10 Jul 2006
Traditional web-based phishing attacks are evolving into sophisticated phone scams as cyber-criminals attempt to keep one step ahead of detection, security experts have warned.
Secure Computing reported today that its engineers have been tracking news group sites and open disclosure discussion groups which are buzzing with talk about a VoIP telephony version of phishing dubbed 'vishing'.
The new technique has been used by criminals to harvest details of the three-digit CVV security code, expiration date and other essential ID information in addition to the user's credit card and account numbers.
"Consumers need to be made aware of this new threat as it hits the UK," said Paul Henry, vice president of strategic accounts at Secure Computing.
"Like most other social engineering exploits 'vishing' relies on the 'hacking' of a common procedure that fits within the victim's comfort zone.
"Specifically this methodology takes advantage of what has become a normal practice for US credit card users when calling a credit card provider.
"Users are asked to enter the 16-digit credit card number before speaking to a representative. Consumers therefore need to be extra vigilant when giving out their information on the phone."
According to Secure Computing, 'vishing' scams usually begin when the criminal configures a war dialler (sequentially dialled regional phone numbers) to call numbers in a given region.
When the phone is answered, an automated recording is played to alert the consumer that their credit card has suffered fraudulent activity and the consumer should call a phone number immediately.
The phone number is often an 0800 number with a spoofed caller ID of the financial company it is pretending to represent.
Latest stories from Telecoms
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
My client is a well established, non profit organisation;...
PHP Web Developer – £30,000 - £35,000 PHP, MySQL, HTML...
HEAD OF DIGITAL - London - £80-95K + Excellent Bens...
Agile C# Developer - (North London) £55,000 - £65,000...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
it's even worse IF the vishing scammer ALREADY has your credit number
I have heard that the vishers are now calling prospective victims for whom the visher ALREADY possesses the victims' credit card number in order to "harvest" the CVV. This makes it seem even more "likely" that the victims' bank is calling so it makes it much easier to trick the victim into giving up the CVV.
Posted by: Thomas Ho 20 Jul 2006