://goo.gl/nvl9 about a "trojan" email message that steals your user IDs and passwords to your online banking account. This new scam is a different Trojan message with a very clever delivery method.
The new scam sends a fake "iTunes receipt" email message to millions of people. The message appears to be completely authentic, except for the price shown in your bill. The message I received was for nearly $1,000. That's part of the trap.
Most people are likely to take action when seeing an "incorrect amount" appear on their bill. (I didn't do that because I never saw the "bill" in my spam folder until I went looking for it later, after reading about the new scam.) Most people will click on the "report a problem" link that is included in the email message. However, that link takes you to a rogue web page that downloads the same Zeus trojan malware as described in the earlier article to your Windows computer. (Linux and Macintosh computers will not be affected.)
The program then waits for the user to log onto a list of targeted banks and financial institutions, and then steals login credentials and other data which are immediately sent to a remote server hosted by cybercriminals. It can also modify, in a user’s browser, the genuine web pages from a bank’s web servers to ask for personal information such as payment card number and PIN, one time passwords, etc.
Panda Labs released a statement explaining the infection process:
"After clicking the link, the victim is asked to download a fake PDF reader. Once installation is complete, the user is redirected to an infected web page containing the Zeus Trojan, which is specifically designed to steal personal data."
Here is the full announcement from Panda Labs:
Massive Phishing Attack Uses iTunes as Lure to Steal Bank Details, Reports PandaLabs
ORLANDO, Fla., Oct. 4 -- PandaLabs, Panda Security's antimalware laboratory, has discovered that Apple's popular iTunes platform has become a major target for hackers looking to steal credit card data from the service's millions of users.
Victims receive a cleverly-crafted email informing them that they have made an expensive purchase on iTunes. The user, having never made the purchase to begin with, is concerned by the email and naturally tries to resolve the problem – in this case by clicking on the proffered (fake) link. An example of this fraudulent iTunes receipt can be seen here: http://www.flickr.com/photos/panda_security/5050360091/
After clicking the link, the victim is asked to download a fake PDF reader. Once installation is complete, the user is redirected to an infected Web page containing the Zeus Trojan, which is specifically designed to steal personal data. This phishing attack was uncovered shortly after a similar phishing attack targeting LinkedIn users appeared last week, which appears to have originated in Russia.
"Phishing is nothing new," said Luis Corrons, Technical Director of PandaLabs. "What never ceases to surprise us is that the techniques used to trick victims continue to be so simple, but the design and content is so very well-orchestrated. It's very easy to fall into the trap. When using services such as iTunes, it is absolutely crucial that users never go to the website via email, but rather from the platform itself where they can verify their account status."
This technique has been reported to the Anti-Phishing Working Group, which has started to block some of the Web addresses linked to in the fake email.
PandaLabs advises all users to be wary of any emails related to iTunes, regardless of how genuine they seem. Users who think they may have been affected are urged to scan their computers thoroughly to locate and remove any possible active threats. [Windows] Users who do not have an antivirus installed can use Panda Cloud Antivirus, a free security service available at www.cloudantivirus.com.
More information is available in the PandaLabs Blog.
About PandaLabs
Since 1990, its mission has been to detect and eliminate new threats as rapidly as possible to offer our clients maximum security. To do so, PandaLabs has an innovative automated system that analyzes and classifies thousands of new samples a day and returns automatic verdicts (malware or goodware). This system is the basis of collective intelligence, Panda Security's new security model which can even detect malware that has evaded other security solutions.
Currently, 99.4 percent of malware detected by PandaLabs is analyzed through this system of collective intelligence. This is complemented through the work of several teams, each specialized in a specific type of malware (viruses, worms, Trojans, spyware, phishing, spam, etc.), who work 24/7 to provide global coverage. This translates into more secure, simpler and more resource-friendly solutions for clients.
More information is available in the PandaLabs blog: http://www.pandalabs.com.
-----
Community News You Can Use
Click to read MORE news:
www.GeorgiaFrontPage.com
Twitter: @gafrontpage & @TheGATable @HookedonHistory
www.ArtsAcrossGeorgia.com
Twitter: @artsacrossga, @softnblue, @RimbomboAAG
www.FayetteFrontPage.com
Twitter: @FayetteFP
Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts
Thursday, October 7, 2010
Wednesday, May 12, 2010
Remington Financial Group Chairman Issues 'Email Fraud Warning,' Alerts FBI
/PRNewswire/ -- Chairman and founder of Remington Financial Group, Andy Bogdanoff, has alerted the FBI and other law enforcement agencies that an email scam is falsely using Remington's name to gain private information that may be used in identity theft.
In making the announcement, Bogdanoff emphasized that none of Remington's customer data had been breached by what appears to be a 'copycat email' scam similar to those that attempted to victimize bank and credit card customers in the past.
Remington is a national financial services company, specializing in providing commercial real estate owners and developers with access to needed capital. Since 1993, Remington has arranged more than $5 billion in financing for all types of commercial property.
Remington uncovered the "phishing" scheme through routine monitoring of the Internet for potential fraud activity. "In keeping with Remington's fraud policy," Bogdanoff said, "we referred the data we collected to the appropriate law enforcement agencies, including the Federal Bureau of Investigation and appropriate state and local authorities."
Earlier in the year, Remington implemented what is believed to be the most comprehensive and stringent fraud policy in the financial services industry. At the time, Bogdanoff called on others in the industry to "shore up" their fraud policies and to rectify any deficiencies. "By doing so," Bogdanoff said, "the financial services industry can help regain public confidence and trust, which has been sorely tested by recent scandals."
