Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Thursday, November 5, 2009

The Phishing/Trojan Scam-What Is It?

The Phishing/Trojan Scam -What Is It?

The phishing/trojan scam has been around for a while, however, it is making a comeback. Why? People and companies are become more savvy-thus, so are the attackers.

If you work on the Internet, do a lot of Internet browsing, or you're into Social Media you must remain, or become more alert. The phishing/trojan scam is hitting not only consumers but enterprises as well.

Check out the details in my article:

Phishing/Trojan Scams on the Rise
There seems to be a decline in straight phishing scams-meaning that attackers are finding different methods to obtain the same gains they found with phishing but are now incorporating a Trojan. I give you a quick intro to what phishing is, as well as, what a Trojan is and can do to your system, before giving examples of what is hitting the Internet. Read More....
Read more...

Tuesday, October 7, 2008

Scams and Your Personal and Financial Data

Whether you work online or offline it's time to educate yourself of the new scams that have morphed itself from the phishing scams.

For those who do not know what a phishing scam let me enlighten you. And for those who have heard about a phishing scam, let me refresh your memory. A phishing scam is the attempt by an individual to gather personal and/or financial information from you through an e-mail, phone call or letter.

Now, what are some of the ways the phishing scams been morphed into?


E-mail phishing

The individual (scammer) will send an official looking e-mail pretending to have come from Paypal, credit union, bank, or even a retail establishment with the hope of gaining personal information. (Note: for those looking for jobs you have to be careful about solicitations from scammers enticing you to try for a position -and all you have to do is provide them
with some additional information.)


Vishing

Vishing is the use of your telephone. The victim will get an e-mail or voice mail message asking them to make a phone call. The victim will make the call which will trigger a voice response system asking the user for their card number or other personal or financial information.


Smishing

Smishing is a mobile phone scam. The mobile phone user will receive a text message with the purpose of getting the user to click on a link.


Phishing-through the mail

The phishing through the snail mail- (surprising as it may seem-since it does cost money to send a letter) is where the scammer sends an individual a letter requesting that they respond to the letter by calling a specific phone number- for their own protection. My advice, if it is an institution that you do business with-contact them to verify-before you decide to give that "specific phone number" a call.


How to protect yourself

1. Do not click on the link they provide.
2. If you want to check the link. Open up a session of the Internet and put in your stored link - NOT THE LINK provided within the email. And verify the information.
3. Contact the company that you are doing business with to make them aware of what is going on - and/or to verify that the email or letter was truly sent by the company. If it was not, then this warning will allow them to notify other people that they do business with, with what is happening.
4. If you do any business online - use security software
5. Make sure the website shows SSI security- (https//)
6. Make sure your browser is up-to-date and all security patches are current.


To conclude: use caution when giving out your personal information-online or offline.

About the Author:

Vickie J Scanlon Visit her site at: http://www.myaffiliateplace.biz for tools, security utilities, articles on affiliate/internet marketing business, ebooks, how to info, tech and tech accessories for the affiliate/internet marketer
Read more...

Friday, April 27, 2007

Phishing-Pharming Scams-The Facts

Phishing and Pharming. Everyone is somewhat familiar with phishing, but pharming -- maybe you need a little information. Anyway, that is what I thought for myself. We are need to be ever vigiliant in both areas online and offline.

Online -- If you are on the Internet a major part of the time, then you are aware that you need to protect yourself online. Those new to the Internet realm, may not be so aware-especially if their experience has been within a corporate setting.

Offline - maybe people are not as informed - but aware. Even though I did not elaborate in my article about how pharmers/phisher obtain your info and identity, let me enlighten you. Offline, it is wise to use a micro shredder to shred your important information that has your name, address, account information before throwing it out to the dumpsters. Unscrupulous individuals can pick through your trash looking for bank statements, credit card states, financial records, etc-purpose to sell or to steal your identity. And if you watched CNN lately, you would have seen an individual who is still trying to clean up her identify after seven years-after someone stole her identity.

Just to add, it's wise to get yourself a shredder-and preferably a micro shredder. Straight cut and cross-cut shredders can still be put back together.

So hopefully, this article will enlighten you to what phishing and pharming is, and how you can try to protect yourself online. One final thought, phishing and pharming protection has to be a collaborative effort between consumer and business -- working together we can be better informed and protected.


