Fishing for 'phishers'

The Anti-Phishing Working Group is arguing that emerging e-mail authentication standards could take the sting out of "phishing" attacks.

According to new research carried out by the group almost 95 percent of e-mail fraud and "phishing" reported in May emanated from forged addresses.

Phishing attacks trick people into parting with personal information by luring them to bogus corporate Web sites. Almost 5 percent of recipients of such deceitful e-mails disclosed vital information such as credit card numbers, account user names and passwords, leading to identity theft and financial loss, the report said. The past few months saw phishing e-mails emerging as a major threat.

The study, however, conducted by the Anti-Phishing Working Group with technical help from Tumbleweed Communications, showed there was only a 6 percent increase in new phishing attacks last month. May witnessed 1,197 new cases, compared with 1,125 unique attacks in April. Of the new attacks, 848 targeted the financial services sector.

"One Achilles' heel of phishing, and other related e-mail threats like spam and viruses, is the reliance on forged 'from' addresses to hide the sender's identity," APWG Chairman Dave Jevans said in a statement.

Despite varying specifications, several evolving technologies designed to provide verification of an e-mail sender's identity can prevent such fraudulent mails from reaching customers.

Several top Internet providers, including Yahoo, Microsoft, EarthLink, America Online, British Telecom and Comcast, formed an alliance last week to push for new technical guidelines to fight spam mails. EarthLink is already working on putting antiphisher software in place.

Like this article? Click below to send it to your mobile for free!

Advertisement

Talkback 0 comments


ZDNet's CIO Vision Series

Video | Optus CIO Lawrie Turner

In this exclusive video interview, Optus chief information officer Lawrie Turner speaks to ZDNet.com.au about being the IT head for Australia's number two telco.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay BarCamp buzz: Let the hacking continue
    Attending last weekend's BarCamp in Sydney, it was hard to escape the conclusion that a certain "dot-com bust" flavour had seeped into the kool aid previously being drunk by Australia's web 2.0 and early stage start-up sector.
  • Array NBN needs workers on board
    Without consensus on labour issues, the eventual winner of the NBN may end up as little more than a lame duck and a cashed-up symbol of the conflict between the desire for progress and the lack of mechanisms to deliver it.
  • Array D'Ascenzo: Read p23 of security review
    Following yesterday's admission by the Australian Taxation Office that its courier had lost a CD containing the details of 3,000 self-managed super funds, it wants to review how it handles information. My suggestion: go back to the review completed in April.
  • More blogs »

Tags

Back to top

Featured