The Remington Financial Group Fraud Policy includes strict monitoring controls and rigorous due diligence procedures designed to protect the integrity of the company and the interests of every person and entity involved in Remington activities.
"My hope is that Remington's Fraud Policy will become the 'gold standard' throughout the industry," Bogdanoff said. "At Remington, our goal is clear: To be super-vigilant against even the hint of fraudulent or other inappropriate activity by any employee, customer or lender associated with Remington. Any such behavior will not be tolerated. And any violation of this policy will be met with swift and appropriate disciplinary or legal action," Bogdanoff said.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
In making the announcement, Bogdanoff emphasized that none of Remington's customer data had been breached by what appears to be a 'copycat email' scam similar to those that attempted to victimize bank and credit card customers in the past.
Remington is a national financial services company, specializing in providing commercial real estate owners and developers with access to needed capital. Since 1993, Remington has arranged more than $5 billion in financing for all types of commercial property.
Remington uncovered the "phishing" scheme through routine monitoring of the Internet for potential fraud activity. "In keeping with Remington's fraud policy," Bogdanoff said, "we referred the data we collected to the appropriate law enforcement agencies, including the Federal Bureau of Investigation and appropriate state and local authorities."
Earlier in the year, Remington implemented what is believed to be the most comprehensive and stringent fraud policy in the financial services industry. At the time, Bogdanoff called on others in the industry to "shore up" their fraud policies and to rectify any deficiencies. "By doing so," Bogdanoff said, "the financial services industry can help regain public confidence and trust, which has been sorely tested by recent scandals."
The Remington Financial Group Fraud Policy includes strict monitoring controls and rigorous due diligence procedures designed to protect the integrity of the company and the interests of every person and entity involved in Remington activities.
"My hope is that Remington's Fraud Policy will become the 'gold standard' throughout the industry," Bogdanoff said. "At Remington, our goal is clear: To be super-vigilant against even the hint of fraudulent or other inappropriate activity by any employee, customer or lender associated with Remington. Any such behavior will not be tolerated. And any violation of this policy will be met with swift and appropriate disciplinary or legal action," Bogdanoff said.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
Labels:
email,
fayette front page,
fbi,
financial,
georgia,
georgia front page,
identity theft,
phishing,
remington,
scam
Friday, April 9, 2010
Phishing Attacks on Taxpayers Rise in the Weeks Leading up to April 15th IRS Tax Filing
/PRNewswire/-- SonicWALL, Inc. (NASDAQ:SNWL) , a leading secure network infrastructure company, last week began seeing the expected rise in phishing threats related to the upcoming April 15 Internal Revenue Service (IRS) tax filing date. The prominent phishing scam comes when taxpayers are notified from the IRS that their tax refund is now available. Scammers will then ask users to provide their bank card information and identity information to assure that the refund is deposited in the appropriate account.
"As we've seen in the past, the weeks before April 15th are the most likely for taxpayers to see a rise in tax-related phishing emails," said Leon Hilton, Email Security Expert, SonicWALL. "We predict that more than 100 million IRS related phishing emails will be sent to tax payers in the days leading up to and after the April 15 tax filing deadline."
While the IRS does not send e-mail regarding your refund, you may still get legitimate e-mail on the subject. A myriad legitimate online filing services, online consultants who answer tax-related questions and online tax calculators currently exist. For example, if you file your taxes with an online tax preparation service you are likely to get legitimate email from them and the bank which acts as the transfer agent for the transaction for the IRS. Phishers use this opportunity to prey on taxpayers who are filing their tax refund -- asking them for bank card information to deposit the refund and social security number so they can verify a taxpayer's identity. Be wary of these types of inquiries.
To help taxpayers identify tax-related potential phishing schemes, the SonicWALL threat team has outlined several steps to help taxpayers defend against these types of phishing-related security threats:
1. Be aware that the IRS does not send you e-mails which ask for any
financial, personal or identity information. Do not respond to these
e-mails. Official correspondence with the IRS is done through US Mail.
2. If you use an online preparations service, pay close attention to
relevant instructions as e-mail messages you could receive include
details such as bank account numbers and when you can expect your
refund to be deposited. Always go back to the tax preparation website
or call to ensure that the online transaction goes smoothly. Also be
sure to print off any related materials to save for later reference if
needed.
3. If you use a tax filing program you will most likely receive an e-mail
notification when your taxes are filed, letting you know that your tax
forms were accepted or possibly rejected. Do not click on any links in
the e-mail. Go back to the tax preparation program and check for any
notifications.
4. Beware of offers that allow you to get loans on your income tax refund.
While some offers are legitimate many others are not and are spam or
phishing scams.
5. If you have a question about an email confirmation of your online
filing and/or refund information from your software program or online
filing service, contact the phone number of the tax service provider.
6. Improve your phishing IQ. SonicWALL has put together the phishing IQ
test specifically to test your phishing knowledge. Go to:
www.sonicwall.com/phishing/
7. For more information about identity phishing, e-mail scams and bogus
IRS websites, go to
http://www.irs.gov/privacy/article/0,,id=179820,00.html?portlet=1
For more information on the topic of phishing and other related threats, go to: http://anti-spam.sonicwall.com/
SonicWALL is a registered trademark of SonicWALL, Inc. Other product and company names mentioned herein may be trademarks and/or registered trademarks of their respective companies.
Safe Harbor Regarding Forward-Looking Statements
Certain statements in this press release are "forward-looking statements" within the meaning of the Private Securities Litigation Reform Act of 1995. The forward-looking statements include but are not limited to statements regarding defensive measures to be used to combat attacks concerning news search sites. These forward-looking statements are based on the opinions and estimates of management at the time the statements are made and are subject to certain risks and uncertainties that could cause actual results to differ materially from those anticipated in the forward-looking statements. In addition, please see the "Risk Factors" described in our Securities and Exchange Commission filings, including our Annual Report on Form 10-K for the year ended December 31, 2008, for a more detailed description of the risks facing our business. All forward-looking statements included in this release are based upon information available to SonicWALL as of the date of the release, and we assume no obligation to update any such forward-looking statement.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
"As we've seen in the past, the weeks before April 15th are the most likely for taxpayers to see a rise in tax-related phishing emails," said Leon Hilton, Email Security Expert, SonicWALL. "We predict that more than 100 million IRS related phishing emails will be sent to tax payers in the days leading up to and after the April 15 tax filing deadline."
While the IRS does not send e-mail regarding your refund, you may still get legitimate e-mail on the subject. A myriad legitimate online filing services, online consultants who answer tax-related questions and online tax calculators currently exist. For example, if you file your taxes with an online tax preparation service you are likely to get legitimate email from them and the bank which acts as the transfer agent for the transaction for the IRS. Phishers use this opportunity to prey on taxpayers who are filing their tax refund -- asking them for bank card information to deposit the refund and social security number so they can verify a taxpayer's identity. Be wary of these types of inquiries.
To help taxpayers identify tax-related potential phishing schemes, the SonicWALL threat team has outlined several steps to help taxpayers defend against these types of phishing-related security threats:
1. Be aware that the IRS does not send you e-mails which ask for any
financial, personal or identity information. Do not respond to these
e-mails. Official correspondence with the IRS is done through US Mail.
2. If you use an online preparations service, pay close attention to
relevant instructions as e-mail messages you could receive include
details such as bank account numbers and when you can expect your
refund to be deposited. Always go back to the tax preparation website
or call to ensure that the online transaction goes smoothly. Also be
sure to print off any related materials to save for later reference if
needed.
3. If you use a tax filing program you will most likely receive an e-mail
notification when your taxes are filed, letting you know that your tax
forms were accepted or possibly rejected. Do not click on any links in
the e-mail. Go back to the tax preparation program and check for any
notifications.
4. Beware of offers that allow you to get loans on your income tax refund.
While some offers are legitimate many others are not and are spam or
phishing scams.
5. If you have a question about an email confirmation of your online
filing and/or refund information from your software program or online
filing service, contact the phone number of the tax service provider.
6. Improve your phishing IQ. SonicWALL has put together the phishing IQ
test specifically to test your phishing knowledge. Go to:
www.sonicwall.com/phishing/
7. For more information about identity phishing, e-mail scams and bogus
IRS websites, go to
http://www.irs.gov/privacy/article/0,,id=179820,00.html?portlet=1
For more information on the topic of phishing and other related threats, go to: http://anti-spam.sonicwall.com/
SonicWALL is a registered trademark of SonicWALL, Inc. Other product and company names mentioned herein may be trademarks and/or registered trademarks of their respective companies.
Safe Harbor Regarding Forward-Looking Statements
Certain statements in this press release are "forward-looking statements" within the meaning of the Private Securities Litigation Reform Act of 1995. The forward-looking statements include but are not limited to statements regarding defensive measures to be used to combat attacks concerning news search sites. These forward-looking statements are based on the opinions and estimates of management at the time the statements are made and are subject to certain risks and uncertainties that could cause actual results to differ materially from those anticipated in the forward-looking statements. In addition, please see the "Risk Factors" described in our Securities and Exchange Commission filings, including our Annual Report on Form 10-K for the year ended December 31, 2008, for a more detailed description of the risks facing our business. All forward-looking statements included in this release are based upon information available to SonicWALL as of the date of the release, and we assume no obligation to update any such forward-looking statement.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
Labels:
cyber scam,
fayette,
fayette front page,
fayetteville,
georgia,
georgia front page,
IRS,
peachtree city,
phishing,
refund,
scam,
tax,
threat,
tyrone
Wednesday, November 18, 2009
Spear Phishing E-mails Target U.S. Law Firms and Public Relations Firms
The FBI assesses with high confidence that hackers are using spear phishing e-mails with malicious payloads to exploit U.S. law firms and public relations firms. During the course of ongoing investigations, the FBI identified noticeable increases in computer exploitation attempts against these entities.
The specific intrusion vector used against the firms is a spear phishing or targeted socially engineered e-mail designed to compromise a network by bypassing technological network defenses and exploiting the person at the keyboard. Hackers exploit the ability of end users to launch the malicious payloads from within the network by attaching a file to the message or including a link to the domain housing the file and enticing users to click the attachment or link.
Network defense against these attacks is difficult as the subject lines are spoofed, or crafted, in such a way to uniquely engage recipients with content appropriate to their specific business interests. In addition to appearing to originate from a trusted source based on the relevance of the subject line, the attachment name and message body are also crafted to associate with the same specific business interests. Opening a message will not directly compromise the system or network because the malicious payload lies in the attachment or linked domain. Infection occurs once someone opens the attachment or clicks the link, which launches a self-executing file and, through a variety of malicious processes, attempts to download another file.
Indicators are unreliable to flag in-bound messages; however, indicators are available to determine an existing compromise. Once executed, the malicious payload will attempt to download and execute the file ‘srhost.exe’ from the domain ‘http://d.ueopen.com’; e.g. http://d.ueopen.com/srhost.exe. Any traffic associated with ‘ueopen.com’ should be considered as an indication of an existing network compromise and addressed appropriately.