Phishing-Pharming Scams-The Facts?
By Vickie J. Scanlon


With the Internet becoming more of an intregal part of many people's busy lives, it is becoming more important to be aware of how you can and should protect yourself. Two different scams to acquaint yourself too is the pharming and phishing scams. They have been around for awhile, but both are becoming more prominent as times goes by. So it is wise to learn what you can about them, as well as, take appropriate action when needed.

Phishing Scams

Phishing Scams are scams in which you asked within an email to click on the provided link so that you can verify the information that they feel may have been compromised. It could be your online banking, paypal, investments accounts, etc. with the purpose of capturing your account number or password.

How do you protect yourself from Phishing Scams

With a Phishing Scam you have to always be on your toes. For example, if you receive an email requesting that you log-in to your PayPal account because they feel that it may have been compromised. They will supply you with a link to click on to get you to the site. The site may look authentic, but it is not. Some precautions can be taken. Such as:


1. Do not click on the link they provide.
2. Open up a session of the Internet and put in your stored link -NOT THE LINK provided within the email. And verify the information.
3. Contact the company that you are doing business with to make them aware of what is going on - this will allow them to notify other people that they do business with, with what is happening.


Pharming Scams

Pharming Scams is like phishing with a slight twist to the whole game. With the pharming scam, you are redirected from your legitimate site to that of the fake site.

How do they get in? They do it in several ways:

1) through an email virus- in which they install a small programs that will direct the user to the fake site. Once the small program is in place, they will use a Keylogger virus. The keylogger virus tracks the users passwords that they (the user) key in with.
2) The other methods involves the pharmer interfering with your DNS. When you type a Web site's name into your browser, your server will read the name, look up its numeric address and take you to the site. This is where the Pharmers interfere with that process. They change the real site's numeric address to the fake site's numeric address. The Pharmers can interfere with your DNS only when you use the "http" and not the "https" for your contacting url.


How to Protect Yourself

If you are on the internet often or do any financial transactions online, it is wise to incorporate as much security as possible. Here are some helpful tips:

1. Use adware/spyware software daily
2. Use anti-virus software
3. Use software that identifies the site, determines the length of time they have been online and allows you to look at their site report. Most software options check against an updated database of blacklisted phishing sites and IPs. One example is Netcraft- it's compatible with Firefox or Internet Explorer.
4. Internet security software
5. Use Firefox or Opera for added security
6. Password Management Software -- helps to eliminate keylogging-and encrypts your passwords. Example: Roboform - ten or less it will be free to use. If you have over 10 you will need to pay a one time charge after 30 days.
7. Always use a secure website. SSl encryption with beginnings like: https://
8. Make sure your browser is up-to-date and have all necessary up-to-date security patches.


What are Businesses Doing To Protect You?

Yes, businesses are concerned with your security. Why? They are on the losing end as well-through lose money and business. So what are some companies doing to protect you.

1. Some business only allow so many attempts into your site in a day. Then you have to wait for the next day to do business.
2. They monitor your IP address for safety.
3. Eliminate all pop-ups during sign-up and sign-in.
4. Some eliminated emailing together.
5. Server side software to protect their customers and employees who use internal or private web-based systems


What to Do If You Are A Victim of Phishing or Pharming

If you feel you are a victim of phishing or pharming don't ignore it, or think nothing will happen. Be pro-active and set things in motion to protect yourself. Such as:

1) Notify the company immediately. They will tell you how to proceed. And be prepared to create a new user-id and password.

2) Depending on the severity of the breach-Report an Initial Security Alert to one of the three consumer agencies listed below:
a) Equifax-www.equifax.com
b) Experian-www.experian.com
c) TransUnion - www.transunion.com

Upon contacting one of the agencies, they will notify the other two. The Initial Security Alert puts an alert on your credit file, as well as, alert creditors to follow certain procedures to protect you. This is protecting your identity.

To conclude, if you work on the Internet or utilize the Internet a lot on a daily basis, do not ignore your security. Swallow hard, get the software you need to protect yourself, your family and online business. And as always, be ever vigilant.



Vickie J Scanlon -- Visit her site at: My Affiliate Place for tools, how to info of affiliate and internet marketing, Report Your Scams, tech accessories, security software and computers for the online business.
Publish Post

Read more...

Saturday, July 30, 2005

Phishing – It’s Signs and Your Options

Phishing can be a serious problem and can be a major threat to your computer-- some you can catch right away, others a little deceptive. If you are working on the Internet, it is important that you protect yourself and your computer. Here is an article that I wrote, that identifies, explains and gives you options on ways to protect yourself.

