Phishing & Identity Theft

What is Phishing? | What is Identity Theft?

Beware of "Computer Support" Phone Calls

Many folks (including myself) have received phone calls claiming to provide computer support (sometimes from Microsoft) or telling you that your computer is infected. These may be a followup to phishing emails.

Do not converse or do business with persons or companies phoning you. You have no idea who you're dealing with (even call display can be faked). Learn how to avoid Identity Theft.

There are huge personal and financial costs if you allow yourself to become a victim ($37 billion in 2010, down from $56 billion the year before). See the graphic on ZoneAlarm's blog: Your ID Price Tag: The cost of a stolen identity and what to do if it's been compromised.

Phishing — Obtaining Information by Deceit

How Phishing Works | How to Tell Fake Links | Abusing Transfer of Trust

Firefox's warning page for a reported attack site

Phishing is a relatively-new form of spam that takes advantage of both vulnerabilities in some browsers and email programs combined with people's ignorance of how the Web works to perpetrate identity theft.

Looks Can Be Deceiving

The purpose of phishing is to obtain financial and personal information by deceit. The intent is to steal your on-line identity — commonly referred to as identity theft.

Identity Theft is a Long Term Problem

If you are the victim of identity theft, you can expect to fight to regain your credit rating for years — over and over again.

Victims report that it takes months or years to regain their credit rating, only to find that a new report forces them to start all over again.

While electronic data can quickly get you into trouble, financial institutions want physical (on paper) evidence that you're not responsible.

Return to Phishing

How Phishing Works

Going on a Phishing Expedition

Becoming a victim is easier than you might think. Let's have a look at the process from the perpetrator's point of view.

Remember, YOU are the intended victim of this trap.

Step One: Create a Fake Website

The first step is to set up a look-alike site that closely resembles a site that your victims are already using or could be using. The company's logo and other trademarked images are used to convey authenticity. (See the section on abusing transfer of trust.)

This could be a bank (most have been targeted), e-Bay, PayPal or any site where you conduct business using a credit card or enter with a user name and password.

Step Two: Send Out an Email

Look at this sample phishing email sent to islandnet.com customers

Next, an email message (see the sample on the right) is sent to thousands of potential victims (like you) indicating that there is a problem with their account, or that their account will be closed unless they go to the website and re-enter personal information, including their user name and password (or bank PIN).

However, this message is not from who you think. The sample show above to the right is a real message sent to Islandet.com customers. (Islandnet.com, like most legitimate businesses, will never ask for this information.) See part of the headers from this example message (the blurring is intentional). The message obviously didn't come from "Islandnet.com" as was indicated in the message.

One of the dangers of "enhanced" or HTML email is that stuff can be hidden and you have to know how to look for it.

Firefox online security features help you avoid problems with invalid or insecure sites.

Step Three: Collect the Information

The victim (you) clicks on the link and finds themselves on what they believe to be the correct site (remember, the perpetrator has created the site to look like the original), so they enter their user name or email address and password.

Of course, this information is not going where you think it is — you're sending it directly to thieves.

Step Four: Assume Your Identity

Taking your electronic identity (which you've just provided to them on the phishing site), the thieves go to the real site (such as your bank) and log into your account.

The information obtained in this manner is then used to either obtain funds from your account or to set up credit in your name.

Return to Phishing

How to Tell Fake Links

Configuring Your Software | Where Does That Link Go? | How Can a Fake Site Exist?

Your Ignorance is Your Downfall

One of the weaknesses that allow phishing and other identity theft practices to succeed is that most of the victims are using technology that they don't understand.

Configuring Your Software to Protect You

Whatever choices you make with your software, you'll want to take advantage of some advanced (and often hidden) features:

Advanced features are often hidden to provide for a cleaner, simpler look. Remember, software vendors don't have to pay to clean up problems that could have been prevented were these features enabled.

If you need help determining how to configure your software and security protection, contact someone knowledgeable. Remember, you're putting your trust in this person, so be careful when selecting your "expert" helper. I provide these services in Greater Victoria.

Get Help From Your ISP

Use whatever tools your ISP makes available to identify potential spam, phishing and other problematic email messages. Check your ISP's help or support website or call their help line.

I strongly recommend Islandnet.com (even if you're using another ISP) because of their extensive PEP anti-spam tools and friendly, knowledgeable help.

Hosted by Islandnet.com

Links Have Two Components

Hyperinks on a website (and in an email) have at least two components:

  1. The hidden encoded address (or link where you are being sent); and
  2. The text that you see .

Only the hyperlink itself (the hidden part) determines where the viewer is going to go. Just as placing a Mercedes license holder doesn't make your Ford into a Mercedes, a misleading link description doesn't change its destination.

Using the Status Bar

Remember I told you that the status bar was a valuable tool? If you hover over the link in a website or email message and look at the status bar at the bottom of the message, you'll see where the hyperlink is actually sending you.

Take a look at the following link and then see where it leads you (a new window opens):

If you hover over the link and look in the status bar you can tell without visiting the link's destination (strongly recommended when dealing with unknown sites and emails).

Just because the linked text says it is pointing towards "www.mybank.com" doesn't mean that is the real hyperlink.

Learning More of the Mechanics

If you are interested in the mechanics of this process, have a look at Cut 'N Paste HTML Editing. It explains simple HTML and demonstrates how an HTML link works.

How Can a Fake Site Exist?