The malicious file does not necessarily appear as an ‘exe’ file in each incident. On occasion, the self-executing file has appeared as other file types, e.g., ‘.zip’, ‘.jpeg’, etc.
Please contact your local field office if you experience this network activity and direct incident response notifications to DHS and U.S. CERT.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
The specific intrusion vector used against the firms is a spear phishing or targeted socially engineered e-mail designed to compromise a network by bypassing technological network defenses and exploiting the person at the keyboard. Hackers exploit the ability of end users to launch the malicious payloads from within the network by attaching a file to the message or including a link to the domain housing the file and enticing users to click the attachment or link.
Network defense against these attacks is difficult as the subject lines are spoofed, or crafted, in such a way to uniquely engage recipients with content appropriate to their specific business interests. In addition to appearing to originate from a trusted source based on the relevance of the subject line, the attachment name and message body are also crafted to associate with the same specific business interests. Opening a message will not directly compromise the system or network because the malicious payload lies in the attachment or linked domain. Infection occurs once someone opens the attachment or clicks the link, which launches a self-executing file and, through a variety of malicious processes, attempts to download another file.
Indicators are unreliable to flag in-bound messages; however, indicators are available to determine an existing compromise. Once executed, the malicious payload will attempt to download and execute the file ‘srhost.exe’ from the domain ‘http://d.ueopen.com’; e.g. http://d.ueopen.com/srhost.exe. Any traffic associated with ‘ueopen.com’ should be considered as an indication of an existing network compromise and addressed appropriately.
The malicious file does not necessarily appear as an ‘exe’ file in each incident. On occasion, the self-executing file has appeared as other file types, e.g., ‘.zip’, ‘.jpeg’, etc.
Please contact your local field office if you experience this network activity and direct incident response notifications to DHS and U.S. CERT.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Labels:
email,
fayette,
fayette front page,
fbi,
georgia,
georgia front page,
law firms,
malicious,
phishing,
public relations,
spear phishing,
target
Tuesday, February 3, 2009
Webroot Threat Advisory: Phony Warnings from the Federal Reserve Bank Aim to Swindle Americans
/PRNewswire/ -- Webroot, a leading security provider for the consumer, enterprise and SMB markets, has detected a phishing scam exploiting the names of the Federal Reserve Bank and other federal entities to fool consumers into clicking Web links that infect their PCs with spyware.
A phony e-mail from the Federal Reserve Bank warns of a "large-scale phishing attack" on banks and credit unions that took place January 21. A link to "more detailed information about affected banks and U.S. Treasury restrictions" leads to a fake Web site that infects victims' computers with malware designed to harvest their Web site and POP3 e-mail account usernames and passwords.
Webroot has identified the malware as Trojan-Backdoor-Graypigeon deploying malware via drive-by download. The cyber criminals behind the scam have recycled the e-mail message a number of times; the FDIC reported a previous version of the e-mail January 20. But the domains linked in the message continually change and suggest the message's origin may be legitimate. All point to one PC on China Railcom's IP address space that was hijacked to carry out the phishing attacks.
"Webroot has uncovered a new twist on phishing for financial gain," said Mike Kronenberg, chief technology officer, Consumer Business, Webroot. "In this case, phishers are capitalizing on widespread concern over the current state of the U.S. finance industry. Over 3.5 million Americans fell victim to phishing in 2007 according to recent research, and we can expect scammers to continue launching attacks against unsuspecting people. PC users should protect themselves by always avoiding unfamiliar URLs and questionable e-mails, and by having proven antispyware, antivirus and firewall software in place."
The malware and some of the domains identified as part of this scam are now blocked by Webroot(R) Internet Security Essentials.
-----
www.fayettefrontpage.com
Fayette Front Page
Community News You Can Use
Fayetteville, Peachtree City, Tyrone
www.georgiafrontpage.com
Georgia Front Page
A phony e-mail from the Federal Reserve Bank warns of a "large-scale phishing attack" on banks and credit unions that took place January 21. A link to "more detailed information about affected banks and U.S. Treasury restrictions" leads to a fake Web site that infects victims' computers with malware designed to harvest their Web site and POP3 e-mail account usernames and passwords.
Webroot has identified the malware as Trojan-Backdoor-Graypigeon deploying malware via drive-by download. The cyber criminals behind the scam have recycled the e-mail message a number of times; the FDIC reported a previous version of the e-mail January 20. But the domains linked in the message continually change and suggest the message's origin may be legitimate. All point to one PC on China Railcom's IP address space that was hijacked to carry out the phishing attacks.
"Webroot has uncovered a new twist on phishing for financial gain," said Mike Kronenberg, chief technology officer, Consumer Business, Webroot. "In this case, phishers are capitalizing on widespread concern over the current state of the U.S. finance industry. Over 3.5 million Americans fell victim to phishing in 2007 according to recent research, and we can expect scammers to continue launching attacks against unsuspecting people. PC users should protect themselves by always avoiding unfamiliar URLs and questionable e-mails, and by having proven antispyware, antivirus and firewall software in place."
The malware and some of the domains identified as part of this scam are now blocked by Webroot(R) Internet Security Essentials.
-----
www.fayettefrontpage.com
Fayette Front Page
Community News You Can Use
Fayetteville, Peachtree City, Tyrone
www.georgiafrontpage.com
Georgia Front Page
Labels:
atlanta,
attacks,
fayette front page,
federal reserve bank,
georgia,
georgia front page,
malware,
phishing,
scam,
security
Monday, December 1, 2008
Holiday Season Cyber Scammers Target Victims
The FBI is reminding people this holiday season that cyber criminals continue to aggressively seek ways to steal money and personal information. Scammers are using several techniques to fool potential victims including sending unsolicited e-mails that contain attachments such as electronic greeting cards containing malware (malicious software), setting up spoofing websites that look like legitimate commercial sites, and unleashing phishing and vishing attacks where
individuals receive e-mails asking for personal data.
