WIRE OPENAn archive editionSEARCHARCHIVERSS
EST. 2000
UKTECH
THE IT-CONTRACTING & TAX RECORD
LATEST

Confidence tricksters catch surfers hook, line and sinker

More web users than ever before are succumbing to the exploits of online fraudsters who, as recent examples show, are using ever more devious methods to fleece their victims.

Just last week, an email attempting to trick Australian online-banking customers into divulging their details was labelled "the most devious example" yet to be seen.

An email, distributed en-masse to customers of Australia's Westpac Bank, represents the latest example of a "phishing scam" - designed to catch the unwary and fool them into divulging their online-banking security details.

Typically, phishing scam emails appear to have been sent from the victim's bank, and contain a link to a fake version of the bank's website and instructions on how to log on to verify their banking credentials.

With the "Westpac" email to customers, fraudsters used wording including: "Westpac will never ask for your personal or login details by email" - even though it then directed readers to do exactly that.

The architects of the email then included a link directing victims to a fake version of the site which simultaneously opened up an authentic copy of the bank's website in another browser window behind it.

The fake version of the site asked for the victim's account access details but then returned an error message when they attempted to use it.

Victims were then sent to the bank's real website completely unaware that they had been duped. Meanwhile, the fraudsters were in their accounts transferring their savings to various locations around the world.

Rob Forsyth, an antivirus writer, says the new techniques used by online confidence tricksters in the Westpac email episode indicate a new level of sophistication in the war on phishing.

He says he wants to see tough new laws brought in to deal with this relatively new type of e-criminal, as existing rules do not seek to properly punish them.

"I think this is not just a scam like the Nigerian scam," he says. "This is actually direct fraud and the perpetrators of the crime should be dealt with severely."

Andreas Baumhof, chief technical officer of Microdasys, a German-based internet security company specialising in Secure Socket Layer (SSL) technologies used to protect commercial web transactions, expressed concern for the wellbeing of online-banking customers.

He says that advice given to the public is often wrong, pointing to a recent high-profile case of phishing in the US involving the ISP, Earthlink.

"Shortly before the scam, the US Federal Trade Commission advised the public to look for an icon depicting a lock in the window of their browsers when conducting sensitive transactions," he said.

"The lock icon is associated with SSL web security technology which involves encryption and security certificates. The FTC's issued blanket advice that such communications were definitively safe," he added.

Baumhof said this advice was patently wrong and may actually have contributed to the flurry of fleecing Earthlink users suffered shortly afterwards.

In that case the scam's designers used encrypted SSL connections to direct users to their site, incorporating fraudulent certificates to persuade victims they were in the right place.

As phishing scams proliferate, more companies are sharpening technological tools to counter them.

Education alone, many agree, isn't enough.

Anti-phishing software is soon to be added to the arsenal of digital shields forged to stop spam, viruses and hacking.

Security companies are also building tools for banks and merchants to use behind the scenes.

The Westpac incident last week serves to show how phishing scammers are now copying and pasting web coding from real sites to give their fraudulent messages and the sites they lead to an aura of authenticity.

They register internet addresses that look real, subbing the letter "l" with the numeral "1", for instance.

A few messages even carry adverts to add to the aura of authenticity.

"What used to be a game and a prank has now been recognised as something that can be lucrative and has attracted organised efforts," says Bill Harris, chairman of PassMark Security LLC and former chief executive of PayPal, a frequent phishing target.

The Anti-Phishing Working Group, formed in October by industry and law enforcement, identified 282 new phishing scams in February, up from 176 the previous month.

About 70 per cent have been traced to Eastern Europe or Asia.

The group says no hard numbers are available on monetary losses from phishing, which represents only a sliver of overall fraud.

In March, British police named three financial institutions that had lost £20 million each to internet crime over the past year.

They added the number of "phishing" cases had increased 600 per cent over the same period.

Banks that were hit included Halifax, Barclays, NatWest, Lloyds TSB and HSBC.

Halifax Bank had to shut down its online banking facilities temporarily last October after they were cloned and a "phishing expedition" launched by e-mail directing customers to a fake website.

The scam was traced to Russia.

The greater cost, the Anti-Phishing Working Group says, is in consumer confidence.

Banks might suffer if their customers shun online banking and insist on using more expensive to operate walk in branches.

Some of the companies hit hardest by scammers are now looking to fight back though. eBay is one of them.

In February, the online auctioneer added an Account Guard feature to its toolbar for Microsoft's Internet Explorer browser.

A green light now appears when users are on a site run by eBay or its PayPal subsidiary. The light goes red for known fraudulent sites.

A warning also appears any time users try to enter their eBay or PayPal passwords elsewhere.

Plug-in tools for browsers and e-mail programs are also being drawn up by other firms.

These add-ins will search for the most common phishing techniques, including web addresses that appear on-screen as one thing but have a different site embedded in the link.

But with online fraud techniques evolving faster than phishing watchdogs can monitor, never mind warn web users about, it may be a while before even basic bases can be covered in this field.

END OF ARTICLE ▪ FILED FROM LONDON