Financial sector strives to reel in phishing scams

Moderators: Moderator, Global Moderator

Post Reply
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Financial sector strives to reel in phishing scams

Post by Tami »

Financial sector strives to reel in phishing scams
By Ian Palmer

Lori Rainone says she's never been phished-in, and Canada's financial industry is working to keep it that way.

Ms. Rainone is a prime target for phishing scams. "I pretty much do all my banking on-line, so I guess I'm an avid user," says the president of Concord, Ont.-based software company WorkGroup Designs Inc. "I pay all my bills and transfer funds and purchase RRSPs — I do all of that on-line. We also use on-line banking for our business."

Phishing involves e-mails designed to look like they come from, say, a bank, asking recipients to update their personal information and passwords. But these fraudulent e-mails, and the fake websites they direct victims to, harvest the information so on-line con artists can use it for identity theft, to pillage on-line bank accounts, make fraudulent credit card purchases and conduct other illegal activities.

The incidence of phishing attacks is soaring, according to security companies, but RCMP Staff Sergeant Paul Marsh says the RCMP doesn't even have "ballpark" figures available for Canada because phishing itself isn't an offence in the Criminal Code. But it could be part of a fraudulent act, for example, if the information obtained is used to create fake credit cards, he says. "It's what you do with the personal information that may constitute an offence."

Private member's bill C-359 would, if adopted, make the unlawful possession and transfer of personal information an offence, but it still would not make phishing an offence until the moment information was obtained.

Criminal offence or not, phishing is still a big deal for most Canadians. A recent Ipsos-Reid survey shows that 80 per cent of Canadians deem ID theft — whether perpetrated on-line or off-line — a serious issue. And a study commissioned by AOL Canada Inc. shows that 39 per cent of Canadians see ID theft as the top on-line security risk.

A recent report from computer security specialist McAfee says roughly 150-million phishing e-mails are sent daily on the Internet, and that about 60,000 people in the U.S. alone suffered losses to on-line scam artists in 2004. International Data Corp. says researchers tracked phishing scams over a four-month period in 2005 and found that at least 80 per cent of known attacks are related to the financial sector.

Despite the numbers and the fact that she's an avid user of on-line services, Ms. Rainone hasn't been hooked. Her good fortune can be attributed at least in part to the fact that as more Canadians bank electronically, financial institutions are increasing their anti-phishing efforts. The problem is serious enough to get the competitive banks to collaborate, says Ontario Provincial Police Detective Staff Sergeant Barry Elliott, who is also the co-ordinator of the fraud investigator PhoneBusters' national call centre.

"The banks quite often will work together, share information to help fight criminals," says Canadian Bankers Association spokeswoman Maura Drew-Lytle.

"They share a lot of information about what they're seeing out there [and] have their own security departments that will work very quickly when they find out about one of these phishing attacks to shut the website down," she adds. "It's more of an informal sharing of information, but a lot of back and forth goes on."

Bank of Montreal participates in a "mutual support" information exchange with the other banks, says Robert Garigue, the bank's chief information security officer. He says his bank has seen a rise in phishing attempts in the past year. Criminals have used false identities to try to access client accounts and phony websites that look like BMO's site have also been popping up, he says.

"In the last couple of years, I think every single bank has been subject to phishing attacks on a recurring basis," Mr. Garigue says.

Jeff van Duynhoven, vice-president of electronic channels at TD Canada Trust, says banks that are members of Interac all have security people who share information relating to threats and types of responses. The regular briefings, he says, are crucial because the financial services institutions want to make sure that clients feel comfortable using on-line banking.

TD also offers the EasyWeb Security Guarantee, which promises on-line banking customers full reimbursement should criminals make unauthorized withdrawals from their accounts, he says. "There are a number of things we are doing ourselves that gives us the comfort to offer such a guarantee. We look at [customer] behaviour patterns . . . and we [look] at behaviour patterns from external websites coming to our own websites."

BMO's anti-phishing efforts include a multipronged approach to monitoring network activity. "You need monitoring on the network level so that you've got an understanding of what kind of traffic is knocking on your door and that you're making sure that you're filtering out the inappropriate types of traffic and requests," Mr. Garigue says.

While Jeffrey Bowen, director of information services for Bowen Workforce Solutions Inc. in Calgary, says people have to adopt a "consumers beware" attitude when banking on-line, he recommends that banks do more to educate consumers on the risks of phishing.

In this vein, Mr. Garigue says BMO is independently promoting customer awareness. He says it's now not uncommon for wary clients to call the bank's help desk and say things like, "Has there been a change to the website? It doesn't really appear that this is really you." If the customers happen to be right, BMO determines where the website is being hosted, contacts the host and ensures the illegitimate site is shut down — a process that usually takes only "minutes or hours."

Alex Leslie, vice-president of technology for AOL Canada, says the focus on consumer education can't let up, because criminals are making counterfeit websites that look more and more authentic.

"In the past, a criminal spoofed one or a couple pages from a bank site," he says. "What they're doing now is spoofing many, many layers of pages from the site, including forms and work flow, including validation built into the forms. They go through the trouble of oftentimes registering the domain that contains the name of a legitimate company, but they'll either prepend [add] or append something else to it."

Source: [url=\"http://www.globetechnology.com\"]Globe Technology[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Post Reply

Return to “Security”