“"These cyber scammers will do whatever they can to steal your money and personal
information this holiday season and are trying many different ways to commit these
crimes. The best way to protect yourself is to report these scams to law enforcement
or the Internet Crime Complaint Center, IC3,"” said Shawn Henry, Assistant Director, FBI Cyber Division, Washington, D.C.
In the greeting card scam, the cards, which are also referred to as e-cards or postcards,
are being sent via spam. Like many other Internet fraud schemes, the criminals use
social engineering tactics to entice the victim, claiming the card is from a family
member or friend. Although there have been variations in the spam message and attached
malware, generally the spam directs the recipient to click the link provided in
the e-mail to view the e-card. Upon clicking the link, the recipient is unknowingly
taken to a malicious webpage.
Spoofing scams are when criminals create a false or shadow copy of a real website
or e-mail in a way that misleads the recipient. All network traffic between the
victim's browser and the shadow page are sent through the spoofer's machine. This
allows the spoofer to acquire personal information, such as passwords, credit card
numbers, and account numbers.
Even though the e-mail looks like the real thing, complete with authentic logos
and working web links, it's a fake. The website where you're told to enter your
account information is also fake. In some instances, really slick spoofers direct
you to the genuine website, then pop up a window over the site that captures your
personal information. The information entered does not go to the legitimate site,
but rather to the spoofer's account. The information you entered will most likely
be sold to criminals, who'll use it to ruin your credit and drain your account.
In phishing and vishing attacks, individuals report receiving e-mails or text messages
indicating a problem with their account. They are directed to follow the link provided
in the message to update their account or correct the problem. The link actually
directs the individuals to a fraudulent website that looks legitimate where their
personal information, such as account number and PIN, is compromised.
Other reported scams have included victims receiving an e-mail message asking them
to complete an online survey. At the end of the survey, they are asked for their
personal account information to allow funds to be credited to the account in appreciation
for completing the survey. Providing this information will allow criminals to compromise
the account.
Here are some tips you can use to avoid becoming a victim of cyber fraud:
* Do not respond to unsolicited (spam) e-mail.
* Do not click on links contained within an unsolicited e-mail.
* Be cautious of e-mail claiming to contain pictures in attached files, as the files
may contain viruses. Only open attachments from known senders.
* Avoid filling out forms in e-mail messages that ask for personal information.
* Always compare the link in the e-mail to the link that you are actually directed
to.
* Log on to the official website, instead of "linking" to it from an unsolicited e-mail.
* Contact the actual business that supposedly sent the e-mail to verify if the e-mail
is genuine.
To receive the latest information about cyber scams please go to the FBI website and sign up for e-mail alerts by clicking on one of the red envelopes. If you have received a scam e-mail, please notify the IC3 by filing a complaint at www.ic3.gov. For more information on e-scams, please visit the FBI's New E-Scams and Warnings webpage.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
individuals receive e-mails asking for personal data.
“"These cyber scammers will do whatever they can to steal your money and personal
information this holiday season and are trying many different ways to commit these
crimes. The best way to protect yourself is to report these scams to law enforcement
or the Internet Crime Complaint Center, IC3,"” said Shawn Henry, Assistant Director, FBI Cyber Division, Washington, D.C.
In the greeting card scam, the cards, which are also referred to as e-cards or postcards,
are being sent via spam. Like many other Internet fraud schemes, the criminals use
social engineering tactics to entice the victim, claiming the card is from a family
member or friend. Although there have been variations in the spam message and attached
malware, generally the spam directs the recipient to click the link provided in
the e-mail to view the e-card. Upon clicking the link, the recipient is unknowingly
taken to a malicious webpage.
Spoofing scams are when criminals create a false or shadow copy of a real website
or e-mail in a way that misleads the recipient. All network traffic between the
victim's browser and the shadow page are sent through the spoofer's machine. This
allows the spoofer to acquire personal information, such as passwords, credit card
numbers, and account numbers.
Even though the e-mail looks like the real thing, complete with authentic logos
and working web links, it's a fake. The website where you're told to enter your
account information is also fake. In some instances, really slick spoofers direct
you to the genuine website, then pop up a window over the site that captures your
personal information. The information entered does not go to the legitimate site,
but rather to the spoofer's account. The information you entered will most likely
be sold to criminals, who'll use it to ruin your credit and drain your account.
In phishing and vishing attacks, individuals report receiving e-mails or text messages
indicating a problem with their account. They are directed to follow the link provided
in the message to update their account or correct the problem. The link actually
directs the individuals to a fraudulent website that looks legitimate where their
personal information, such as account number and PIN, is compromised.
Other reported scams have included victims receiving an e-mail message asking them
to complete an online survey. At the end of the survey, they are asked for their
personal account information to allow funds to be credited to the account in appreciation
for completing the survey. Providing this information will allow criminals to compromise
the account.
Here are some tips you can use to avoid becoming a victim of cyber fraud:
* Do not respond to unsolicited (spam) e-mail.
* Do not click on links contained within an unsolicited e-mail.
* Be cautious of e-mail claiming to contain pictures in attached files, as the files
may contain viruses. Only open attachments from known senders.
* Avoid filling out forms in e-mail messages that ask for personal information.
* Always compare the link in the e-mail to the link that you are actually directed
to.
* Log on to the official website, instead of "linking" to it from an unsolicited e-mail.
* Contact the actual business that supposedly sent the e-mail to verify if the e-mail
is genuine.
