By
Laura Shannon, Financial Mail On Sunday
17:09 EST, 9 March 2013
|
05:29 EST, 10 March 2013
Blamed: Camilla Jackson is one of thousands to have fallen victim to a ‘phishing’ email.
Despite widespread publicity about the dangers of ‘phishing’ – where conmen trick you into revealing financial details – the practice continues to claim thousands of victims.
The con usually involves directing people to a fake website, often via a link in an email, where they are told to enter user names and passwords for accounts. Armed with this information, crooks swiftly drain them of money.
New, more convincing forms of phishing are evolving to keep ahead of the high-profile warnings and campaigns.
Camilla Jackson, 38, from Calne,
Wiltshire, lost £1,500 because of a ‘phishing’ scam involving PayPal,
the online payment company.
She
received an email in December, purportedly from PayPal, asking her to
log on and change her password. She followed the instructions but what
happened next left her panicked.
Camilla,
who runs her own catering business, was emailed by the real PayPal to
say that it had taken £1,500 from her Lloyds business account and paid
it to another PayPal customer. Camilla discovered she had given her
password to a fraudster who had used it to authorise the transfer.
PayPal assures customers on its website that help is readily available to victims of phishing.
However,
Camilla disagrees and felt dismissed when she raised the alarm. She
says: ‘Immediately I was on the phone to PayPal to say this was wrong
but they said it was nothing to do with them and I should have known it
was fraud. It seemed as if they washed their hands of the situation.’
PayPal
says: ‘Like many online banks, shops and services, PayPal can be
targeted by criminals who use fraudulent emails to deceive users. We
will only ever ask a user to enter personal details on our secure
website after they have logged in to their account. We never ask for
details in an email.’
Lloyds
replaced the money, but delays in signing forms prompted it to retract
the refund. Camilla was left confused as she was unfamiliar with the
process.
Endless phone calls and form-filling left the mother-of-three angry and exhausted.
‘I just wanted an answer,’ she says. ‘I was so tired of it all and spent hours on the phone.’
Lloyds told Financial Mail that in these instances it refunds customers immediately but requires further information to verify claims.
Camilla’s refund was withdrawn while the bank was waiting for necessary paperwork to be completed. These were submitted and the bank has now reissued the refund.
Others might not be as lucky. Banks pledge to refund victims of fraud with various online guarantees, but it is not a certainty in every case.
Payment services regulations require banks to refund fraud unless they can prove a customer acted negligently or fraudulently, but what constitutes negligence is a grey area.
Terms and conditions for HSBC customers, for example, stipulate that customers must take all reasonable precautions to keep personal security information secret. This includes never visiting an internet banking site from a link in an email.
DESPERATE JOBSEEKERS ARE TARGETED IN ACCOUNTS SCAM
Fake job adverts calling for ‘money
transfer agents’, or ‘cash flow managers’, are snaring unemployed people
searching for work.
The jobs ostensibly involve applicants’ accounts being used to move money, in exchange for a fee.
Sometimes applicants’ accounts are
robbed. In other cases they are used to move money on behalf of
criminals. In one instance, a job hunter was told she could work from
home, but would have to deposit cheques, which she believed came from
sales she had arranged. More than 45,000 instances of account misuse
were identified last year, according to fraud prevention service CIFAS,
of which many were thought to involve a ‘money mule’.
Victims could face criminal
prosecution and exclusion from the banking system unless it is clear
that they were not wilfully involved.
Hundreds of phishing websites are established every day and each campaign can generate thousands or even millions of emails. Customers of banks and payment services, such as PayPal, are the most common targets.
But it is not just banks that are mimicked. Natural disasters are a trigger for fake charity appeals – exploiting donors’ generosity in the aftermath of a tragedy. Emails appear genuine and can tug on the heart strings. When in doubt, go direct to a known and trusted website instead of using a link in an email.
According to not-for-profit organisation GetSafeOnline the average loss per phishing scam is £247.
Tony Neate, chief executive of the campaigning and advice group, says people should never give out their user names and passwords. Banks and building societies would never ask for these details in an email.
Online users also need to take greater care with the information they display on social sites such as Facebook and Twitter.
Anyone who has been the victim of internet crime should report their experience to Action Fraud.
Visit actionfraud.police.uk or call 0300 123 2040.
Share this article:
The comments below have not been moderated.
-
Newest -
Oldest -
Best rated -
Worst rated
Duhhh. Everyone should know this by now.
Sophie
,
Chester,
10/3/2013 18:27
Report abuse
“A fool and their money are easily parted”
Sudd3r
,
Liverpool, UK,
10/3/2013 14:15
Report abuse
I’ve just red-arrowed everyone who used the word ‘stupid’. We’re not all 15 yr old technophiles.
telboy
,
bedfordshire,
10/3/2013 13:57
Report abuse
Stupid woman. And she was dismayed that she had to fill out paperwork for Lloyds? What did she think was going to happen just phone the bank and say I’ve had £1500 taken can you put it back please? Idiot !
Cmt
,
Croydon,
10/3/2013 12:33
Report abuse
Rule no.1 . A bank will NEVER ask for your personal details in E-Mails. It is set in concrete. It’s simple.Learn it.
Mossie2072
,
Newport,
10/3/2013 12:12
Report abuse
Stupid woman
somewhere
,
Birmingham,
10/3/2013 11:48
Report abuse
Moral of the story, always use your own bookmarks or type the address in manually
Swipe
,
Shropshire,
10/3/2013 11:31
Report abuse
Well how stupid is she?
jay
,
mids,
10/3/2013 08:18
Report abuse
Clicking links in an email is a bit basic. If the banks are going to refund people who do, the money comes from the prudent who don’t.
Cloud 9
,
Persepolis, Bonaire, Sint Eustatius and Saba,
10/3/2013 07:59
Report abuse
Headline should read. Stupid person loses £1500 in internet scam. Why do people click on a link in an email to any financial organisation are they thick !!
Alan
,
South West, United Kingdom,
10/3/2013 06:48
Report abuse
The views expressed in the contents above are those of our users and do not necessarily reflect the views of MailOnline.
