You are here: silicon.com > Software > Security Strategy

Security Strategy

Phishers branch out to smaller bank scams

Little phish?

Tags: phisher, websense, phish, phishing

By Munir Kotadia

Published: 17 June 2005 08:55 BST

The number of people complaining about falling victim to or being targeted by a phishing scam has doubled in Australia over the past few months, according to the Australian Securities and Investments Commission (ASIC). While in the US, internet security firm Websense has warned that phishers are targeting customers of smaller banks in an attempt to evade detection.

ASIC commissioner Professor Berna Collier told ZDNet Australia on Wednesday that she felt the issue was accelerating so fast a general warning to raise awareness was necessary.

"The number of complaints we received in April and May was double the amount we received in February and March this year. Last year the number of complaints was double what we received the year before so unfortunately it is an accelerating trend," said Collier.

Collier said ASIC received complaints from both individuals and companies alike and although the largest and best-known organisations were hardest hit, phishers are not discriminating who they target.

"We receive all types of complaints. You are more likely to surrender your personal details - by way of confirmation - to an organisation that you believe is your bank. But much commerce is done electronically so people expect to be contacted electronically," said Collier.

Internet security firm Websense is warning that phishers in the US have started targeting customers of relatively unknown banks and smaller financial institutions in an attempt to fly under the radar.

Phishing has traditionally targeted financial organisations with household names, such as Barclays, Citibank and PayPal. However, Dan Hubbard, senior director of security and technology research at Websense, said that since the start of the year, customers from more than 30 relatively unknown banks and credit unions in the US have been attacked.

"The targets are becoming much smaller and more localised... By targeting a bank with just a few branches, the number of potential phishing prey is reduced to a much smaller number, sometimes to just a few thousand people. Nonetheless, the fact that we are seeing more and more of the smaller financial outlets being targeted by phishing attacks may indicate that this is a highly profitable scam," said Hubbard.

Hubbard, who calls this kind of activity 'puddle phishing', said that although the targets have changed the method used by phishers is identical, which means the attacks could be linked.

"The attack style and dynamics are very similar on many of these recent puddle phishing attempts, which may mean that there is some tool sharing or a small amount of attackers behind this recent wave," said Hubbard.

Munir Kotadia writes for ZDNet Australia

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
CRM Targeting Manager - Financial - 45k -60k

International Commercial Bank is looking to recruit two highly important Targeting Managers 1 for Loans division/ 1 for Insurance & Mortgage ...

CRM Targeting Analyst - Warwickshire - 30k - 38k

International Commercial Bank is looking to recruit a highly important CRM Targeting Analyst for the Loans division. The purpose of the role is to ...

Mid Level C#. Awesome Client List. Telecoms, Finance. Leeds to 32,000

Want to work with leading City Banks? Working on some of the highest profile financial systems in the current market place, this role can lead into ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: