Waterloo Region Record
WATERLOO REGION — Another phishing season is upon us.
“It seems to go in waves,” Sgt. Rob Cowan said. “This time of year, it’s starting to pick up again with Christmas coming on.”
So the Waterloo Regional Police fraud branch is dealing with calls — a few this week, Cowan said — about some pretty crafty email “phishing” scams which try to trick residents into handing over personal information.
The emails try to look official. The phishers aim to fool you hook, line and bobber into letting them access your personal accounts or use your identity to land credit.
The most problematic new scam poses as an email from the Canada Revenue Agency.
“It tells people they’ve got a refund,” Cowan said. “They give you a nice oddball amount to make it look realistic. Then they require you to fill out all this personal information.”
Regional police refer those complaints to the Canadian Anti-Fraud Centre, which has been “inundated” by calls on the refund scam.
The Centre’s automated phone message says there is no need to speak to an agent unless you’ve been duped into providing personal information. Otherwise, it advises to simply “stay vigilant” and delete this email or forward the message to info@antifraudcentre.ca.
Phishing has become a major fraud issue via email in recent years. One in 299 emails was a phishing expedition in 2011, according to Symantec Corp.’s Internet Security Threat Report for 2013. In 2012, the phishing rate dropped to one in 414.
But the report says that simply means fraudsters have been shifting their efforts from straight emails to social media, where they can access all your contacts by stealing your passwords. Then, they try to hook friends and contacts into giving up private information.
The number of phishing sites that spoofed social network sites increased 123 per cent in 2012, the report adds.
And those sites aren’t just impersonating the Canada Revenue Agency. They’re also pretending to be your bank. Every year, the phishing hooks look more and more convincing in the hope you might bite hard.
“Phishing has evolved,” said Maura Drew-Lytle, communications director for the Canadian Bankers Association.
“It started off where it was pretty easy to tell. They had spelling mistakes and would just look like a plain text email. Now, some of the emails will have links to the actual bank website. The link they want you to click on takes you somewhere else.”
The bankers association has no stats on phishing, Drew-Lytle said.
Credit card fraud is considered credit card fraud, whether they got your information through a phishing site or by skimming your card.
“Sometimes it results in credit card fraud. Sometimes it results in health-card fraud,” Drew-Lytle said. “It’s hard to quantify it.”
And people might be reluctant to admit they fell prey to phishing.
“Sometimes people will feel silly about it and not tell anyone and just take the losses,” Drew-Lytle said.
The sophisticated new look of phishing scams makes it easier to be duped. The “spoofing” of genuine sites is much more convincing, Cowan said.
“It’s to make things like real, like a TD Canada Trust email or a BMO email,” he said. “What they’re copying and pasting off the web and importing into their email, it kind of legitimizes it. It helps them with their fraud.”
And stopping such fraudulent emails and shutting down their phoney sites is not as simple as shooting phish in a barrel.
“Wouldn’t it be great if it was?” said Cpl. Judy Falbo of the Kitchener detachment of the Royal Canadian Mounted Police.
“I’m sure you know how difficult it is to even know where a site is set up. To track all of that is an enormous undertaking in some cases. You shut one down and the next one pops up. And the next one. And the next one. It’s just a never-ending challenge for law enforcement to keep up with.”
Falbo says the Kitchener office refers all fraud complaints to regional police. Residents are also told to report the incidents to the Canadian Anti-Fraud Centre, as do regional police. The anti-fraud centre is swamped and only wants to speak to you if you gave out information to a phishing scam.
So what else can you do? Don’t get fooled in the first place.
Drew-Lytle offers simple advice.
Many phishing emails are not personalized. If a bank contacts you via email, it likely is personalized. A bank would never email you asking you to verify your online banking password immediately or under pressure of a deadline.
“A lot of it is common sense,” Drew-Lytle said. “If it seems unusual, don’t respond. If you think it is your bank, give them a call. Go into a branch. Do it through one of the traditional ways rather than clicking on anything in the email.”
Phishing season is back. Don’t get hooked for the holidays.
jhicks@therecord.com