First of all, people that set these up and send out the phishing emails wish to remain anonymous. They are breaking the law and don't want you to be able to find them after they steal your identity.

Short-Term Links

The provided links are only up for a short time before they are removed by the financial institutions affected or by the legal authorities.

Forged links often point to a site in an educational institution where passwords and access are easy to come by. By their very nature, universities house a lot of smart and curious people. Smart as they are, too many don't view the issue of security as their problem. Because of a few people's lax attitudes, many will suffer significant financial setbacks.

Delete Attached Forms

More recent phishing attempts have provided an attachment to their messages which, when opened, replace the fake site with a form which accomplishes the same nepharious purpose — to get your information using deception. Don't be fooled.

Return to Phishing

Abusing Transfer of Trust

The successful phishing scheme depends upon your trust for your financial institution (or other authority) being carried over into trust in the fraudulent email and the website link it contains.

The Internet Can Be Exploited

Browsers and enhanced (HTML) email messages can be exploited for this purpose. Unless you understand the language (markup code) you are unlikely to detect this deceitful practice.

Preventing Successful Phishing

There are a number of things that you can use to avoid being the victim of this type of attack:

Return to top

Use a Safer Browser

Your Choice Matters

Your choice of web browser can make a difference in your ability to protect yourself online. Whichever browser you choose, the most recent will usually have improved security features and/or have known security issues patched.

Internet Explorer, which is tightly integrated into Windows, is not recommended for most routine surfing and browsing sites on the Web. While Internet Explorer may be convenient, any security issue in any Microsoft product puts your computer at risk.

Firefox Recommended

Firefox is a much safer browser to use. As an independent program it is less vulnerable to cross-program security issues while still able to perform the intended functions and call to outside featurs like email programs.

Have a look at some of the built-in security features of Firefox:

Firefox's warning page for a reported attack site

Return to top

What is Identity Theft?

Reporting Identity Theft | Protect Your Identity | Other Resources

Identity theft, in a nutshell, is the obtaining of information about you that will enable someone else to impersonate "you" electronically online.

Identity theft is, unfortunately, a rapidly growing crime.

It Used to Be Harder

Obtaining personal information is much easier than it used to be. At one time you had to go to your bank, speak to a real person who would then check a card with your signature and ensure that you were who you said you were before releasing funds or a providing new credit card.

Today, Information is Too Easily Accessed

These days credit card applications appear unsolicited in your mailbox and are easily available online. Verification depends upon electronic data rather than hard copies (original documents in the teller's hand).

Passwords — Your Electronic Signature

Many people using this technology don't really understand it. They worry that they'll forget a password, so they make it simple and use the same one over and over again. Your bank PIN is only four numbers (not very many permutations are possible, so it is relatively easy to guess). Learn more about using effective passwords.

Lack of Knowledge is Your Undoing

Folks don't really understand the risks of using an obsolete email program like Outlook Express (targeted by spammers and phishers because it is so common and doesn't contain sufficient protection for the user). These programs are the electronic equivalent of a skeleton key and are both "easy to use" and ineffective in providing protection.

Just as seatbelts, car alarms and ignition keys are inconvenient, Internet security is too. But they also share the provision of protection otherwise unavailable.

Return to Identity Theft

Protect Your Identity

Everyone is Gathering Information

Everyone is collecting information about you. They want all the tools at their disposal to get you to buy their products and services. If they can get your email address, they can send their advertising right to your inbox. If they know your marital status and how many children you have they can identify potential markets.

See how to opt out of being placed in these lists and well as how to get off these lists if you didn't ask to be put on them in the first place.

Beware of Phone Callers

Do not converse or do business with companies phoning you.

Don't Give Away Unnecessary Information

Personal Information

Do not release the following personal information, since it is your identity when you conduct business on-line:

Be careful about releasing billing addresses and employment information as well. While the successful completion of many credit card transactions requires that the shipping address match the credit card's billing address, this information is not necessary for other transactions.

"Innocent" Information Dangerous

Take Care When Posting on Social Media Sites

People sometimes post things on Facebook or other social media (as well as mention over the phone) without thinking about the consequences.

Watch that you don't reveal the sort of information that allows you to recover a lost password as this is usually something you should remember, but strangers wouldn't, (unless you post it on Facebook):

Being "In the Cloud" Has Risks

You may have heard the term "cloud" computing as the next big thing in computing.

While it may free you to access your information anywhere at any time, it also provides the same access to anyone on the Internet (and to the employees of the company providing the service). Hacking of these networks have become very common:

Return to Identity Theft

Reporting Identity Theft

Reporting Identity Theft

If you suspect you've been the victim of identity theft, the sooner you act, the sooner you can begin to resolve the issue.

Remember, it will likely be harder to prove identity theft than to execute it, hence the long warnings on this page.

If you do receive bills for unauthorized credit cards or are billed for goods or services you did not receive (particularly from a foreign country) you may have to file a report with your financial institutution(s) and to the police.

Return to top

Other Phishing & Identity Theft Resources

More About Phishing

More information about identity theft and how to prevent it is found on these sites:

More About Phishing

The following sites deal more with the issue of phishing.

Return to top

More About Related Issues

Protecting Your Online Identity

The following related pages offer more information about protecting your online identity:

Securing Your Computer

The following related pages offer more information about securing your computer:

Return to top

www.RussHarvey.bc.ca/resources/identitytheft.html
Updated: January 24, 2012