Archive for the ‘Phishing’ Category

At $560M, losses from online crime nearly doubled in 2009

The Internet Crime Complaint Center (IC3) recently released their report on 2009 Internet crime statistics.  As you can probably guess, there were more complaints, more losses, higher average loss per incident.  IC3 is a federally funded non-profit, a joint operation between the FBI and the National White Collar Crime Center (NW3C).
In brief:

Complaints received:  336,655
Total loss:  [...]

Read the rest of this entry »

1024-bit RSA encryption cracked by carefully starving CPU of electricity

Several researchers the University of Michigan have succeeded in cracking  the RSA security technology which protects all ecommerce and online banking transactions.
The university scientists found that they could deduce tiny pieces of a private key by injecting slight fluctuations in a device’s power supply as it was processing encrypted messages. In a little more than [...]

Read the rest of this entry »

First Direct serves up more than just no-fee banking

First Direct bank in the UK has been the first British bank to embrace Twitter. Does that really surprise anyone? As a 100% online bank, they’ve maintained a business pace a few clicks ahead of competitors in online services.
But last weekend their clients and colleagues got a little surprise. First Direct’s Twitter account was duped, [...]

Read the rest of this entry »

New attack reveals user identities

Browsing on the web just became a little more scary.   A group of researchers found a way to deploy an attack that can “de-anonymize” the users behind the browser (research paper available in PDF format).  Focusing on the users of social networking sites (LinkedIn.com, Facebook, Xing.com, etc.), these security researchers show how to de-anonymize a [...]

Read the rest of this entry »

Turning Green into Cash – Phishing for Carbon Emissions Permits

A world wide phishing attack on carbon emissions trading registries forced registries in nine countries to shut down, while in other countries trading was temporarily suspended.  Fake registries (phishing sites) were set up by a group of criminals who then sent out messages to thousands of users in different companies, making off with about 250,000 [...]

Read the rest of this entry »

Twitter’s been phished!

2 of my 3 Twitter accounts asked me to reset my password this morning when I signed in. It seems that a third party application may have compromised accounts, but stories abound about what really happened.
What I can tell you is that I know enough about where to share my passwords that I didn’t accidentally [...]

Read the rest of this entry »

3 reasons online banking is safer than paper

We read stories about phishing and data breaches and we get worried. Some of us start thinking that maybe we’re better off (security-wise) with paper-based banking. Sending checks, receiving statements in the mail, paying bills the old fashioned way – manually with a checkbook and a stamp. But as Jean Chatzky said this morning on [...]

Read the rest of this entry »

More online users know about phishing, while number of victims is up by 600%

Two studies show that young people are more likely to be victims of online fraud.  You’d think that since most of them have not experienced a world without Internet and email, they’d be more knowledgeable about phishing and other schemes.  But the insurance group CPP reports that the 16 to 24 age group is most [...]

Read the rest of this entry »

Squeezing some browser sense from the Google-China phishing incident

A few days ago Google decided to shut down its operations in China after a spear phishing attack directed towards Chinese human rights activists, as well as attempts to steal some of Google’s intellectual property.   It is presumed that the attackers sent exploit-ridden PDF attachments in emails to Google employees, thus attempting to gain access [...]

Read the rest of this entry »