Published on Security Management (http://www.securitymanagement.com)
Cyberthieves Phishing for Cash
By Laura Spadanuta, Assistant Editor
Created 02/14/2008 - 10:52



    
Wrap-Up?: 
No
Weight: 
0
Lead Headline?: 
No
Date: 
02/14/2008
By Line: 
By Laura Spadanuta, Assistant Editor
Teaser: 

Bank accounts are a major target of cyberthieves who use "phishing" tactics to steal customers' money and tap into bank accounts.

CNN has an article [1] that details the tactics taken by cyberthieves to steal money out of bank accounts. The tool of their trade is phishing, which is when they send fraudulent e-mails to obtain sensitive information that can then be used to access bank accounts.

An example are e-mails that appear to be legitimately from a bank and often have warnings about account security or messages about accounts being locked.  The e-mail will then ask an individual to log-in from a link in the e-mail, and that false log-in site will capture account information such as account number and password.

The article highlights an even more complicated form of phishing:  a malware that facilitates hacking of server settings.

For example, a user types www.bankofamerica.com [2] into his or her browser. But instead of the computer using the service provider's server, which would take the user to the real Bank of America server, the computer uses a bogus server run by phishers -- and that takes the user to a fake Bank of America server.

The phishers take the user's login information and empty the account.

An IBM Internet Security Systems X-Force survey shows that banking industry companies made up 19 of the 20 companies targeting by phishing in 2007.

The article advises that it might be worth keeping a paper trail of the bank account.  It cites criminals in Brazil who have been able to wipe out entire accounts and leave no trail behind. 

 

Related Resources: 

Comments


Security Management is the award-winning publication of ASIS International, the preeminent international
organization for security professionals, with more than 35,000 members worldwide.

ASIS International, Inc. Worldwide Headquarters USA, 1625 Prince Street, Alexandria, Virginia 22314-2818
703-519-6200 | fax 703-519-6299 | www.asisonline.org
ASIS
Copyright © 2008, Security Management

Powered by: Phase2 Technology

Source URL: http://www.securitymanagement.com/news/cyberthieves-phishing-cash

Links:
[1] http://edition.cnn.com/2008/TECH/02/12/cyber.thieves/
[2] http://www.bankofamerica.com