There has been a significant increase in the number of phishing scams being targeted to trick Apple users, around the globe, revealed a recent study from security vendor Kaspersky Lab.
According to the study, cybercriminals are using the fake Apple sites to trick users into submitting their Apple ID credentials, to steal the users’ account login and access the victim’s personal data, information and credit card numbers stored on their iCloud and iTunes accounts.
It is significant to note that the cybercriminals increase their phishing attempts whenever there is a big Apple event or announcement. For instance, on December 6, 2012, immediately after the Apple’s announcement to open the iTunes stores in India, Turkey, Russia, South Africa and an additional 52 countries, Kaspersky Lab detected an all-time record of more than 900,000 phishing attempts by fake Apple sites in a single day.
A case in point is that of New Delhi based businessman Amit Pahal, has been tracked by Light Reading India, who was apparently tricked by a US-based cyber criminal. Pahal had bought an iPad and was trying to sync his device with iTunes through Apple store. He was trapped by an almost identical mail with Apple, and ended up losing INR 30,000 to fraudsters.
“It [Apple store] asked me to furnish the personal data and credit card details for renewal, which I did. However, immediately after that I got a security alert in my mailbox saying that my Apple ID had been disabled for security reasons as someone just tried to sign in through another IP address. The mail asked me to confirm my identity by clicking on the link or else my account will be re-set. That’s a normal practice from Apple to verify users’ credentials and moreover it gave the impression of being a legitimate email, which I found to be malicious later,” explains Pahal.
Once Pahal clicked the malicious link, he was again asked to submit his personal and credit card details to activate the account. And within a week of this submission, he was informed by his bank of two back–to-back online shopping transactions— INR 11,000 and INR 19,000, happened using his ICICI bank credit card in USA. According to the experts, these emails are deceivingly clever and professionally designed in order to make them appear authentic.
“It was shocking. Within few hours I reported the fraud to the bank [ICICI] and blocked my card. The bank, however shared the inability to track the transactions and help me find culprits. Even when I reported to Police they had no idea how to trace this without bank’s support and what to do. After my failed battle which lasted several days, I decided not to pursue the matter further as it was impacting my business hours”
The case also signifies the lack of training skills to track cyber crimes in the country and ill-preparedness of banks to collaborate with banks and resolve such issues quickly
In order to guard against such crimes, the onus is on users to use effective security solutions and verify e-mail address by checking the original sender address.
“On a computer this can be done by mousing over the sender address field, which reveals the sender alias’ true email address. When using a mobile device, users should touch the email alias from the sender, which expands the alias to show the full address of the sender,” Kaspersky notes.
There is also a two-step authentication process being provided by Apple for its users to guard against fraudsters. The process includes sending a four digit code to one or more devices, used earlier by the same users.
—Jatinder Singh, Principal Correspondent, Light Reading India
