On TV.com: ADAM LAMBERT'S A Big Faker
BNET Business Network:
BNET
TechRepublic
ZDNet

March 17th, 2005

Phishing concerns taint legitimate email

Posted by Chris Jablonski @ 1:53 pm

Categories: General, Security

Tags:

Increasingly, people are regarding legitimate transactional e-mails from companies as fraudulent, not just mistaking phishing e-mails as real, according to Jonathan Oliver from MailFrontier. He spoke at Etech this afternoon about phishing attacks and social engineering. A recent study showed 30 percent of respondents incorrectly identified a phishing e-mail as real or real message as a phishing attack. Oliver showed slides of legitimate e-mail from Citibank and Network Solutions that people considered phishing.

Some other disturbing facts: only 9 percent got a 10/10 on a phishing IQ test; 51 million US adults were phished in the last 12 months; there was a 1,126 percent increase in phishing attacks from 12/03 to 6/04; and 5 percent of recipients who receive a phishing e-mail then click on the link.

He then showed how easy it is to set up an attack, and then came up with a figure for the average pay-off–a lucrative $1,200 per victim.

After highlighting some of the activity around corporate phishing (new employees can be targeted by phishers exploiting the Identity Directory Harvest), Oliver touched on methods for identifying a phishing email, which include: identify the sending server; identify links to the fake web server; identify that the e-mail does not originate from who it purports to come from (authentication); identify suspicious content; and identify attempts to exploit browser security holes. But he also showed cases where these don’t always work.

He concluded by saying that security solutions must use multiple techniques to be effective. But while vendors struggle to keep up, those engaged in transactional activities on the Web, such as selling products on eBay, should be on the guard as they are more heavily targeted.

  • Talkback
  • Most Recent of 2 Talkback(s)
Hi
I think that security solutions must use multiple techniques to be effective. But while vendors struggle to keep up, those engaged in transactional activities on the Web, such as selling products on e... (Read the rest)
Posted by: ip_fresh@... Posted on: 03/18/05 You are currently: a Guest | | Terms of Use
Hi  ip_fresh@... | 03/18/05
Hi  ip_fresh@... | 03/18/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More