<!– Sign up for our Newsletters | –>
Sign up for our Newsletters |
Email the Editor |
Print
Email phishing scams have grown more sophisticated since they first began popping up in corporate inboxes in the 1990s. Early phishing emails were relatively easy to detect as they were characterized by poor grammar and spelling. No legitimate business would send an email to customers chockfull of typos.
As email users grew wary of phishing attempts, cybercriminals
have had
to change their tactics and their lures. Today, phishers are churning
out much more convincing and effective emails. Not only are the most
persuasive specimens well-written, they are also often personalized,
addressing the recipient by name. In addition, they replicate the look
and feel of authentic emails from legitimate businesses down to the
fonts, footers, logos and copyright statements those companies use in
electronic correspondence with their customers.
Why criminals keep phishing
The result of these refinements has been an explosion in phishing
attempts. In 2011, approximately one out of every 300 emails
circulating the web was deemed to contain elements indicative of
phishing, according to “The Year in Phishing,” a report from RSA. The
cumulative number of phishing attacks recorded that year was 279,580, a
37 percent increase over 2010, by RSA’s count.
RSA says that phishing attacks are on the rise despite heightened user
awareness in part because they’ve become so easy for cybercriminals to
execute. Malware writers have created automated toolkits that
fraudsters use to easily create and host phishing pages. On average,
every phishing attack nets a $4,500 profit in stolen funds for the
perpetrator, according to RSA.
Because phishing attacks are easier for cybercriminals to produce and
more convincing than ever, RSA predicts even more of them in 2012. To
help you and your end-users determine whether those suspicious emails
in your inboxes are legitimate or phishing scams, CIO.com asked Daniel
Peck, a research scientist with Barracuda Networks, a provider of email
and web security products, to analyze a particularly convincing
specimen allegedly from American Express. We include below a copy of
the email in question, along with Peck’s tips for discerning the
validity of suspicious emails.
This “Fraud Protection Alert” allegedly
from American Express is in
fact a phishing scam.
The above email is an alleged “Fraud Protection Alert” from American
Express. It informs the recipient and would-be cardholder of potential
fraudulent charges on their credit card.
This email is, in fact, a phishing scam, but it’s convincing for a
variety of reasons. For one, it sounds authoritative. Second, the
footer–with its putative links to American Express Customer Service
and the company’s privacy statement–makes it look authentic. The
message at the end of the footer that reads, “Your Cardmember
information is included in the upper-right corner to help you recognize
this as a customer service e-mail from American Express. To learn more
about e-mail security or report a suspicious e-mail, please visit us at
americanexpress.com/phishing,” makes it look even more authentic and is
designed to further confuse the recipient.
Page Navigation 1) Why the bad guys keep using phishing methods. -Page 1
2) 5 tips for sniffing out phishy emails. – Page 2
Next Page
Back
