As big companies like eBay and Target bolster their defenses following attacks from hackers, experts say that cybercriminals are also targeting other e-commerce and retail firms that could be vulnerable to phishing attacks intended to steal credit-card and other personal data.
The targets include China’s largest e-commerce company, Alibaba, which is preparing to launch a U.S. IPO soon.
The Anti-Phishing Working Group (APWG) — an industry, law-enforcement and government trade coalition — said in a May report that phishing rose in the second half of 2013.
An officer points at fraudulent credit cards confiscated after an arrest tied to December’s Target credit-card breach. AP View Enlarged Image
Phishers try to acquire personal data such as usernames, passwords and credit-card details by pretending to be a trustworthy entity in electronic communications such as emails. They often register for a legitimate-sounding domain name in attempts to make the emails they send appear aboveboard.
“Phishers appear to be looking for companies that are newly popular, have vulnerable user bases and/or are not ready to defend themselves against phishing,” Greg Aaron, a co-author of the APWG report, told IBD. “From the results of our latest survey, it is obvious that most any enterprise with an online presence can be a phishing target.”
The trend is recognized by other cybersecurity experts.
“The attackers look for any weak link in any type of industry or sector,” David Burg, global and U.S. advisory cybersecurity leader of PricewaterhouseCoopers (PwC), told IBD.
Burg says that financial-services firms are other frequent targets. He says that “hacker attack groups” have recently switched from targeting U.S. financial companies with relatively strong cyber-defenses to more vulnerable companies overseas.
Attacking New Targets
APWG points to a rise in the number of new phishing attacks against retailers in the second half of 2013. The group’s “Global Phishing Survey” study says that in the second half of last year, 324 of the 681 retailers and brands hit by phishing attacks had not been targets in the first half. APWG says that’s an unusual number of new targets and shows that phishers are trying out new targets at an an accelerated rate.
The victims of phishing attacks tracked by APWG in the second half of 2013 included U.S. firms as well as Chinese and other foreign companies.
Taobao, Alibaba’s e-commerce unit, was the second-most targeted institution, with 19,290 phishing attacks, the study found. EBay‘s (NASDAQ:EBAY) PayPal payments unit was the most targeted, with 24,580 attacks.
Other U.S. targets included Home Depot (NYSE:HD), jeweler Tiffany (NYSE:TIF) and Hertz Global Holdings‘ (NYSE:HTZ) Hertz Rent-a-Car.
