Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Friday, January 27, 2012

Phish NET Stalkings available on ebook

All Jane wanted was to find love. Was that too much to ask?

How difficult could it be to find one man, the perfect man for her? After dating the losers of the century, Jane decides there has to be a better way. She turns to an online dating service. After all, they guarantee a ‘happily ever after’ or your money back.

Jane East, CEO of Not-So-Plain-Jane’s organic cosmetics wants to fall in love with a man who makes her toes curl when he kisses her. Unfortunately, the one man who makes her toes curl also wears ladies’ pink underwear and a badge. The pink underwear she could probably deal with, but the badge is a different story.

Ever since seeing her mother and granny Pearl murdered by men with badges, Jane has a fear of cops and anyone who carries a badge. Especially, because the killers are still on the loose and searching for her.

Former FBI Cybercrime special agent turned small-town Chief of Police, Cooper Chance, gets caught with his pants down and his family jewels tucked in pink ladies’ underwear with lacy frills when he meets the woman of his dreams. That’s not his only issue. The woman has a fear of cops. If he can get past her guard, maybe he can save her life.

The ebook is out now and available at:

www.allromancebooks.com

www.amazon.com

Phish NET Stalkings will be available at Barnes & Noble and in print soon!!

Friday, January 8, 2010

Gone Spear Phishing

Yesterday we discussed Phishing, the most common form of social engineering that targets a large number of people in the hopes that someone, anyone gullible enough will take the bait.

Today we move onto Spear Phishing, which are focused attacks and seem to come from people you know. Much as a fisherman uses a spear to target a single fish, spear phishing targets individuals. Where cyber criminals might send a single, mass email to a couple hundred thousand people in a phishing attack, spear phishing attacks are customized and sent to a single person at a time.

How does spear phishing work?

First, criminals need some amount of inside information on their targets to convince them the e-mails are legitimate. Often criminals obtain this “inside” information by hacking into an organization’s computer network or sometimes by combing through other websites, blogs, and social networking sites.

Once the criminals have your name and whatever other personal information they could retrieve they send emails that look like the real thing to targeted victims, offering urgent and legitimate-sounding explanations as to why they need your personal data. Just as in a phishing scam, the victims are asked to click on a link inside the email that takes them to a phony but realistic-looking website, where they are asked to provide passwords, account numbers, user IDs, access codes, PINs, etc.

Unlike phishing scams where the email is addressed to “Dear Valued Customer,” the spear phishing email usually contains personal information such as a name or some tidbit about employment. They are unique emails, rather than being the mass “your bank account has been compromised,” type emails that are more common in phishing.

Spear phishing is a greater threat because the email message is addressed to a name and not a generic addressee. In addition, the email may contain other legitimate information about the receiver. The email message might look like it comes from your employer, or from a colleague who might send an email message to everyone in the organization, such as the head of human resources. It might include requests for user names or passwords or might contain malicious software, like a trojan or a virus, but by all accounts, the message appears genuine.

How can you identify Spear Phishing emails?

Spear phishing is a more sophisticated type of social engineering than phishing, but the techniques used to avoid being scammed are the same with the exception of now the cyber criminal sends the message addressed to you with your name.

Just because the email is addressed to your name does not mean the email is legitimate, be suspicious. As long as the email is requesting you to click a link or provide personal information then be wary.

If you do not see "https" in the link, do not proceed. Roll your mouse over the link and see if the pop-up matches what appears in the email. If there is a discrepancy, DO NOT click on the link.

If you receive an email requesting your personal information, it is probably a phishing attempt. The whole point of sending phishing email is to trick you into providing your personal information.

If there is a sense of urgency, be suspicious.

If you see misspellings or bad grammar, do not proceed.


What to do if you responded to a phishing scam?

If you suspect you have responded to a phishing scam with personal or financial information, take the following steps to minimize any damage.

Report the incident

Contact your credit card company or bank if you have given your credit information. The sooner an organization knows your account has been compromised, the easier it will be for them to help protect you.

Contact the organization that you believe the forged information came from directly, not through the email message you received.

In the United States, report the circumstances to the Federal Trade Commission: National Resource for Identity Theft. http://www.ftc.gov/bcp/edu/microsites/idtheft/

You can also report the phishing scam to the Anti-Phishing Working Group and to the FTC at spam@uce.gov. Visit their website at http://www.ftc.gov/bcp/edu/microsites/spam/index.html for further information.

Change all your passwords

Change all your passwords and start with passwords related to financial institutions or information.

Change all your passwords and make sure they are STRONG passwords. What is a strong password?

An ideal password is long and has letters, punctuation, symbols, and numbers.
Whenever possible, use at least 14 characters or more.

The greater the variety of characters in your password, the better.

Use the entire keyboard, not just the letters and characters you use or see most often.

Don’t be caught off guard

Visit the Internet Crime Complaint Center (IC3) http://www.ic3.gov/crimeschemes.aspx and LooksTooGoodToBeTrue http://www.lookstoogoodtobetrue.com/ websites for tips and information.



**I hope the research for my latest novel has made you a little more security conscious.**

Thursday, January 7, 2010

Gone Phishing

No, I'm not talking about the kind of fishing where you use a rod, reel, and bait.

The kind of phishing I am referring to is the most common form of social engineering. Before I delve too deep, let me take a step back and define phishing. Phishing is the process of falsely posing as a legitimate enterprise through an email or website in an attempt to acquire sensitive information such as usernames, passwords and credit card details. In short, it’s a scam.

Hmm. Maybe phishing does involve rod, reel, and bait. Rod would be the email or website you receive or visit. Bait would be the load of crap the supposed legitimate email or website is spewing. And the Reel is the link you click on that takes you to the place where you put in the information they just scammed from you.

Let's get into a little more detail. One example of phishing is a fraudulent email or website.

Phishing scams employ fraudulent e-mail messages or Web sites that try to trick you into revealing personal information.

Who has not received an e-mail message appearing to come from your bank or other financial institution that asks you to update your account information?

The e-mail message includes a link that appears to go to a legitimate site, but really takes you to a spoofed or fake Web site.

Does this email message look familiar? Or have you seen a similar email message in your inbox?

Dear First Bank User,

As a courtesy to our valued customers, First Bank conducts regular account verification processes.

In order to ensure your account information is not made vulnerable please visit http://www.firstbank.com.aaccount-update-info.com.

Please click on the above link to our website to confirm or update your account information. If you do not do this within 48 hours, you will not be able to use your First Bank account for 30 days.

Sincerely,

First Bank


**If you enter your login, password, or other sensitive information, a criminal could and would use it to steal your identity.**

How can you identify Phishing emails?

If you don't see your name, be suspicious. Notice the generic greeting. Internet criminals tend to send phishing emails in large batches and to save typing time the criminals use generic names like "First Bank Customer".

If you don't see "https", do not proceed. Notice the forged link. Even if a link has a name you recognize somewhere in it, it does not mean it links to the legitimate company. Roll your mouse over the link and see if the pop-up matches what appears in the email. If there is a discrepancy, DO NOT click on the link. Notice how the link starts with “http”. Secure websites where it is safe to enter personal information begin with "https" — the "s" stands for secure.

If you receive an email requesting your personal information, it is probably a phishing attempt. The whole point of sending phishing email is to trick you into providing your personal information.

If there is a sense of urgency, be suspicious. Notice the time sensitivity. The faster the criminal gets your information, the faster the criminal can move on to another victim. Internet criminals want you to provide your personal information now. They do this by making you think something has happened that requires you to act fast.

If you see misspellings or bad grammar, do not proceed. Phishing e-mail messages often include misspellings, poor use of grammar, threats, and exaggerations.


Tune in tomorrow when I discuss Spear Phishing.

In the meantime, DO NOT reveal any personal information in e-mail or online unless you know who you are dealing with and why. Additionally, make sure you are in a secure environment.

  © 2009 DENISE ROBBINS | Design and graphics by Will Design For Chocolate | Blogger template 'Contemplation' by Ourblogtemplates.com