By Kelly Shermach CRM Buyer Part of the ECT News Network
03/28/05 5:00 AM PT
Unfortunately, banks and other frequently phished organizations, as well as independent security developers, are moving more slowly to deter these attacks than the phishers are to commit them, said Peter Cassidy, secretary general of the Anti-Phishing Working Group.
Phishing is one of the most significant threats to online consumers, and as the incidence of this type of fraud increases, so does the perpetrators' average take. Phishers who lucked out and lured several customers of a British bank into false communications recently made off with an average of 5,000 pounds sterling, or US$9,348, per phished account.
With every successful intrusion on consumers' financial identities, phishers also gain more financial resources which they can then use to invest in more programmers and technology to advance their sophistication in fraud.
Phishers may target tens of millions of online consumers, but they only need a tiny fraction of those users to bite for them to collect a handsome reward. And many more malicious e-mails, culled from ever-expanding data sources, are going out as the months pass, according to the Anti-Phishing Working Group.
Unfortunately, banks and other frequently phished organizations, as well as independent security developers, are moving more slowly to deter these attacks than the phishers are to commit them, said Peter Cassidy, secretary general of the group.
Many-Splendored Thing
Not long ago, phishing consisted only of a social engineering scam in which phishers spammed consumer e-mail accounts, positioning themselves as real-life banks. Half of these fake e-mails fell into spam filters employed by e-mail service providers, and another 35 percent got dumped by wise consumers.
The remaining 15 percent, however, arrived in the inboxes of consumers who were actually customers of the banks named by the phishers in their attacks. A smaller percentage of these messages were opened and acted upon by gullible recipients who clicked on links in the e-mails and entered their user names, passwords and other personal information the phisher requested on a phony bank login page.
Now phishers worldwide play an even sneakier game. They send e-mails offering content like sports scores or porn or daily jokes. These e-mails deliver their recipients to real Web sites that feature the advertised content, but the phishers use the visits to download key-logger programs, record keystrokes made on computers on which phishers have overridden the host files, or malware on consumer computers. In this way, they effectively take control of unwitting computer users' hardware so that when they visit their banks online, phishers literally cash in.
Cassidy called this "blended" or "hybrid" phishing because it combines the social engineering -- tricking e-mail accountholders into a communication based on a feigned relationship or a social invitiation -- with technical subterfuge, or the co-opting of private computers through the Internet.
"That combination is not wholesome," he said.
Heads in the Sand
Cassidy warned that banks need to be paying careful attention.
"When you're a bank, all you're really selling is trust, so you can't make it look like you're out of control of the solution," he told CRM Buyer.
"Everyone is aware that this is going on, but at the end of the day, the losses are so small that [banks] wipe the crocodile tears of their customers away and put the money back into their accounts," he said. "In terms of rational economics, they figure anything they spend [on security] would completely eclipse any losses from phishing. They don't want to go out with a solution that won't work in another six months or a year."
But that doesn't do much for trust, especially when consumers read about phishing attacks in the media. Richard Stiennon, vice president of threat research at Webroot Software Inc., the maker of Phish Net, an application for consumers that is in beta test now, predicted that all banks eventually will adopt biometrics, single-use security codes or smart card functionality being tested by a handful of security-savvy institutions now.
But they may wait until the last possible minute to implement these safety measures.
"Whenever cybercrime intersects with existing business models, they don't react until they're affected," he said. "Banks are the most guilty parties in not evaluating the risks well enough. ... There are technology solutions that the banks should be using."
Attacking eBay
While the most recent report from the Anti-Phishing Working Group -- results for the month of January 2005 -- show that 80 percent of phishing activity involves financial institutions, eBay (Nasdaq: EBAY) also ranks among the top five companies most frequently targeted by phishers.
EBay's problem stems from its prominence in the online world. With the scads of transactions that take place through the auction house and the virtual nature of all communications occurring through it, phishers can hardly pass the opportunity to scam sellers.
"EBay has over 20 million active users. That makes it one of the most likely targets. Citibank doesn't have that many online users even though it might have more accounts," said Stiennon.
The Anti-Phishing Working Group's Cassidy commended eBay for its security initiatives, however, and said, "eBay has been subject to this probably longer than anyone else and is doing a lot that's probably smarter than anyone else," he said. "It is way ahead of the world."
Understanding the Problem
"The message that really has to come across is that phishing is evolving," said Cassidy. "It's going to higher levels of automation that ultimately will not require any interaction from consumers at all."
Art Mannion, Internet security analyst with the CERT Coordination Center, a center for Internet security expertise at Carnegie Mellon University, agreed. "Phishing is not a technical problem," he said, referring to the hybrid of social scam artistry and sneaky arrests of hardware. "That's why it's uncontrolled. There aren't necessarily technological solutions for all human problems."
Skybox Security Introduces Worm Prediction Software March 26, 2005
To meet the heightened threats posed by worms, Skybox View takes a different approach than other security software. Its recently released ENHANCED software shifts to a pre-attack defense strategy by predicting which network vulnerabilities can be exploited based on behavior patterns of worms.
Related Stories
Phishing Attacks Number 33 Million Each Week March 22, 2005
"Offline retailers worked together to reduce fraud over the years and have cut it down to under 1 percent of all retail sales," said Jupiter Research retail analyst Patti Freeman Evans. "Now online retailers have to work together to make sure phishing doesn't continue at this rapid growth rate."
EBay, Microsoft, Visa Join in New Anti-Phishing Effort February 15, 2005
"EBay and PayPal's participation in the Phish Report Network is one of many steps we have taken to improve security of the e-commerce experience," said Howard Schmidt, eBay and PayPal's chief security strategist and former White House cyber-security advisor.
FBI Spearheading Anticrime Initiative Against Phishing December 27, 2004
Other industry groups have focused on identifying phishing Web sites and sharing case information. Digital PhishNet, however, is the first group to focus on aiding criminal law enforcement and assisting in catching and prosecuting those responsible for committing crimes against consumers through phishing.
Browser Flaw Leaves Shoppers Open to Phishing Scam December 10, 2004
Security firm Secunia reported that the vulnerability affects nearly all browsers, including Internet Explorer, Mozilla, Firefox, Konqueror, Opera, Netscape and Safari. The company said it alerted the browsers' developers of the vulnerability months ago.
Loyalty Card Programs Refocus on Customer Satisfaction December 07, 2004
To determine customer satisfaction, packaged goods companies use the standard measures of case volume moved, but with the help of loyalty program data, they also can measure such phenomena as build in customer satisfaction, customer response to the loyalty program, consumer attitude regarding the brand, and sustainable sales lift.
Related News Alerts
More by Kelly Shermach
Does SaaS Meet the Customization Challenge? April 17, 2007
SaaS market leaders have improved their customization options to meet most enterprise needs, says Michael Greenberg , vice president of marketing at Loyalty Lab. "Salesforce.com leads the way with their Apex platform providing a dizzying array of options to incorporate SaaS into any enterprise environment."
Getting Physical With Online Shopping April 14, 2007
"Because each customer has a different buying style, unique selection criteria, personal motivations and shopping approach, retailers must deliver a more dynamic experience to better accommodate customer preferences," notes Errol Denger, senior strategist for WebSphere commerce at IBM.
Accenture Partner Garret Wu: Health Info Prototype Is One Small Step April 11, 2007
"Accenture's prototype introduces both common language and data standards, and integrates information across the entire healthcare system. It enables a single view of a patient's medical information. This helps provide better patient care, more consistent care and supports the secondary use of data," said Garret Wu, a partner at Accenture Health & Life Sciences.