Security specialist Kaspersky Lab said that nearly 30 percent of phishing attacks in 2014 targeted consumers’ financial information, signaling a shift by cybercrooks from banks to payment systems and online shopping websites.
Phishing is an online fraud tactic to trick users into providing personal, private data–such as sign-ons, passwords and other confidential information–by creating fake Web pages that in many cases can look and feel like the real thing.
Kaspersky Lab Launches Cyber Threat Logbook Project
Kaspersky Anti-Virus for Windows Receives vCloud Ready Status
Kaspersky said the results from its recent study, “Financial Cyber-Threats in 2014,” revealed that online phishing criminals used the names of banks known to consumers in about 16 percent of attacks, down about 6 percent from 2013, but increased using well-known online shopping sites by nearly one percent and doubled the number of times payment systems were mentioned to more than 5 percent.
Specifically, banks were mentioned in 29 percent of attacks, payment systems in 11 percent and online shopping sites in 8 percent of attacks, Kaspersky said.
Cybercriminals preferred aiming at data from Visa card owners (31 percent) more than PayPal (30 percent) or American Express (nearly 25 percent), the security vendor said. The number of times online phishing crooks used PayPal in 2014 actually declined by 14 percent compared to 2013, the company said.
Financial phishing on Mac systems occurred in about 48 percent of all instances, an increase of 9.6 percent compared to 2013, Kaspersky reported.
“The rise in financial phishing that we saw in the past has naturally drawn a response from the brands most frequently abused in phishing scams,” said Nadezhda Demidova, Kaspersky web content analyst. “They are beginning to tackle phishing distribution channels, especially email spam, more actively. That leads to a reduction in the levels of phishing that targets some of the larger brands.”
Cybercriminals responded to the increased awareness by name brands, Demidova said, by aiming at new markets, such as websites that sell plane tickets, which used to be an afterthought in phishing scams, she said.
