All the latest UK technology news, reviews and analysis

Industry struggles to tackle phishing

by Tom Sanders at RSA Conference in San Jose

16 Feb 2006

Comment: 1

  • Tweet this
Phishers have shown increasing sophistication in recent months
Phishing websites detected in January soared to nearly 9,000

The number of phishing websites detected in January soared to nearly 9,000 setting a new monthly record, according to figures from the Anti-Phishing Working Group.

David Jevans, the organisation's chief executive, said during a session at the RSA Conference in San José that the previous record was 7,197 set in December 2005.

Phishing scams attempt to trick unwary surfers into divulging sensitive and confidential information to bogus websites designed to appear as bona fide businesses such as internet banking sites.

The latest development is the rise of corporate phishing, where attackers aim to steal confidential information or gain access to corporate networks. Attackers often use instant messaging to contact their victims, as many businesses use such networks internally.

Panellists in a conference session about phishing attacks painted a grim picture of the industry's chances of beating the phishers.

"At some point or another, statistically speaking, you will fall for these attacks. They are getting that good," said Bob Lord, senior engineering director for identity management products at Red Hat.

"We know that there is a certain amount of user education that we can go through that will work. But there also is an upper bound.

"It doesn't matter how many memos come out within an organisation telling users to never trust these things, we know that people will fall for them across the board."

Security initiatives are attempting to block phishing attacks at several points. One way is blocking emails that solicit users to go to a phishing website where they are asked to leave their information.

But few spam filters will catch an email sent from a domain that is made to look like that of a bank, as they do not typically look like spam emails.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

36%

0%

10%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Software Developers - London Start-up

Start-up company in West London are looking for a number...

Telephony/Media Software Developer

This team is responsible for developing and running carrier...

Graduate Mathematical Modeller

Graduate Mathematical Modelling position focused on research...

Software Engineers – Network programming

Working on real projects and real high performance software...

To send to more than one email address, simply separate each address with a comma.