Showing posts with label email. Show all posts
Showing posts with label email. Show all posts

Monday, February 15, 2010

Fraudsters now targeting malware to individual consumers

When it comes to email most marketers know they must follow white-hat policies. Have email authenticated, use valid subject lines, clean the list regularly and pay attention to sender reputation. Despite this consumers are defrauded daily by fraudulent emails, making it more and more difficult for legitimate marketers to engage consumers. According to Symantec's MessageLabs, a new threat is now at the horizon: targeted, fraudulent emails. The research lab has identified Olympic-themed emails which appear to be legitimate - the messages even have actual travel and Olympic links - but hidden inside the message is an i-frame which could leave malware of consumer computers.

"We have seen three instances of this attack so far in February," said Paul Wood, Senior Intelligence Analyst with MessageLabs. "[This is] a very small number in terms of global malware, but by its nature it is not designed to be widespread. This targeted attack is meant to attempt to gain access to a small number of specific users' machines. If just one gets through, the damage to the victim could be substantial." The messages contained subject lines such as "Information and resources to help you travel during the 2010 Winter Games" and "How to make Olympics more interesting". The body of the messages seems innocuous, but an attached program file then attempts to install malware on the person's computer.

This is another example of why sender reputation is so important for legitimate email marketers and why white hat practices should always be followed. Consumers, more than ever, are smart about which emails they open but some are still fooled by spammers. A consumer only has to be burned once to never again open a message sent from someone other than a personal friend. By following the 'best practices' there is a better chance that consumers will actually open real email messages.

Read more...

Wednesday, December 16, 2009

Great Cyber Security Advice for the Holiday Season and the 12 Scams of Christmas: Part 1

The FBI has this holiday-time warning: 'Tis the season to be wary, especially when opening up those particularly alluring offers popping into Utahns' e-mail in boxes. Ken Porter, acting agent in charge of the FBI's Salt Lake City Office, said Tuesday that whether these unsolicited messages pose as prize announcements, banking correspondence or purport to offer legal services, they have this in common: they seek money or your personal information.



People who unknowingly comply with the scams end up losing hundreds of dollars for so-called processing fees to collect lottery or sweepstakes winnings, or provide cyber-criminals with sensitive data such as bank account, credit card and Social Security numbers to clear up nonexistent problems with accounts.



In the latter case, such information has often left victims on the hook owing thousands of dollars in bogus charges, along with credit rating headaches. Another danger in opening such e-mails, or downloading provided links, is that virus or malware programs can be installed on the victims' computers. In recent years, such scams have become increasingly sophisticated, spoofing not only banks and other corporations official logos, but even government agencies -- among them the FBI itself.


Some good rules of thumb to avoid being scammed online:

  • Don't respond to unsolicited e-mail.

  • Don't click on links contained within an unsolicited e-mail.

  • Don't open e-mail containing attached files (i.e. pictures, documents) from senders you do not know. Or at the very least, run the attachments through your virus scanner before opening.

  • Don't fill out forms contained within e-mails seeking personal information, period.

  • If you do plan to follow a provided link, carefully compare the purported link in the e-mail with the link where you are actually directed, careful to make sure they match.

  • Or, log on directly to the official Web site of the business identified in the e-mail instead of linking to it from the e-mail. Better yet, contact the business by its telephone number -- as listed on your actual billing statements or official correspondence -- to verify the e-mail's claims.

Read more...

Monday, August 17, 2009

Twittergate: Update 3

Twittergate Reveals E-Mail is Bigger Security Risk than Twitter

First, everyone needs to calm down. Twitter.com itself was not breached. According to Evan Williams as quoted in a TechCrunch article, the attack did not breach Twitter.com or its administrative functions, nor were user accounts affected in any way. So everyone can just stop with the “Twitter needs to revamp its security!” and “Twitter isn’t secure” headlines and articles because it’s not only blatantly wrong, it’s diverting attention that should be devoted to the real problem: e-mail and account self-service.

What was compromised remains somewhat of a mystery. Following through the TechCrunch article to a blog on the same subject reveals some interesting details, however. A screen shot of what appears to be an internal memo to Twitter employees requires a change in passwords (along with instructions on improving the strength of said passwords) but mentions the password to be changed is the password you use to login to internal sites. From this one might infer that a breach was perpetrated through an intra/extranet, as opposed to twitter’s core infrastructure. Regardless, the breach of Twitter was only ancillary to the real security risk: the access to e-mail. That’s where the real meaty data was obtained; not from Twitter or its internal systems.

In this case, it was GMail access that enabled the miscreant to use password recovery techniques (“Forgot your password?”) to gain access to other related information and sites: personal credit cards, GoDaddy registrar accounts, etc… Did the attacker really need to breach Twitter’s internal applications to get that information? Probably not. Certainly gaining access to Twitter’s internal applications made accessing employees’ GMail accounts that much easier, but it likely wasn’t necessary except as a means to garner attentiongmail-logo which was, the miscreant claims, the intent of the attack. The danger of a GMail breach is that Google is very integrated across applications, so gaining access to one often makes it a no-brainer to gain access to others.

Read more...

Followers

Search This Blog

Who am I?

I am a law enforcement professional with over 35 years experience in both sworn and civilian positions. I have service in 3 different countries in both the northern and southern hemispheres.

My principal areas of expertise are: (1) Intelligence, (2) Training and Development, (3) Knowledge Management, and (4) Administration/Supervision.

  © Blogger templates The Professional Template by Ourblogtemplates.com 2008

Back to TOP