To receive the latest information about cyber scams please go to the FBI website and sign up for e-mail alerts by clicking on one of the red envelopes. If you have received a scam e-mail, please notify the IC3 by filing a complaint at www.ic3.gov. For more information on e-scams, please visit the FBI's New E-Scams and Warnings webpage.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Labels:
atlanta,
cyber scam,
fayette front page,
fbi,
georgia,
georgia front page,
phishing,
spam,
spoofing,
warning
Thursday, October 16, 2008
Teaching Consumers On-Line Safety Easiest When They Take the Bait
(BUSINESS WIRE)--The Anti-Phishing Working Group (APWG) and Carnegie Mellon University’s Supporting Trust Decisions Project have established a phishing page redirect initiative that protects global online consumers who have been tricked into clicking links in scam emails by delivering them to Web pages that instruct them on the dangers of phishing – and how to avoid them. The program was announced today at the APWG conference in Atlanta.
The AWPG/Carnegie Mellon Phishing Education Landing Page program builds on the philosophy of using the “teachable moment” to warn users immediately after they’ve fallen for a phishing lure and then give them on-line safety instruction precisely at a time when they are receptive to it. Phishing sites are designed to resemble Web sites of legitimate businesses, such as banks and online retailers, to trick people into revealing credit card numbers, bank accounts or login names and passwords. Actionable messaging will help consumers to avoid falling victim to these scams a second time.
“We are excited about the opportunity to educate consumers as they are falling victim to a phishing site,” said Dr. Laura Mather, Managing Director of Operational Policy for the APWG and CEO of Silver Tail Systems. “We see this initiative as having real impact in helping people understand when they have received a phishing communication so that they can protect themselves going forward.”
This education-at-time-of-action is accomplished by leveraging the URLs of the phishing sites themselves after anti-phishing investigators have identified the sites and shut them down. Instead of leaving the URL file blank, returning a ‘PAGE NOT FOUND’ message to consumers following phishing links, they will be served a page of instruction on how to avoid phishing and reduce the risk of falling victim to electronic crime. (Redirect scripts placed at the sanitized phishing URL will automatically forward the advisory content.)
“Our research has shown that most Internet users don’t know very much about online scams and don’t realize that there are some simple things they can do to protect themselves,” said Dr. Lorrie Cranor, an associate professor of computer science and engineering & public policy at Carnegie Mellon and director of the Supporting Trust Decisions Project.
Ponnurangam Kumaraguru, a computer science Ph.D. student who is leading the effort to design and evaluate anti-phishing training materials at Carnegie Mellon added, “Nobody wants to spend their time taking on-line safety courses. But we’ve demonstrated that users are receptive to on-line safety instruction immediately after they fall for a phishing attack and they tend to remember this instruction."
The phishing education landing page developed by APWG and Carnegie Mellon teaches would-be victims not to give out personal information upon email request and to use a skeptical eye in judging online communications.
The implementation of the program depends on the participation of both takedown service providers and the ISPs and other companies whose servers have been co-opted to host phishing sites. The APWG is already successfully recruiting companies that perform phishing site takedowns, victimized brandholders and trade associations to encourage ISPs and other organizations that remove phish sites to use the APWG’s education landing page program.
The program is based on a similar program initiated by Bank of America in 2007. The APWG/Carnegie Mellon program builds on Bank of America’s ideas by creating a page that can be used for phishing site against any brand. Bank of America has already implemented the APWG/Carnegie Mellon program.
“Bank of America is committed to providing its customers with industry leading security tools and advice to protect them and enhance their overall customer experience. Educating our customers about the risks of identity theft and fraud is critical,” says David Shroyer, SVP for eCommerce Online Security at Bank of America.
"We know from experience that an educated customer is the best defense against fraud, and with this program we are educating our customers at the point of incidence, and letting customers know that we are working to protect them,” Mr. Shroyer said.
The APWG/Carnegie Mellon scheme will augment the usual procedure for communicating to the hosting organization about phishing sites. Instead of asking that the site be disabled and file content associated with the phishing URL removed, the takedown provider or victimized brandholder would request that the URL be preserved and a redirect script send the duped user to a webpage hosted by the APWG.
The education landing page will automatically determine whether the user is using a PC or laptop or handheld device and vend the device-appropriate page. Users of PDAs and Web-enabled cell phones will receive a page exclusively of text. People using PCs and laptops will receive an enhanced page of text, graphics and a number of links to online resources.
The APWG/Carnegie Mellon scheme will augment the usual procedure for communicating to the hosting organization about phishing sites. Instead of asking that the site be disabled and file content associated with the phishing URL removed, the takedown provider or victimized brandholder would request that the URL be preserved and a redirect script send the duped user to a webpage hosted by the APWG.
The APWG page will automatically determine whether the user is using a PC or laptop or handheld device and vend the device-appropriate page. Users of PDAs and Web-enabled cell phones will receive a page exclusively of text. People using PCs and laptops will receive an enhanced page of text, graphics and a number of links to online resources.
“This initiative gives takedown teams, ISPs, registrars, and registries the opportunity to take one more step in protecting consumers against identity theft and the other crimes perpetrated by Phishers,” said Dr. Mather.
As a next step, the APWG will organize the translation of the pages into various languages to serve the larger international community of consumers, brandholders and ISPs who are confronting the threats of electronic crime and engaging questions of efficacious consumer education.
