Phishing attacks hook more and more victims

Topics

apwg, plaxo, ebay, phishing

Phishing attacks have increased in quantity and quality over the past two months, according to research published by the Anti-Phishing Working Group on Monday.

Phishing is an Internet scam in which unsuspecting users receive official-looking emails that attempt to fool them into disclosing online passwords, user names and other personal information. Victims are usually persuaded to click on a link in an email that directs them to a doctored version of an organisation's Web site. The APWG was formed in November 2003 to provide a forum for financial institutions and other organisations to share information about phishing attacks.

The APWG's Phishing Attack Trends Report compares the level of phishing activity recorded by the organisation's members on a monthly basis. According to the latest report, February saw 282 new phishing attacks, an increase of 60 percent compared to January and a 163 percent increase over December 2003. There were an average of 10 new attacks reported every day, but the third week of February was the busiest, with an average of 12.5 attacks reported each day.

The financial services sector continues to be the most frequently targeted industry sector, and eBay remains the phisher's favourite individual target.

Dave Jevans, chairman of the APWG and a senior executive at Internet messaging firm Tumbleweed, said phishing attacks are getting more common and more complex: "We are seeing more use of Javascript, pop-ups and cross-site scripting techniques to fool even sophisticated users. At stake is our very trust that the Internet can be relied upon for safe and secure commerce and communications," he said in a statement.

The report said that between 1 percent and 5 percent of recipients responded to recent attacks, which look increasingly official and so are hard to detect.

A classic exploitation of a cross-site vulnerability was demonstrated last week when a security researcher from Lodoga discovered a flaw in contacts management company Plaxo's Web site. Had the error been discovered by phishers, it could have resulted in Plaxo members exposing their personal details.

Jeremy Wood, a security test engineer at Web application security company Lodoga, told ZDNet UK that within an hour of discovering the weakness, he had built an attack script that could exploit the vulnerability. Wood's script added an additional layer over the Plaxo Web site's username and password box; if a user typed in their access details, that information would be transferred to the attacker's Web site.

Rikk Carey, vice president of engineering at Plaxo, said that the Web site was fixed a few hours after the problem was highlighted and he was "fairly certain" that the vulnerability had not been exploited by anyone except Lodoga's security testing.

However, Wood said the cross-site vulnerability was a common problem. "We have been running workshops this month and every client we deal with has the same problem. Developers haven't really realised how robust they have to be in terms of security coding. This is probably the number one problem, and companies really are jeopardising their trade name and potentially their customers' data," he said.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

"xfire: Why is telecommunications being treated different to roads, water and electricity?" Good question, my guess is AUS is far behind...

1 minute ago by ngoctranminh on Five pros and cons of the NBN

“@zdnetaustralia: Is Windows Phone really the third challenger to Android and iOS? http://t.co/Tr7ASra0 ”. It's different but fast and good

Can HP bounce back? http://t.co/TSlWjmrA

Thanks for the response Luke, Given that the quotes are accurate, then the person in charge of the Vic Health App needs to find another j...

12 minutes ago by butterflyeffecs on Android fragmentation steers Vic Health

Social business in Australia http://t.co/aBuXFy40 . Australian businesses still laging behind with social business. Time to catch up!

Can Windows Phone bring a new challenge? #WindowsPhone http://t.co/m82nU7hK

Nice analogy. Another factor is whether you can find 50 people with powerful enough weapons. Minassian's argument is essentially that the...

22 minutes ago by Mukimu on National Botnet Network coming: Earthwave

RT @digitaltasmania: @ZDNetAustralia #NBN's Tassie upgrade to cost $1.3m http://t.co/1nTbLUJv -Countdown begins for 1st Oppn. MP to misconstrue per unit cost

@ZDNetAustralia #NBN's Tassie upgrade to cost $1.3m http://t.co/1nTbLUJv -Countdown begins for 1st Oppn. MP to misconstrue per unit cost

RT @mosfreshmedia: Start-up accelerator targets cleantech 'Atlassians, BigCommerce' via @zdnetaustralia http://t.co/oho3oQSK @atpinnovations @hamishhawthorn

Can #HP bounce back?: HP's move to cut 27,000 jobs, reinvest in research and development (R&D) and generally get... http://t.co/dlgAhwxb

Can HP bounce back? http://t.co/qLlHB5FV

It's nice to see Tas finally get some decent internet connectivity, for too long Tas has been stooged on decent internet connectivity but...

43 minutes ago by Jingles on NBN's Tassie upgrade to cost $1.3 million

Cloud inefficiency - Bad habits are hard to break: Cloud can save you a lot of money - if you use it effectively... http://t.co/oVoNx2na

by http://t.co/vmlLt4bh: Can HP bounce back?: HP's move to cut 27,000 jobs, reinvest in research and development ... http://t.co/EjWWU9O1

Can HP bounce back?: HP's move to cut 27,000 jobs, reinvest in research and development (R&D) and generally get ... http://t.co/KDGewBVH

Can HP bounce back?: HP's move to cut 27,000 jobs, reinvest in research and development (R&D) and generally get ... http://t.co/y2ajlh9V

Three tips for businesses to support connected customers: While the connected home offers benefits to the consum... http://t.co/psgHJelD

#Agedcare 30 servers to 7: BUPA redoes virtualisation: Most IT teams spend 90 per cent of today making sure that... http://t.co/HmVXHRQ7

[plug] #NBN cost-benefit analyses are so 2011 http://t.co/2mRUKI8G @TurnbullMalcolm has forgotten his CBA; sh/would he still do one? #zdnet

Can HP bounce back? http://t.co/LlAUcyYP

Who is Luke Hartsuyker? He must be the Apprentice FUDster. As PaulPC has already said regional consumers want, deserve and are entitled...

