My Photo

Adsense


Add to Google Reader or Homepage

Subscribe in Bloglines

Subscribe in one go

  • Subscribe to RSS Feed

Your email address:


Powered by FeedBlitz

Google reader

Software worth checking out

  • ActiveWords
    Do everything without leaving the keyboard
  • Anagram
    Translates copied text into Contact, Calendar, Task, and Note items for Outlook, Palm etc
  • BlogJet
    Weblog client for Windows that allows you to manage your blog without opening a browser.
  • ConnectedText
    Intriguing Wiki-based organiser
  • Copernic Desktop Search
    Great alternative to Google's or Microsoft's offering for searching your PC. Simple and unobtrusive
  • Courier Email
    Great email program
  • DtSearch
    Text Retrieval / Full Text Search Engine
  • ExplorerPlus
    Organize and manage all your system files and folders
  • Gmail
    Webmail that really works. Great for catching spam too.
  • Google Deskbar
    Search with Google from any application without lifting your fingers from the keyboard.
  • Google Earth
    Zip around the planet and see things differently
  • Google Reader
    Best online RSS reader I think there is out there
  • Google Talk
    Chat online and make free internet calls
  • Jot+
    store all of your notes and information in an easy-to-use outline
  • Mindjet
    The mindmapper of choice.
  • MSGTAG - MessageTag
    Email receipt alert
  • MyInfo
    free-form information organizer
  • NoteTab
    Great text and HTML editor
  • PersonalBrain
    If you've ever wanted to organise your information in a way that's different, try this. Worth spending time on mastering
  • Process Explorer
    Not too geeky way to figure out what software is slowing down your computer. Just keep it running for a while and the culprit will become obvious.
  • Safari
    Surprisingly fast browser -- and for Windows too.
  • Skype
    Dump those phone bills
  • SpaceMonger
    Keep track of the free space on your computer via treemaps
  • Stick
    Post-It note-like tabs to store text, folders etc that cling to the edge of your screen
  • SuperNotecard
    Great for authors and writers organizing their thoughts
  • TaskTracker
    Lists recent documents by type for easy access
  • Text Monkey
    Easily clean copied text
  • Trillian IM Clients
    Gathers all your instant messaging accounts in one window
  • UltraMon
    Increase productivity and unlock the full potential of multiple monitors.
  • Vyooh DiskView
    Visually see disk space usage in Windows Explorer
Blog Widget by LinkWithin

« The Skype Marketplace Gets A Dating Service | Main | Amazon's Popup Storefront »

June 12, 2005

Phishing Gets Smaller, Smarter

It’s intriguing how phishers are targeting smaller and smaller groups. Not only does it indicate that the bigger banks and institutions are becoming more secure (or their customers smarter) but it indicates that the phishers must be employing increasingly sophisticated methods of harvesting email addresses. Or is there something else afoot?

The Bakersfield Californian yesterday reported an attack on the Kern Schools Federal Credit Union which has, according to its website, 140,000 members and 10 branch offices. That’s actually not a lot of people to target, in spamming terms. Still, up to 25 members got the email and reported it to the union. One must assume many more received it and didn’t report it. The Bakersfield paper went on to say:

As large financial organizations become better at fighting off such phishing attacks, scammers seem to be targeting smaller regional banks and credit unions. Smart phishers are finding sources of e-mail addresses and using them to get in touch with bank customers. "They're figuring out how to beat the probabilities of targeting people," said Peter Cassidy, secretary general of The Anti-Phishing Working Group. "I guess this is the same discipline that marketers use."

In many cases, that's meant targeting people whose e-mail address is public. "In the past, phishers used to go after mainstream consumer Web sites with millions of users, but now the targets are becoming much smaller and more localized," Dan Hubbard, senior director of security and technology research at online security firm Websense Inc., said in a statement.

An interesting feature of this chapter in the phishing saga. My guess is that these attacks are from quite different gangs than the original East European/ex Soviet groups that started all this. But I could be wrong. But here’s a thought: Could the customer data have been gathered from a data security breach? Clearly these breaches are a growing worry for financial institutions of any size, as high profile cases have illustrated. Indeed, last December Kern hired a company called Ingrian to secure its members’ data:

“As we looked at the NCUA legislation and the ongoing incidence of security breaches taking place, we decided that it made sense to augment our existing security capabilities by implementing encryption inside our enterprise,” explained David DuBose, vice president, information technology, Kern Schools Federal Credit Union. “After evaluating the alternatives available, we became convinced that Ingrian’s approach—providing a centralized appliance that intelligently manages encryption, keys, and policies—gave us the most secure and most cost-effective way to protect sensitive data.”

i think perhaps it’s time for banks to look proactively at how many of its customers are getting targeted and see whether there is a correlation with missing data (the Privacy Rights Clearing House counts nearly 10 million people — Americans, I assume — whose data has been stolen or otherwise compromised this year.) If there is any correlation between phishing attacks and stolen data, then perhaps banks and other institutions need to be more proactive in warning customers, rather than just posting tardy warnings or warning ‘brochures’ that are in a format (PDF) many customers won’t know how to open and way too big (3+MB) for anyone not on broadband to download.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8341c5af153ef00d8344910e553ef

Listed below are links to weblogs that reference Phishing Gets Smaller, Smarter:

Comments

PDF is a relatively standard format; most modern computers come with the free Adobe Acrobat Reader pre-installed. Also, the same "Consumer Alert" page (http://www.ksfcu.org/default.asp?fileID=185) that links to the phishing PDF has a link to the FDIC at the top of the page (http://www.fdic.gov/news/news/SpecialAlert/2005/sa1105.html), which provides its information in HTML.

Considering that the majority of the phishing emails I receive are for small banks which I have never heard of, I do not think most phishers are currently attempting to use such strict targeting methods. I would not be surprised, however, if such an occurrence became more commonplace in the future.

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Loose Wire search

Eco-Safe

Rank

  • Wikio - Top Blogs - Technology
Blog powered by TypePad
Member since 12/2003

Facebook

ten mov.es

tenminut.es