Links:
Redirect education page: http://education.apwg.org/r/en/
Text only redirect education page: http://education.apwg.org/r/index.html
About the redirect education page initiative: http://education.apwg.org/r/about.html
About the APWG: The APWG is an industry, founded as the Anti-Phishing Working Group in 2003, is an industry, law enforcement and government coalition focused on eliminating the identity theft and fraud that result from the growing problem of phishing, email spoofing, and crimeware. Membership is open to qualified financial institutions, online retailers, ISPs, the law enforcement community and solutions providers. There are more than 1,800 companies and government agencies worldwide participating in the APWG and more than 3,200 members. The APWG's Web site (www.antiphishing.org) offers the public and industry information about phishing and email fraud, including identification and promotion of pragmatic technical solutions that provide immediate protection. APWG's corporate sponsors include: 8e6 Technologies, AT&T (T), Able NV, Afilias Ltd., AhnLab, BillMeLater, BBN Technologies, BlueStreak, BrandMail, BrandProtect, Bsecure Technologies, Cisco (CSCO), Clear Search, Cloudmark, Cydelity, Cyveillance, DigiCert, DigitalEnvoy, DigitalResolve, Digital River, Earthlink (ELNK), eBay/PayPal (EBAY), Entrust (ENTU), Experian, eEye, Fortinet, FraudWatch International, FrontPorch, F-Secure, Goodmail Systems, Grisoft, GeoTrust, GlobalSign, GoDaddy, Goodmail Systems, GuardID Systems, HomeAway, IronPort, HitachiJoHo, ING Bank, Iconix, Internet Identity, Internet Security Systems, IOvation, IS3, IT Matrix, Kaspersky Labs, Lenos Software, LightSpeed Systems, MailFrontier, MailShell, MarkMonitor, McAfee (MFE), MasterCard, MessageLevel, Microsoft (MSFT), MicroWorld, Mirapoint, MySpace (NWS), MyPW, MX Logic, NameProtect, National Australia Bank (ASX: NAB) Netcraft, NetStar, Network Solutions, Panda Software, Phoenix Technologies Inc. (PTEC), Phorm, SalesForce, Radialpoint, RSA Security (EMC), SecureBrain, Secure Computing (SCUR), S21sec, Sigaba, SoftForum, SOPHOS, SquareTrade, SurfControl, Symantec (SYMC), TDS Telecom, Telefonica (TEF), Trend Micro (TMIC), Tricerion, TriCipher, TrustedID, Tumbleweed Communications (TMWD), SurfControl (SRF.L), Vasco (VDSI), VeriSign (VRSN), Visa, Websense Inc. (WBSN) and Yahoo! (YHOO)
About the Carnegie Mellon Supporting Trust Decisions Project. The Supporting Trust Decisions Project (http://cups.cs.cmu.edu/trust) is a research project affiliated with Carnegie Mellon University’s CyLab and the CMU Usable Privacy and Security Laboratory. The project has developed a number of approaches to end-user security education as well as automated tools for detecting phishing attacks. These user education tools and phishing filters are being commercialized by Wombat Security Technologies, Inc. This project is sponsored by the US National Science Foundation, Fundação para a Ciência e Tecnologia Portugal under a grant from the Information and Communications Technology Institute at Carnegie Mellon, and by the Army Research Office.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
News to Use in Fayetteville, Atlanta, Macon, Peachtree City and all of Georgia
The AWPG/Carnegie Mellon Phishing Education Landing Page program builds on the philosophy of using the “teachable moment” to warn users immediately after they’ve fallen for a phishing lure and then give them on-line safety instruction precisely at a time when they are receptive to it. Phishing sites are designed to resemble Web sites of legitimate businesses, such as banks and online retailers, to trick people into revealing credit card numbers, bank accounts or login names and passwords. Actionable messaging will help consumers to avoid falling victim to these scams a second time.
“We are excited about the opportunity to educate consumers as they are falling victim to a phishing site,” said Dr. Laura Mather, Managing Director of Operational Policy for the APWG and CEO of Silver Tail Systems. “We see this initiative as having real impact in helping people understand when they have received a phishing communication so that they can protect themselves going forward.”
This education-at-time-of-action is accomplished by leveraging the URLs of the phishing sites themselves after anti-phishing investigators have identified the sites and shut them down. Instead of leaving the URL file blank, returning a ‘PAGE NOT FOUND’ message to consumers following phishing links, they will be served a page of instruction on how to avoid phishing and reduce the risk of falling victim to electronic crime. (Redirect scripts placed at the sanitized phishing URL will automatically forward the advisory content.)
“Our research has shown that most Internet users don’t know very much about online scams and don’t realize that there are some simple things they can do to protect themselves,” said Dr. Lorrie Cranor, an associate professor of computer science and engineering & public policy at Carnegie Mellon and director of the Supporting Trust Decisions Project.
Ponnurangam Kumaraguru, a computer science Ph.D. student who is leading the effort to design and evaluate anti-phishing training materials at Carnegie Mellon added, “Nobody wants to spend their time taking on-line safety courses. But we’ve demonstrated that users are receptive to on-line safety instruction immediately after they fall for a phishing attack and they tend to remember this instruction."
The phishing education landing page developed by APWG and Carnegie Mellon teaches would-be victims not to give out personal information upon email request and to use a skeptical eye in judging online communications.
The implementation of the program depends on the participation of both takedown service providers and the ISPs and other companies whose servers have been co-opted to host phishing sites. The APWG is already successfully recruiting companies that perform phishing site takedowns, victimized brandholders and trade associations to encourage ISPs and other organizations that remove phish sites to use the APWG’s education landing page program.
The program is based on a similar program initiated by Bank of America in 2007. The APWG/Carnegie Mellon program builds on Bank of America’s ideas by creating a page that can be used for phishing site against any brand. Bank of America has already implemented the APWG/Carnegie Mellon program.