Phishing – It’s Signs and Your Options
By Vickie J. Scanlon

Phishing is the act of some individual sending an email to a user in an attempt to scam the user to release personal information. Is it easy to determine if it’s a scam? Sometimes – but not always. I hope to give you enough examples and information to help you to safeguard yourself from these unsavory individuals.

In addition, sometimes the email is sent to malicious software so as to render your computer helpless. Thus, it is important that you do not click on the link they provide, because that is the trigger that will load the software to your system.

EXAMPLES OF PHISHING

You receive hundreds of emails in your mailbox, but one email catches your eye – it directs you to a website, requesting that you need to update your personal information. It requests such personal information as:

passwords
credit card numbers
social security number
bank account numbers

“It appears to be legitimate”, you say to yourself. And you also notice that the emails are from companies that you have been doing business with for a while. Warning: The website could be bogus.

Here are several examples of phishing in action.

E-mails stating they are from E-bay and they feel that your account may have been compromised and would like you to verify your information with they so conveniently supply. DO NOT click on it.

  • E-mails from Paypal or your bank asking that you verify your information because they feel that your account has been compromised, or heaven forbid, suspended. Same scenario, different company. DO NOT click on the link.
  • E-mail that states that an unauthorized transaction has occurred on your account. Please click the link below and confirm your identity. DO NOT.
  • Here’s a work at home scam – We have seen your resume on Monster and feel you would fit our position. If you are interested, please go to our website, look over the experience required and submit your resume if you have this background. Website is professional looking, offer looks good – but it could be a scam.


    WHAT ARE THEY AFTER

    In the above examples they are after information about you, be it passwords, credit cards, social security numbers, anything that can identify you – and that which they can use to profit from you.

    The job email is used to verify that the email address is a true blue, active email address. What do they do with this info – they sell these accounts to spammers for good money. They need to verify your email address—because if the spammers come up empty – this person’s business is dead.


    HOW TO VERIFY SAFELY

    1) If they want you to verify your account, do not cut and paste, or use the link they provide in the email. Close your Internet session, open a new session and enter the site that you have on record to verify.
    2) Emails requesting resumes – Verify their account before you send your resume. When verifying – these red flags should be considered:

    1) If they are hesitant to provide a phone number – might be a scam. 2) If their business address is not verifiable –might be a scam. 3) If the website is new – might be a scam. 4) If they use a large company’s name—and that company never heard of them – might be a scam. 5) Again, verify this information before you send your resume.


    WAYS TO PROTECT YOURSELF

    Here are some quick tips to protect you and your computer system.

    * Use anti-virus software and a firewall – keep them up to date.
    * If you have a broadband connection make sure you have a firewall in place.
    * Don’t email personal or financial information.
    * Before providing personal information – search to see if the site is secure – look for a lock icon. However, remember not all phishers are stupid – in fact, they could be computer savvy enough to forge security icons. Thus, look for a site whose link looks like this: https://www.somename.com -- this shows that it is a secure site.
    * Coupons from respected companies – Verify that it is a true-blue coupon from the company – I had one coupon sent to my email address from what I thought was Staples. Verified it with Staples – not a coupon honored by Staples. When on the Internet – if it looks like a duck, quacks like a duck, it still may not be a duck!
    * When making transactions on the Internet – be it online banking, Paypal, Internet Gold, etc. – complete your transaction, log out of the website, and close out of your Internet Explorer—and then continue with a new session of Internet Explorer.

    WHERE TO FORWARD SPAM THAT IS PHISHNG

    If you encounter spam that is phishing, or are a victim of a phishing scam, you can forward the information to spam@uce.gov and to the company, bank or organization that the email may have stated they are from. In many cases, the other organizations have information on their website where you can report the attempted scam.

    In addition, if you have been scammed, and you wish to file a complaint – go to ftc.gov.

    To conclude, no one is immune to spam or a scam. But try to be ever vigilant and do your due diligence with anything you do on the Internet. But being human is a scammer’s hope – they know that most will ignore the bait, but some will be tempted. So, if you so humanly slip, and succumb to a phishing scam, you can report them to ftc.gov.

    ========================
    Vickie J Scanlon -Visit her site at: http://www.myaffiliateplace.biz for free tools, articles, ebooks, affiliate "how to" information, where to report your scam, Affiliate programs to join, computers for business, software and more



Read more...