Monday | 13 October, 2008
CIO
Fighting Phish, Fakes and Frauds
The Internet makes identity theft almost laughably easy. Phishing - or the practice of sending e-mails and using fake Web sites that spoof a legitimate business in order to dupe unsuspecting customers into sharing personal and financial data - requires minimal effort and capital.
Alice Dragoon 06 October, 2004 12:10:14

Companies on the front lines of the phishing wars share tactics for making their sites spoof-proof and protecting online transactions.

Reader ROI

  • Why phishing is a major threat to future e-commerce
  • How you can protect your employees and customers from phish attacks
  • What you can do to make your Web site a difficult target

On June 25, an e-mail that appeared to be from the PayPal Support Centre asked members of the online payment service to update their account information to protect themselves from fraud. Failure to update records by July 15, the message read, would result in account suspension. Recipients who clicked on the embedded link encountered a familiar PayPal log-in screen, then an announcement of a new immediate payment option as well as a ho-hum notification of changes to PayPal's user agreement and privacy policy.

All standard PayPal fare. So, few customers would have thought twice about filling in the online form that followed - even though it asked them to cough up their e-mail address and PayPal password, credit card number and expiration date, billing address and phone number, cheque account number, ATM code, Social Security number, birth date and mother's maiden name. Upon hitting the "Continue" button, the PayPal member would have been greeted with an "Updating Your Account" screen for a few seconds before landing on a replica of a general PayPal page.

It was all so convincing that respondents might never have suspected that the online form they just completed was on its way to a crook in Seoul. Those who did reply gave away access to their PayPal account, credit card and cheque accounts, and quite possibly enough information for the fraudster to take out a second mortgage on their homes.

The Internet makes identity theft almost laughably easy. Phishing - or the practice of sending e-mails and using fake Web sites that spoof a legitimate business in order to dupe unsuspecting customers into sharing personal and financial data - requires minimal effort and capital. "A lot of drug lords are getting into phishing," says Avivah Litan, a vice president and research director at Gartner. "They set up phishing rings because it's easier and more lucrative than selling cocaine."

Not surprisingly, the incidence of phishing is growing at an alarming rate. In June, the Anti-Phishing Working Group (APWG), an industry group, counted 1422 phishing attacks - more than 12 times the number of attacks reported in December. So far, phishers have mostly targeted customers of large banks, credit card companies, online payment services, ISPs and online retailers. In June, Citibank alone was the target of 492 attacks, and eBay experienced 285 attacks. PayPal was targeted 42 times in February, 63 in March, 135 in April, 149 in May and 163 in June. But any company with a recognizable brand name could very well become the next target. Government agencies, including the IRS and the FBI in the US, have been spoofed by phishers eager to capitalize on governmental authority to make an easy profit. In fact, even internal corporate data is becoming a target for phishers, as executives at Wyndham International discovered when a message purporting to be from the hotel chain's IT department asked employees to verify their corporate passwords.

"Spoofing is a threat to any company with a sizeable customer base," says Ken Miller, vice president of risk management at PayPal. "Every CIO needs to be aware of this issue."

Indeed, phishing has scared some consumers so badly that they say they're not going to bank online any more, says Dave Jevans, APWG chairman. Although technological solutions are on the horizon, they won't be in place for at least a year, and quite likely not for two or three. In the meantime, there are measures CIOs can put in place to staunch the billions of dollars in potential losses to their customers and companies. Here's a look at the current state of phishing, why it's such a serious threat to e-commerce and what companies on the front lines are doing to minimize the risk to their customers and brands.

Market Place
 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
  • +

    CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00

    Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00

    Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05

    Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    Cutting Through the Spin of Recent Vulnerability Disclosures 13 October, 2008 10:53:00

    The FUD surrounding the ClickJacking and TCP/IP vulnerabilities has the world seemingly frozen in fear. But once you cut through the spin, the vulnerabilities aren't all that they were made out to be.
    There are a few highly publicised vulnerabilities at the moment which haven't completely been disclosed and which, it is claimed, could threaten the whole Internet as-we-know-it. Only, when the vulnerabilities are finally disclosed, it seems that the whole incident has been somewhat Chicken Little.
  • +

    PCI app security: Who's guarding the data bank? 13 October, 2008 11:09:00

    Compliance strategies for PCI's new application security requirements
    While Willy Sutton never really said it, the truth is that people rob banks because that is where the money is. Today's criminals don't walk into banks with loaded guns and get-away drivers. Rather they connect from a remote location using a browser and are armed with hacking tools and spyware.
  • +

    Data-center security tools to not overlook 10 October, 2008 11:37:00

    With the rise of security suites, it's time to consider some emerging security tools and rethink others
    Protecting a corporate data center is like trying to keep an elephant safe from a swarm of flies. Despite your best efforts, bites happen. As the staples of security -- such as firewalls, antivirus software, spam and spyware filters -- come together in suites of products that allow for sophisticated management, there are other security tools either emerging or worth a rethink.
  • +

    IBM, Secret Service, others study identity/cybercrime issues 09 October, 2008 10:09:00

    Center for Applied Identity Management Research organization teams experts in criminal justice, financial crime, biometrics, cybercrime and cyberdefense, data protection, homeland security and national defense.
    IBM, LexisNexis and the Secret Service are among a group of corporations, government agencies and academic institutions that has formed to study and help solve identity management challenges around cybercrime, terrorism and narcotics trafficking.
  • +

    Strange account management at Amazon 09 October, 2008 09:51:00

    A careless login led to the discovery of some strange ccount management practices at one of the Internet's largest retailers.
    Via the RISKS mailing list comes an interesting tale of poor online account management at a major online retailer. According to Graham Bennett, accounts with Amazon display an odd behaviour that doesn't seem to have attracted much attention in the past.
CIO Webcast Innovation #8 - What are the biggest roadblocks to IT's involvement in innovation at your company?
Watch the latest latest edition of CIO Innovation which is now available for download.
Watch the webcast
Sign up to the CIO Innovation update email


CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper

Web Security SaaS: The Next Generation of Web Security

Discover the latest web security SaaS solutions. Learn how to increase overall security effectiveness and reduce the burden on your IT department. Uncover the security challenges facing SMB environments today and identify the critical elements that can provide you with lower-cost and easier-to-manage web security solutions.