“Bank of America is committed to providing its customers with industry leading security tools and advice to protect them and enhance their overall customer experience. Educating our customers about the risks of identity theft and fraud is critical,” says David Shroyer, SVP for eCommerce Online Security at Bank of America.
"We know from experience that an educated customer is the best defense against fraud, and with this program we are educating our customers at the point of incidence, and letting customers know that we are working to protect them,” Mr. Shroyer said.
The APWG/Carnegie Mellon scheme will augment the usual procedure for communicating to the hosting organization about phishing sites. Instead of asking that the site be disabled and file content associated with the phishing URL removed, the takedown provider or victimized brandholder would request that the URL be preserved and a redirect script send the duped user to a webpage hosted by the APWG.
The education landing page will automatically determine whether the user is using a PC or laptop or handheld device and vend the device-appropriate page. Users of PDAs and Web-enabled cell phones will receive a page exclusively of text. People using PCs and laptops will receive an enhanced page of text, graphics and a number of links to online resources.
The APWG/Carnegie Mellon scheme will augment the usual procedure for communicating to the hosting organization about phishing sites. Instead of asking that the site be disabled and file content associated with the phishing URL removed, the takedown provider or victimized brandholder would request that the URL be preserved and a redirect script send the duped user to a webpage hosted by the APWG.
The APWG page will automatically determine whether the user is using a PC or laptop or handheld device and vend the device-appropriate page. Users of PDAs and Web-enabled cell phones will receive a page exclusively of text. People using PCs and laptops will receive an enhanced page of text, graphics and a number of links to online resources.
“This initiative gives takedown teams, ISPs, registrars, and registries the opportunity to take one more step in protecting consumers against identity theft and the other crimes perpetrated by Phishers,” said Dr. Mather.
As a next step, the APWG will organize the translation of the pages into various languages to serve the larger international community of consumers, brandholders and ISPs who are confronting the threats of electronic crime and engaging questions of efficacious consumer education.
Links:
Redirect education page: http://education.apwg.org/r/en/
Text only redirect education page: http://education.apwg.org/r/index.html
About the redirect education page initiative: http://education.apwg.org/r/about.html
About the APWG: The APWG is an industry, founded as the Anti-Phishing Working Group in 2003, is an industry, law enforcement and government coalition focused on eliminating the identity theft and fraud that result from the growing problem of phishing, email spoofing, and crimeware. Membership is open to qualified financial institutions, online retailers, ISPs, the law enforcement community and solutions providers. There are more than 1,800 companies and government agencies worldwide participating in the APWG and more than 3,200 members. The APWG's Web site (www.antiphishing.org) offers the public and industry information about phishing and email fraud, including identification and promotion of pragmatic technical solutions that provide immediate protection. APWG's corporate sponsors include: 8e6 Technologies, AT&T (T), Able NV, Afilias Ltd., AhnLab, BillMeLater, BBN Technologies, BlueStreak, BrandMail, BrandProtect, Bsecure Technologies, Cisco (CSCO), Clear Search, Cloudmark, Cydelity, Cyveillance, DigiCert, DigitalEnvoy, DigitalResolve, Digital River, Earthlink (ELNK), eBay/PayPal (EBAY), Entrust (ENTU), Experian, eEye, Fortinet, FraudWatch International, FrontPorch, F-Secure, Goodmail Systems, Grisoft, GeoTrust, GlobalSign, GoDaddy, Goodmail Systems, GuardID Systems, HomeAway, IronPort, HitachiJoHo, ING Bank, Iconix, Internet Identity, Internet Security Systems, IOvation, IS3, IT Matrix, Kaspersky Labs, Lenos Software, LightSpeed Systems, MailFrontier, MailShell, MarkMonitor, McAfee (MFE), MasterCard, MessageLevel, Microsoft (MSFT), MicroWorld, Mirapoint, MySpace (NWS), MyPW, MX Logic, NameProtect, National Australia Bank (ASX: NAB) Netcraft, NetStar, Network Solutions, Panda Software, Phoenix Technologies Inc. (PTEC), Phorm, SalesForce, Radialpoint, RSA Security (EMC), SecureBrain, Secure Computing (SCUR), S21sec, Sigaba, SoftForum, SOPHOS, SquareTrade, SurfControl, Symantec (SYMC), TDS Telecom, Telefonica (TEF), Trend Micro (TMIC), Tricerion, TriCipher, TrustedID, Tumbleweed Communications (TMWD), SurfControl (SRF.L), Vasco (VDSI), VeriSign (VRSN), Visa, Websense Inc. (WBSN) and Yahoo! (YHOO)
About the Carnegie Mellon Supporting Trust Decisions Project. The Supporting Trust Decisions Project (http://cups.cs.cmu.edu/trust) is a research project affiliated with Carnegie Mellon University’s CyLab and the CMU Usable Privacy and Security Laboratory. The project has developed a number of approaches to end-user security education as well as automated tools for detecting phishing attacks. These user education tools and phishing filters are being commercialized by Wombat Security Technologies, Inc. This project is sponsored by the US National Science Foundation, Fundação para a Ciência e Tecnologia Portugal under a grant from the Information and Communications Technology Institute at Carnegie Mellon, and by the Army Research Office.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
News to Use in Fayetteville, Atlanta, Macon, Peachtree City and all of Georgia
Labels:
anti-phishing,
atlanta,
bait,
consumers,
email,
fayette front page,
fayetteville,
georgia,
georgia front page,
peachtree city,
phishing,
safety,
scam,
tips,
victim
Subscribe to:
Posts (Atom)
