The sheer number of attempts daily is only one reason the problem is so big, but the impact on that individual — or the organization or company they represent — magnifies it so much more.
Teju Herath, assistant professor of information systems with Brock University, outlined the growing problem of cyber fraud Thursday at Grenfell Campus, Memorial University Cyber-Crime Speaker Series. She provided a closeup view at phishing — the attempt to acquire sensitive information such as usernames, passwords and financial details through email by impersonating a trustworthy entity.
So, if 97 per cent of phishing attempts are unsuccessful, why is it such a large issue? Because there are 156 million phishing emails sent worldwide daily.
A certain somebody has died in Africa, send $500 now and receive a large portion of the inheritance. Your bank account has been hacked, click on this link to reset your account — where it asks to provide your account information and password.
Those are just two of the countless examples.
Originally, phishing concentrated on obtaining financial information, said Herath, who is a researcher in the area of information assurance. Now, there are as many attempts to gain personal or business information. This can be as simple as social media account names and passwords. The perpetrators can then use this knowledge to conduct further illegal activity or take down a specific company, she said.
Of the 156 million phishing emails sent daily, 16 million get through filters. Another eight million are opened by recipients. 800,000 click on the link provided, and 80,000 provide the information requested. That provides context into just how big a problem it is.
Sometimes those conducting the crimes use the information immediately, including wiping out bank accounts. Other times, they wait a certain period to lessen suspicion.
Once an identity has been stolen, a person will find out just how big a problem it is. It can take years, and a lot of effort, to regain one’s identity, Herath said.
“People who have fallen for this identity theft called phishing, and you can see the many documentaries, it is a personal agony for them to regain their own identity,” she said.
Phishing has become such a popular form of fraud because of the many forms of convenience to the perpetrator, explained Herath. It has proven to be very difficult to get caught. While many of the emails go undetected, very seldom are they ever reported and technology makes it difficult to charge or persecute the culprit, she said.
It is also easy to execute, according to the researcher. There is no direct contact between the people, the cost to do it is very low, it reaches a large target, and only takes a knowledge of technology, she said.
