Posted by: Tiffany Suk Han | June 27, 2009

Phishing: Examples and Its Prevention Methods

Phishing

is a fraudulent attempt, usually made through email, with the intention to steal your personal & valuable information.

Scammers usually send mass emails to many addresses and typically, it will appear to come from a financial institution or an e-commerce provider. Commonly, the email will request that you update your information for one reason or another, and they usually provide a link that you can click on in order to do so.

Look below, the following email pretends to be from Citibank:

Example 1

When proposed link is clicked, the user is taken to the following authentic-looking page:

Example1a

Once on the website, which generally looks and feels much like the valid eCommerce/banking site, the victim is instructed to login to their account and enter sensitive information such as their bank PIN number, their Social Security number, mother’s maiden name, etc.

Here, the scam is proven when the address bar is turned back on using View, Toolbars, Address Bar where the proper address is revealed

Example 1b

Below is another example, where this attack tries to draw a box over the address bar to hide the real address:

Example 2

_____________________________________________________________

No doubt, the best way to protect you from phishing is by learning how to recognize a phish. When you could recognize them, you would not  get trapped by them!

These are the few characteristics of phishing:

Generic greeting

If you don’t see your name, be suspicious.

Forged link

Websites where it is safe to enter personal information begin with “https” — the “s” stands for secure. If you don’t see “https” do not proceed.

Requests personal information

If you receive an email requesting your personal information, it is probably a phishing attempt.

Sense of urgency

Internet criminals want you to provide your personal information NOW. They do this by making you think something has happened that requires you to act fast.

To read more details, visit this

Of course, the easier way would be by installing addons that can help detect phishing scam or  by simply turning on the phishing filter of your browser.

_____________________________________________________________

As we could all see, phishing scams have increased alarmingly day by day. In my opinion, we shouldn’t only stop at preventing phishing scams. Instead, we should all cooperate to take the initiative to report phishing scams so that there wouldn’t be another victim after you. If you received a suspicious email, report it, as an example, by clicking on the “Report as Junk” (or similar) button on your email program.

Always be aware and keep in mind that

phishing

Let’s together make the eCommerce world a better place!


Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

Categories

Follow

Get every new post delivered to your Inbox.