You are here: silicon.com > Software > Malware

Malware

Bank phishing fraudsters learn to spell

RSA Conference: The scammers' path from broken English to broken links

Tags: banks, hackers, virus, phishing

By Steve Ranger

Published: 23 April 2009 12:43 GMT

Phishers aiming to defraud banks have raised their game - and at the very least have learned to spell - according to the banking executives tasked with stopping them.

According to David Shroyer, Bank of America senior vice president of online security and enrolment, the attacks fraudsters are targeting at financial services organisations are continuing to develop. For example, fraudsters are now building phishing sites with malware embedded in them which means the unwary risk not only losing their bank details but also getting malware on their PCs if they are tricked into visiting such sites.

"People are still clicking on the links to see if they are real and those who aren't adequately protected are getting infected," he told a session at the RSA Conference in San Francisco.

"We've educated our customers as an industry but the fraudsters aren't standing still," he added.

The fraudsters have fixed some of their basic problems too.

"The bad guys have invested in a spell checker," he joked, a reference to the poorly spelt and designed phishing emails and websites which characterised phishing attempts a few years ago.

But as the fraudsters increase the sophistication of their attacks, educating customers becomes more difficult. "Now we are talking about a much harder topic, about customer protection on the PC and safe browsing habits and that's a hard message to convey," said Shroyer.

One response from the banks is that, upon finding a phishing site, instead of shutting it down they replace it with a warning explaining phishing. As a result, any customers that do click on the link in a phishing email are alerted to the scam, rather than simply finding a broken link.

"We have an opportunity to educate customers, at that point we can say 'you got phished and this is how to prevent it in the future'," Shroyer said.

According to Stan Szwalbenest, remote channel risk director consumer risk management at JP Morgan Chase, there is an easy way to avoid most of the problems: "We have a simple message: have all the patches in place and antivirus up to date."

"Fraud is a loss to the bank but the impact on the customer is much greater and protecting the customer protects our brand," he added.

According to a report by analyst house Gartner, the average cost of a phishing attack to the US financial services industry was $351 last year - a drop of 60 per cent on the year before.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
Integration Architect/Manager Websphere MQ,WMQ,WMB, Message Broker

Integration Architect/Manager Websphere MQ,WMQ,WMB, Message Broker Location: London Salary: 50,000 - 70,000 Company: ANSON MCCADE Job type: Permanent ...

WebSphere MQ Message Broker Consultants - UK Wide

WebSphere MQ Message Broker Consultants - UK Wide - ? Due to their continued grown, they are currently looking to recruit an experienced WebSphere MQ ...

Middleware / Java developer

The bank is keen to train this person on Message Broker 6.1. This is an exciting opportunity to manage and develop their WebSphere MQ and Message ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: