You are here: silicon.com > Software > Security Strategy

Security Strategy

Phishing continues to rise

Month-on-month increases unabated...

Tags: websense, phishing

By Will Sturgeon

Published: 30 March 2005 18:05 GMT

The phenomenon of phishing attacks, which were the security story of 2004, continues to flourish unchecked while other threats have been stealing the headlines.

According to the Anti-Phishing Working Group (APWG) there are still month-on-month increases in the number of unique attacks. February saw a 2 per cent increase on January with 13,141 unique emails in mass circulation.

Although these figures are down on the boom period of growth in phishing scams which came in mid-2004 the fact the total number shows little sign of decreasing is certainly cause for concern.

Like other threats, part of the problem is the tendency for the scams to evolve faster than awareness and solutions.

Mark Murtagh, technical director EMEA at Websense, told silicon.com: "We saw a real evolution and explosion in phishing in the second half of last year and now there has been a real shift in the way people are targeted."

The APWG reported the number of live phishing websites during February was 2,625. Since last July this has risen at an average of 28 per cent per month.

In their wake these sites ambushed 64 different brands over the course of the month – most commonly high-transaction sites such as eBay, PayPal and major banks. Only six brands accounted for the top 80 per cent of phishing campaigns.

"While the major brands still account for 80 per cent of the phishing attacks it is the other 20 per cent which are the most interesting. We are seeing a shift towards smaller ecommerce companies and regional banks. We're also seeing a real evolution in the way users are targeted."

Murtagh said less action on the part of the recipient and more covert infection are becoming common. Most worrying is the DNS poisoning of an infected PC which enables 'pharming'. Users who have been infected will be caught the next time they try to visit the real target website.

Users may actually type www.eBay.com into their address bar but if they are infected then they may well be directed to a website that looks like eBay, acts like eBay and even says it is eBay. But it isn't eBay.

The most common country hosting phishing websites is the US and the average length of time the sites remain online is just 5.7 days, though the longest was 30 days.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Senior Software Engineer

CompanyMcAfee creates best-of-breed computer security solutions that span large enterprises, governments, small- & medium-sized businesses, & ...

Freelance HTML / Ajax Developer

Freelance Web Interface Developers required for on-going requirements with a Digital Media Agency in Shropshire.This is an agency that has witnessed ...

Lead ASP.Net Web Developer - .Net 3.5/C#/Agile - RBI MEDIA - SUTTON

s largest business media owner and an internationally respected information provider.Our UK Web Solutions Group is a team of c.staff who look after ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: