Combating the Increase of Phishing Attacks
Identity theft is a difficult problem to solve. Insider theft, lost backup tapes, and improperly keeping personal information are some of the causes cited in recent incidents where personal data has been lost. There is no silver bullet to solving the problem of identity theft and it is going to require action by consumers and financial institutions to address these problems. According to the US Federal Trade Commission about 10 million Americans per year fall victim to identity theft.
As a first step in helping financial institutions, IBM’s Data Governance Council brings companies together so they can measure the value of their data, including the types and probability of risks around data loss. As it stands, there is no standard way to mitigate these risks. As a result, all data is protected the same way: low quality data is over-protected and high value data is under-protected. Companies need to integrate data security policies into business processes, to use quantitative methods to assess risk and to allocate essential resources to protecting critical data resources in high value business transactions.
For consumers, many people have taken measures to better secure their personal information thanks to the public discourse surrounding identity theft. More people now investigate the trustworthiness of a website before providing credit card information. They shred papers with bank accounts. They are more selective in sharing personal information. Phishing, however, is still an area that is luring consumers to divulge information in record numbers.
Phishing is an attempt to illicit sensitive personal or financial information directly from the individual by posing as credible source, such as a bank or a credit card company. By sending out large volumes of unsolicited mail, phishers entice consumers to divulge personal information. Unfortunately, these phishers too often succeed.
IBM’s Global Business Security Index, a monthly report that assesses, measures and analyzes potential network security threats, reported that in May 2005 the volume of phishing emails increased by 226 per cent. IBM’s strategic partner, MessageLabs, collects this data in order to ascertain the dangers posed by e-mail traffic. The rise of phishing attacks appears to be related to the motto: ‘obtain the greatest reward for the least effort’. Specifically, why should an attacker exert the effort to hack into an online system to steal this type of information when people are willing to provide it voluntarily?
This technique of directly questioning the individual, combined with the tremendous increase of e-mail usage (even among users that are not technically inclined) provides a means to communicate with vast numbers of potential victims. Viruses and malware (malicious software) also continue to infiltrate systems and often result in massive volumes of scam e-mails being blasted out to millions of potential victims who are not educated on how to protect themselves and their sensitive information. Even if response rates to these millions of e-mails are less than one per cent, it can be a lucrative hit for the attacker.
As hackers become more sophisticated in their tactics, people need to become more wary. Since phishing is such a discrete process, it is imperative to be extra sensitive regarding the personal information they share and keep in mind the following common phishing tactics.
1. Spoofed source – The communication appears to originate from a legitimate and trusted source, such as a well-known bank, service provider, company or government organization. The spoofed communication provides legitimacy and a point of authority from a trusted source.
Solution: Even if they claim to be from an organization you know and trust, they are likely to be a scam. Companies will almost never ask for any of this information via e-mail. Unless you were the one who initiated the call, never give your credit card number or personal information of any kind over the phone.
2. Sense of urgency – Conveying a sense of urgency to the potential victim seeks to invoke an immediate reaction. The demand for ‘immediate’ action helps to ensure that the potential victim responds before being able to think about what is happening. This is combined with the potential threat of fines, loss of service, negative consequences to status, or other conjured negative consequences.
Solution: When in doubt, contact the organization by phone or via another trusted means to confirm the status of an account.
3. Personal details – The communication asks the victims to divulge details about their personal life, financial data, online user IDs and passwords, or other sensitive information. To prevent the terrible consequences befalling a potential victim, which is being threatened from the reputable source, there is a simple course of action to resolve the perceived issue: follow the directions and answer the questions. The attacker can then use this information to commit identity theft.
Solution: Be wary of e-mails asking for social security numbers, credit card information or addresses. Do not immediately trust the source, instead call the company directly. For instance if it’s a credit card company, use the number on the back of card, or if it’s a bank, go to a branch to speak in-person with a representative. Also, at that time, confirm the company’s policy on requesting personal information, for future reference.
Also, continue to remember general Internet security tips. Take the proper steps to make sure you’re keeping would-be thieves out of your computer. You wouldn’t leave your house without locking your door, so use the same mentality with your PC. When creating new accounts of any kinds, use non-obvious passwords, frequently patch your software, set up a personal firewall and use updated antivirus software. Otherwise, you risk a hacker getting access to your network and your personal documents within your computer.
Also, be wary of where you surf. Only log on to servers you know and trust, and avoid the temptation to sign onto ‘free’ websites. Also important, avoid transmitting personal information over public wireless connections.
While phishing contributes to the increasing number of identity theft victims, there are many other ramifications of phishing attacks that can also impact companies and service providers. Some of these impacts include:
Phishing and the problems that follow cannot be taken lightly. By realizing the impact it could have on your company, take some preliminary steps to begin protecting your employees and customers.
While there is no quick cure for phishing, the best ways a company can address the problem include: consumer education, corporate management to protect customer information and transactions, technology for spotting potential fraud, stringent laws and co-operation among industry groups.
Protecting customer information and transactions – A company can require multiple levels of authentication, such as passwords, smart card or biometrics, signed and certified e-mail so customers know it is coming from a legitimate source. In addition, the company can establish a communication policy, reviewed and approved by senior management that clearly states that customers and business partners will never be asked to provide sensitive information in an e-mail response.
Consumer education – Once a communication policy is created, efficiently and clearly communicate it with customers and inform them what type of information would ever be requested via telephone, e-mail or on the Internet.
Technology for spotting potential fraud – Spam filters can also be a first line of defense against phishing and are effective at reducing the amount of spam mail that gets through to e-mail in-boxes. Also consider firewall software to protect a system from a hacker by monitoring what goes in and out. In addition, even anti-virus and anti-spyware software can identify and combat the viruses that often spur spam. Businesses must also monitor the traffic on their websites for signs that their site is being looked at with the objective of creating a fake website. This can include the analysis of its design, images, and navigation structure – the pattern of use is different to someone visiting the site to transact business.
Stringent laws – Monitor emerging regulations regarding phishing and support legislation that boosts penalties and mandates minimum prison terms.
Join industry groups – Co-operate across the Internet by joining forces with industry groups such as the Anti-Phishing Working Group and the Trusted Electronic Communication Forum. For instance, IBM created the Data Governance Council, along with dozens of companies, institutions and technology solution providers around the world, to develop a ‘blueprint’ of common standards and approach to data security and privacy challenges and policies governing them.
Identity theft and the loss of personal information are serious problems that consumers, companies, and governments around the world must step up to address. Consumers should be more vigilant in protecting their data. Financial institutions – or any organization that collects personal information – must do everything within their power to protect the sanctity of personal information. Finally, government bodies need to ensure that stiff penalties deter identity theft.