'Spear-Phishing,' Risky Behavior and Poor Protections To Blame
By Tracy Kitten
What's on tap for fraud in 2011? Quite a bit, unfortunately. The list of schemes and trends hasn't shortened from 2010.
The good news: most banking/security leaders are more aware of the risk management and security items they need to check off their to-do lists.
One area where they will inevitably spend investment dollars and time relates to the fight against phishing. Like most fraud, phishing attacks are increasing in number and sophistication. Banks know these are a problem, but fighting back is becoming increasingly difficult.
According to our own research, phishing and vishing rank among the top three fraud threats banks and credit unions currently face. About half of the respondents to our Faces of Fraud Survey say phishing and vishing are major concerns. Interestingly, only 20 percent say they feel prepped to fight and prevent those attacks against their customers and brands.
Part of the concern stems from emerging channels, such as mobile, which are more often used to access online banking.
To read the entire article, click here - http://blogs.bankinfosecurity.com/posts.php?postID=855&rf=2011-01-18-eb
Showing posts with label vishing. Show all posts
Showing posts with label vishing. Show all posts
Wednesday, January 19, 2011
Phishing Attacks Pose Heightened Threat
Saturday, November 13, 2010
Phishing Attacks On The Rise
Global Effort is Only Way to Fight Threat to Banking Customers
Tracy Kitten, Managing Editor
A recent rash of targeted phishing schemes -- which included hits to military accountholders and their families at USAA and Navy Federal Credit Union, as well as a separate attack on officials at the World Bank -- has again brought the crime to the fore.
It's just the latest spree in a long line of phishing and vishing attacks that have grown to be more selective in their approaches, using malicious e-mails or phone calls that send unsuspecting users to spoofed websites, where malware hijacks banking credentials.
The schemes are more targeted than they were 18 months ago, says John Buzzard, client relations manager for FICO, which provides decision management and predictive analytics solutions. Those targeted launches, which hit customers and members at specific financial institutions, often reap more rewards for the fraudsters.
"For the criminal, you get more out of targeting a specific institution, because a lot of these folks are not used to getting scammed," Buzzard says. "Oftentimes, they are targeting people who are not quite so savvy and don't have a lot of experience with the Internet and banking online."
In the USAA and Navy FCU cases, Buzzard says, targeting military families has proven profitable. "It's not that military members and their spouses are less savvy; but when you have one parent overseas fighting and the other at home taking care of all of the finances, they can be stressed and distracted and may not be paying so much attention," he says. "Stressed-out military spouses are juggling many things, and they could be in a hurry to respond to something without thinking about it thoroughly."
To read the entire article, click here - http://www.bankinfosecurity.com/articles.php?art_id=3080&rf=2010-11-13-eb
Tracy Kitten, Managing Editor
A recent rash of targeted phishing schemes -- which included hits to military accountholders and their families at USAA and Navy Federal Credit Union, as well as a separate attack on officials at the World Bank -- has again brought the crime to the fore.
It's just the latest spree in a long line of phishing and vishing attacks that have grown to be more selective in their approaches, using malicious e-mails or phone calls that send unsuspecting users to spoofed websites, where malware hijacks banking credentials.
The schemes are more targeted than they were 18 months ago, says John Buzzard, client relations manager for FICO, which provides decision management and predictive analytics solutions. Those targeted launches, which hit customers and members at specific financial institutions, often reap more rewards for the fraudsters.
"For the criminal, you get more out of targeting a specific institution, because a lot of these folks are not used to getting scammed," Buzzard says. "Oftentimes, they are targeting people who are not quite so savvy and don't have a lot of experience with the Internet and banking online."
In the USAA and Navy FCU cases, Buzzard says, targeting military families has proven profitable. "It's not that military members and their spouses are less savvy; but when you have one parent overseas fighting and the other at home taking care of all of the finances, they can be stressed and distracted and may not be paying so much attention," he says. "Stressed-out military spouses are juggling many things, and they could be in a hurry to respond to something without thinking about it thoroughly."
To read the entire article, click here - http://www.bankinfosecurity.com/articles.php?art_id=3080&rf=2010-11-13-eb
Tuesday, October 26, 2010
ID Theft: SARs On The Rise
Identity Theft Reports Jump; Most Attributed to Family
Tracy Kitten, Managing Editor
The majority of identity theft incidents reported by U.S. financial institutions don't relate to phishing attacks and spoofed website pages. According to a new ID theft report from the Financial Crimes Enforcement Network, most cases of ID theft are linked to a victim's family members or coworkers.
John Summers, a project officer at FinCEN and a lead in FinCEN's report, "Identity Theft: Trends, Patterns and Typologies Reported in Suspicious Activity Reports", says ID theft perpetrated by family, friends and business partners ranked No.1 among SARs filed by U.S. depository institutions in 2009. "In 27.5 percent of the filings, this was the highest," he says. "It basically means someone close to them was getting access to their files and using their information."
Summers says only 3.5 percent of the ID theft incidents reported in SARs related to computer viruses and Trojans, such as Zeus. For vishing and phishing, the incidents reported were even fewer. "The only ones I found were in new data, and it would only come out to .15 percent," he says. "That does not mean those types of attacks did not occur and account for theft and losses. It just means that the victim was not aware and did not report it as a phishing (or vishing) attack."
To read the entire article, click here - http://www.bankinfosecurity.com/articles.php?art_id=3031&rf=2010-10-26-eb
Tracy Kitten, Managing Editor
The majority of identity theft incidents reported by U.S. financial institutions don't relate to phishing attacks and spoofed website pages. According to a new ID theft report from the Financial Crimes Enforcement Network, most cases of ID theft are linked to a victim's family members or coworkers.
John Summers, a project officer at FinCEN and a lead in FinCEN's report, "Identity Theft: Trends, Patterns and Typologies Reported in Suspicious Activity Reports", says ID theft perpetrated by family, friends and business partners ranked No.1 among SARs filed by U.S. depository institutions in 2009. "In 27.5 percent of the filings, this was the highest," he says. "It basically means someone close to them was getting access to their files and using their information."
Summers says only 3.5 percent of the ID theft incidents reported in SARs related to computer viruses and Trojans, such as Zeus. For vishing and phishing, the incidents reported were even fewer. "The only ones I found were in new data, and it would only come out to .15 percent," he says. "That does not mean those types of attacks did not occur and account for theft and losses. It just means that the victim was not aware and did not report it as a phishing (or vishing) attack."
To read the entire article, click here - http://www.bankinfosecurity.com/articles.php?art_id=3031&rf=2010-10-26-eb
Tuesday, September 14, 2010
Vishing Scam Hits FDIC
Analysts Say Socially Engineered Schemes on the Rise
By Tracy Kitten, Managing Editor
Telephone-based phishing, or vishing scams are quickly ranking among the most popular socially-engineered schemes perpetrated by fraudsters. The latest target: The Federal Deposit Insurance Corp., which last week warned of a vishing scam that is duping consumers.
According to the FDIC's statement, the criminals behind the vishing calls allegedly told consumers they were delinquent in loan payments that had been applied for over the Internet or made through a payday lender. The loans may or may have not even existed, giving the vishers opportunity to collect personal information to confirm the authenticity of the loans. Recipients of the calls said the vishers requested everything from Social Security numbers to dates of birth.
To read the entire article, click here - http://www.bankinfosecurity.com/articles.php?art_id=2911&rf=2010-09-14-eb
By Tracy Kitten, Managing Editor
Telephone-based phishing, or vishing scams are quickly ranking among the most popular socially-engineered schemes perpetrated by fraudsters. The latest target: The Federal Deposit Insurance Corp., which last week warned of a vishing scam that is duping consumers.
According to the FDIC's statement, the criminals behind the vishing calls allegedly told consumers they were delinquent in loan payments that had been applied for over the Internet or made through a payday lender. The loans may or may have not even existed, giving the vishers opportunity to collect personal information to confirm the authenticity of the loans. Recipients of the calls said the vishers requested everything from Social Security numbers to dates of birth.
To read the entire article, click here - http://www.bankinfosecurity.com/articles.php?art_id=2911&rf=2010-09-14-eb
Labels:
FDIC,
fraud,
identity theft,
phishing,
small business,
vishing
Subscribe to:
Posts (Atom)
Do Do You Keep Your Career Options Open?
OSBW Blog Archive
- January (1)
- October (3)
- September (1)
- March (2)
- December (1)
- November (1)
- October (4)
- August (1)
- March (2)
- February (1)
- January (3)
- December (13)
- November (11)
- July (2)
- March (2)
- February (1)
- January (2)
- December (7)
- November (9)
- October (17)
- September (11)
- August (5)
- July (15)
- May (3)
- April (7)
- March (23)