1 hour ago by dickster on Regional review highlights NBN, mobile

Three tips for businesses to support connected customers http://t.co/W7Sr3RpD

by http://t.co/vmlLt4bh: Did RIM shelve plans to license BBM?: Research In Motion (RIM) had considered licensing ... http://t.co/z6VlO472

Did RIM shelve plans to license BBM? - ZDNet Australia http://t.co/j042NNOM

Did RIM shelve plans to license BBM? - ZDNet Australia http://t.co/qMNEifi1

Its good to see the NBN keeping up with the latest equipement & letting the people benefit from it. After all thats why it was a trial, ...

1 hour ago by fibretech on NBN's Tassie upgrade to cost $1.3 million

#Google TV will revolutionize television once viewers understand it http://t.co/Pmie5zEC http://t.co/2GN4qz9j http://t.co/j3wf6jEF

RT @zdnetaustralia: NBN Co will spend $1.3 million upgrading some 700 network terminating units in Tasmania. http://t.co/6GWYMcZQ

Did RIM shelve plans to license BBM?: Research In Motion (RIM) had considered licensing BlackBerry Messenger (BB... http://t.co/G13GBXl4

Did RIM shelve plans to license BBM? http://t.co/KKPZVPOr

Did RIM shelve plans to license BBM? http://t.co/1AutUH8l

Are college students dependent on technology? http://t.co/4p3v9PZ9 via @ZDNet

30 servers to 7: BUPA redoes virtualisation http://t.co/dOR009Te

Govt urges telcos to team up against NBN Co http://t.co/Sn7pMhew

NBN's Tassie upgrade to cost $1.3 million http://t.co/iDlBr20I

Govt urges telcos to team up against NBN Co: The Department of Broadband, Communications and the Di... http://t.co/YVVOyRWA #suretelecom

by http://t.co/vmlLt4bh: NBN's Tassie upgrade to cost $1.3 million: NBN Co will spend $1.3 million on replacing o... http://t.co/FwL9gNKF

NBN's Tassie upgrade to cost $1.3 million: NBN Co will spend $1.3 million on replacing outdated network technolo... http://t.co/sIP3aI5l

RT @zdnetaustralia: Google found itself embroiled in a vicious tax debate this week. Serves it right? http://t.co/Ga14Yg6x ^ST

NBN's Tassie upgrade to cost $1.3 million: NBN Co will spend $1.3 million on replacing outdated network technolo... http://t.co/JYdFJbxj

Shadow Minister for Regional Communications Luke Hartsuyker has got it wrong. Regional consumers want improved mobile services AND the NB...

2 hours ago by PaulPC on Regional review highlights NBN, mobile

Just remember that Google haven't broken any laws here, they're just doing what all their other multinational competitiors do; minimise t...

2 hours ago by Pachanga on Much ado about Google's tax

ルイヴィトン バッグ : http://www.lovebagjp.com/ Louis Vuitton bags, Louis Vuitton pretension nose about,Louis Vuitton daydre...

3 hours ago by bundLourb on Reservoir blogs: Fan fakes Tarantino diary

シャネル バッグ : http://www.bagssalejp.org/ Chanel trap,chanel shekels,gucci bags,direct purse,poor recent Louis Vuitton keep...

5 hours ago by bybrinkLync on Reservoir blogs: Fan fakes Tarantino diary

I guess but in both cases, dead body!

14 hours ago by Doubt on National Botnet Network coming: Earthwave

I think it's for the very reasons you mention in your first paragraph that there is no CBA. With the ideological differences and vested ...

15 hours ago by RealismBias on NBN cost-benefit analyses are so 2011

Good points; but how do you establish consensus about the terms of reference of a cost-benefit analysis? What is to be included? How far ...

15 hours ago by Gwyntaglaw on NBN cost-benefit analyses are so 2011

I live in a small country town & have done since 2002. When I got to this town it had no mobile phone & no broadband. The only reason w...

16 hours ago by fibretech on Regional review highlights NBN, mobile

Hi there, just became alert to your blog through Google, and found that it is really informative. I am going to watch out for brussels. I...

16 hours ago by Uttedsips on Fujitsu Stylistic ST5011

Like most things in life, the devil is in the details. If a cost benefit analysis included a societal element, I'm certain nobody on eit...

16 hours ago by RealismBias on NBN cost-benefit analyses are so 2011

The coalition has done nothing else but keep changing their view over the last 2 years. -first it was "there is nothing wrong with the ...

17 hours ago by djz on NBN cost-benefit analyses are so 2011

Use the force Luke... FFS

17 hours ago by Beta on Regional review highlights NBN, mobile

michael kors outlet http://www.michael-kors-discount.com/#5923

17 hours ago by michael kors bag on Best iPhone travel apps

Hey butterflyeffecs and lex, Sorry you're not fans of this piece. But you're dead right in that it is the thoughts and experience of a se...

17 hours ago by LHopewell on Android fragmentation steers Vic Health

This story has been voted 12000 times in the last 24 hours!

20 hours ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

2 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

2 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar