Showing posts with label Phishing. Show all posts
Showing posts with label Phishing. Show all posts

Thursday, 10 November 2011

Let’s be careful out there


The internet offers a huge range of opportunities to everyone and some people use it for good, some for bad.  To say that there is a sucker born every minute is probably an understatement when it comes to the web as many, many people fall daily to internet based scams. For a company like us we spend hours and hours of time defending and countering internet-based attacks. Just this week, two scams were doing the rounds of classified based websites.
One of the tricks used is that the true victim is unaware of the scam right until the last minute, by which time it is generally too late. Many people are surprised by how organised and targeted internet-based scams are and think “ I’m so small, why would they attack me?”  Like a few things in life as the scam unfolds you find that you are only part of a bigger and more complex picture. The timings used are very exact and ensure maximum impact on the intended targets and time periods -long weekends are favourites.  During this time the scammers are banking on the fact that the targets are more relaxed and their system and web providers have less support available to manage or monitor events.  From our point of view, we have support available in the AutoBase office during Saturday and have strict monitoring in place 24/7.
Along with timing, a scam will normally build in a number of stages that do not seem to link until the very last minute. The first step is to always gain access to user accounts.  As there are many complex tools in place to stop the scammer hacking the user information directly, the easiest way is to just ask the users for their login information directly. Surprising, this does work with the old ‘click on this link to update your information’ trick. The user is further fooled as the site mirrors the expected interface, as it is a direct copy of the legitimate website.  An extra step used to stop the user thinking something is wrong is when after the first attempt to enter your username and password , the second attempt works and redirects you back to the legitimate website.
With this user information, and generally before a weekend, the user information is used to change the following.  The price is reduced only enough to make the items look attractive, but not enough to raise the suspicion of the purchaser.  This leaves the purchaser with a sense of urgency around closing the deal. What makes the pricing look even more legitimate is the adding of comments stating that the company is running some type of sale before re-locating or closing down.  Finally, the contact details have been updated to redirect enquires back to the scammer. Now the spider web is set.
As the purchasers start to make contact, the scammer feeds off the urgency of the buyer and states that they have had a number of enquires and to hold or secure the item a holding fee or deposit is required to be paid immediately.  Stung! By the time it has come to the surface of what is happening, it is too late for some.  Nowadays the scammers are heading back for a second go and enquiring  about the vehicles that they have changed and updated.  By doing this they then see when they have been sprung, as they are notified along with the other buyers that they have been involved in a scam.  
The golden rule is to never reply to an email or click on a link requesting your username and details.  No online trader or bank will ever ask you to do this and if you have any doubt call the company requesting the information directly.  If it is found to be a scam, this kicks off a number of processes around getting the website removed and efforts in locating where the scammer operating from.  This also allows any other users who could have been impacted to be contacted.
How do I identify a phishing scam?
·         You receive an email from a company that you currently do business with and they are requesting you username and password
·         The email could state your name or company.  However generally they state Sir or Madam
·         The email warns that you have been a victim of fraud
·         The email says that you need to confirm or enter a new password
·         The HTML tags behind the links on the email will reveal that the underlying URL usually does not link to a page within the authentic domain
·         You did not initiate contact with the sender or may not have expected to receive it
·         The email contains grammatical errors and spelling mistakes.
Always be on your guard.


For more tips and information, check out the Scambusters NZ website here

Wednesday, 1 June 2011

Gone Fishing - but not the good kind!

Last year and once this year our dealers were targeted by a ‘phishing scam’ - a bogus email  e.g:
A group of AutoBase clients received an email asking them to confirm their account – it had the AutoBase logo and branding on it and looked fairly realistic. When a few of our clients clicked on the link in the email, a website that looked exactly like the AutoBase site appeared with fields to enter their Username and Password. It all looked authentic – apart from the fact that the URL was wrong. When a few of our clients clicked on the link in the email, a website that looked exactly like the AutoBase site appeared with fields to enter their Username and Password. It all looked authentic – apart from the fact that the URL was wrong. This was the fake website which looked real as it was copied directly from our own site - However the URL was http://admin-autobase.com/ which is not the correct one. Our website would have come up as http://admin.autobase.co.nz/ - the mere difference of a ‘dot’ instead of a ‘dash’ and extension. 

Another example of the URL of the fake website a more recent scam used is www.idealerbase.co.nz instead of real www.dealerbase.co.nz. The mere fact of an addition letter in this case was a subtle change to the URL address.
Only a few clients actually entered their details, which took the Phisher into their AutoBase account where on some existing listings they reduced listing prices, added ‘Half Price Liquidation Sale’ to the comments, changed the images to look like an AutoBase brochure and changed contact details by entering an email address they had created. They also added bogus listings including all of this information.  Some viewers on Trade Me who saw the scammer’s listings took interest and emailed the bogus address, where they were asked to deposit money for the vehicle into the scammer’s account.
Luckily, bogus listings were spotted and reported to AutoBase within hours of the client entering their username & password into the link in the scam email.  Within hours myself, the General Manager and the IT team were in the AutoBase office. The bogus listings were pulled and amended and all clients’ passwords were immediately changed to protect anyone who had already sent the scammer their details. Every client was sent an email warning them of the scam and advising of their new passwords. Trade Me were notified and sent an email to every person who viewed a bogus listing, letting them know it was fake. The Police Departments National Cyber Crime Centre (yes, a Cyber Crime department does exist!) was contacted and the bogus site was shut down.  Due to the quick response, no sellers or buyers were affected - and the scammer got NO money!
You may have received one of the most popular phishing scam emails that appear to be coming from a bank asking you to confirm your account details. More often than not you don’t even belong to that bank! Phishers are ‘fishing’ for your personal details or even worse, your customer’s details – they want your username and password so they can access your private accounts such as your bank, email (Gmail, Xtra, Hotmail etc) or Trade Me. So how do you stay safe and avoid being duped? The rule of thumb to keep you safe is NEVER enter your username and password into a website link that has been emailed to you. If in any doubt, call the company who appears to be sending you the email – guaranteed it will be a scam. 
Scammers and Phishers are becoming increasingly clever. Click on the link and the website looks real, with legitimate looking logos and design exactly like the real thing - this is how victims are lured into entering their details. It looks real, so they assume it is real.   No matter how realistic the website looks, do not enter your username and password.
How do I identify a phishing scam?
  • The email fails to confirm that the company does business with you (i.e. by referencing your account number)
  • The email fails to address you by your name, and may be addressed ‘Dear Sir/Madam’ or‘Dear Cardholder’
  • The email warns that you have been a victim of fraud
  • The email says that you need to confirm or enter a new password
  • The HTML tags behind the links on the email will reveal that the underlying URL usually does not link to a page within the authentic domain.
  • You did not initiate contact with the sender or may not have expected to receive it
  • The email contains grammatical errors and spelling mistakes
Do not reply to any email that requests your personal information, or click on the link provided. Again, if in doubt, contact the company who appears to be sending you the email. For more information, check the Ministry of Consumer Affairs scam information here.

Footnotes
 1. Scambusters NZ website - Click here
Related Posts Plugin for WordPress, Blogger...