All the latest UK technology news, reviews and analysis

Cyber-criminals switch to VoIP 'vishing'

by Robert Jaques

10 Jul 2006

Comment: 1

  • Tweet this
Traditional web-based phishing attacks are evolving into sophisticated phone scams
A fraudulent automated recording instructs users to enter credit card information on their keypad

Traditional web-based phishing attacks are evolving into sophisticated phone scams as cyber-criminals attempt to keep one step ahead of detection, security experts have warned.

Secure Computing reported today that its engineers have been tracking news group sites and open disclosure discussion groups which are buzzing with talk about a VoIP telephony version of phishing dubbed 'vishing'.

The new technique has been used by criminals to harvest details of the three-digit CVV security code, expiration date and other essential ID information in addition to the user's credit card and account numbers.

"Consumers need to be made aware of this new threat as it hits the UK," said Paul Henry, vice president of strategic accounts at Secure Computing.

"Like most other social engineering exploits 'vishing' relies on the 'hacking' of a common procedure that fits within the victim's comfort zone.

"Specifically this methodology takes advantage of what has become a normal practice for US credit card users when calling a credit card provider.

"Users are asked to enter the 16-digit credit card number before speaking to a representative. Consumers therefore need to be extra vigilant when giving out their information on the phone."

According to Secure Computing, 'vishing' scams usually begin when the criminal configures a war dialler (sequentially dialled regional phone numbers) to call numbers in a given region.

When the phone is answered, an automated recording is played to alert the consumer that their credit card has suffered fraudulent activity and the consumer should call a phone number immediately.

The phone number is often an 0800 number with a spoofed caller ID of the financial company it is pretending to represent.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Information Security Manager

My client is a well established, non profit organisation;...

PHP Web Developer

PHP Web Developer – £30,000 - £35,000 PHP, MySQL, HTML...

HEAD OF DIGITAL - London - £80-95K+

HEAD OF DIGITAL - London - £80-95K + Excellent Bens...

Agile C# Developer - (North London)

Agile C# Developer - (North London) £55,000 - £65,000...

To send to more than one email address, simply separate each address with a comma.