Plan Finder Complete Guide Articles and Reviews Downloads About Us
Email Service Guide

Avoid The Hook: Protect Yourself Against Phishing

1 Comment »
November 1st, 2009
Chris Hoke

phishing_loginThe technology news headlines have lately been buzzing with news of recent widespread phishing attacks. One report from earlier this month states that a phishing scheme aimed at email users took in more than 20,000 email addresses and passwords. The FBI director even admits to a brush with such a scam, which prompted his wife to take over the responsibility of their online banking.

When it comes to phishing scams, a compromised email account can be the least of your problems. Many people use the same password on several websites, including their online bank accounts. Information gathered through various online accounts can be used to steal not only your money, but your identity. Criminals can then use your stolen identity to obtain medical care, loans, or commit crimes in your name.

Phishing efforts can be particularly devious in the current economic climate, preying on fears that our money might not be safe with the financial institutions we use. Recent bank mergers also give criminals an opportunity to collect your password. Emails might pretend to be from your local bank’s branch manager, your credit card company, or even your investment broker. A particularly nasty scam that impersonates the Internal Revenue Service (see image below) demands your financial information and threatens an audit if you do not comply immediately.

As fraudulent email scams become more sophisticated, the average user must become proactive regarding their online security. Armed with common sense and the knowledge of what you should be looking out for, anyone can learn to avoid phishing scam and protect themselves from becoming another victim.

phishing_irs

How to Recognize a Phishing Scam

Gone are the days of being able to spot a fraudulent email scheme because of extensive spelling and grammar errors. Modern cyber criminals create pitch-perfect emails, complete with stolen images and boilerplate text that has been stripped from the very websites they are emulating. The return email address can no longer be trusted either: messages can ostensibly be from a family member, a friend, a social networking site you frequent, or a corporate website. Below are a few tips on recognizing a fraudulent email.

  • Beware emails that encourage you to “Verify your account” or ask you to “Respond within 48 hours or your account will be closed.” or even “(Your bank or workplace) has installed new security measures. Please login here to verify your info.” These typical phrases are known as “calls to action” that lead you to click on a link and divulge information. When an official-looking email makes you feel rushed, take a step back and reevaluate it. When in doubt, call or email the company directly (don’t reply) and verify that the message is genuine.
  • Ignore emails that tell you that you’ve won a “lottery” or special “drawing”. These are usually advanced fee scams, where you need to give up some amount of money in advance before you receive a lump sum (which never comes).
  • Avoid email links that go to “misspelled” corporate addresses such as Micorsoft.com, Googel.com, Yahooo.com, PayPa1.com, PayPaI.com (uppercase “i” or numeral one instead of an “L”).
  • Also avoid links that will take you to an IP address (e.g. 192.0.32.10). Some links may look legitimate at first glance, but by hovering over a link in most browsers, you can see where it will actually take you.
  • Learn to spot newer “spear” phishing scams. Now that many of us know not to send sums of cash to wayward Nigerian princes, the criminals have devised a more personal approach to scamming you: emails that contain information such as your full name, the last few digits of your social security number, your home address, or the knowledge that you are in a desperate financial situation. These emails lull you into a sense of security and believing that they already possess all of your information makes you more apt to fill in the blanks for them.

Five Steps To Staying Secure

  1. Don’t give out personal information through email and don’t follow links from emails to websites that prompt you for your login ID, password, social security number, address, or any other information. Simple in theory, difficult in practice.
  2. Use a web browser with a built-in anti-phishing filter or that monitor websites for phishing attempts, such as Internet Explorer 8, Firefox 3.0, Google Chrome, Opera 9.2, and Safari 3.2. Keep your browser updated.
  3. Use email encryption when sending potentially sensitive information such as passwords and financial information.
  4. Check potential phishing websites against Phishtank.com.
  5. If a site asks you for your password, enter a false one. If the site accepts it as valid, then it was probably phishing. Report it.

phishing_chase

What to Do If You Think You’ve Been Hooked

  • Act quickly. First, change your email password, then your account passwords. If you change your account passwords before your email password, the accounts usually send a copy of your new password to your email address. Make sure your email address is not set to forward messages.
  • If you believe your online banking password has been compromised, change your password immediately and alert your branch manager.
  • If you’ve accidentally given out credit card information or your social security number, ask the three major credit bureaus to put your credit report on “fraud alert” which will help you recover your credit rating if it’s abused by criminals.
  • Close any unnecessary financial accounts that you know or feel may be compromised.
  • Go here for more information: http://www.ftc.gov/bcp/edu/microsites/idtheft/

A common mistake that many people make is thinking that they won’t fall for these scams because they’re net-savvy. But as smart as you are about avoiding phishing scams, a criminal’s job is to stay one step ahead. By adopting a few standard safety procedures when it comes to email, and practicing them faithfully, you can keep your personal and financial information, and your identity, safe from cyber criminals.

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Mixx
  • Google Bookmarks
  • LinkedIn
  • Posterous
  • Reddit
  • Slashdot
  • StumbleUpon
  • Suggest to Techmeme via Twitter
  • Technorati
  • Twitter
Tags: phishing, phishtank, scams, security Posted in Tips 1 Comment »

One Response to “Avoid The Hook: Protect Yourself Against Phishing”

  1. Tweets that mention Email Service Guide – Avoid The Hook: Protect Yourself Against Phishing -- Topsy.com says:
    November 2, 2009 at 4:46 AM

    [...] This post was mentioned on Twitter by Email marketing, etc, Email Service Guide. Email Service Guide said: Avoid The Hook: Protect Yourself Against Phishing http://bit.ly/eeWGp #phishing #scam #email [...]

  • RSS Feed
  • Facebook Fan
  • Twitter Feed
Old school? Join our mailinglist.

Latest Articles

  • 02/03 - Email Marketing Pt. 3: MadMimi, Aweber, Benchmark, iContact, CampaignMonitor Reviews
  • 01/28 - Atmail 6.1.3 is out. Now supports LDAP and Active Directory
  • 01/28 - Email Marketing Pt 2: MailChimp, ConstantContact, EmailBrain, LetterPop Reviews
  • 01/26 - Making Facebook’s messaging system IMAP compatible
  • 01/26 - Pegasus Mail 4.52 is out
  • 01/20 - Email Marketing Part 1: An Introduction
  • 01/14 - Major new deal for LotusLive
  • 01/13 - Gmail is now more secure.
  • 01/12 - It’s official: VMware+Zimbra=True
  • 01/12 - Finally two-way email communication with Facebook

Resources

  • Downloads
  • Browse our download-section that includes a number of email-related virtual appliances.
  • Email Troubleshooting Guide
  • A complete guide for troubleshooting IMAP, POP3 and SMTP.

Sponsored Link: YippieMove

Need to transfer email between accounts? The YippieMove email migration tool lets you do that easily online.


Tags

    ActiveSync AOL apocalypse Atmail chat client collaboration Exchange Facebook FastMail.FM Gmail Gmail Labs Google Google Apps Google Wave Hotmail IBM IMAP iNotes iPhone LotusLive Microsoft mobile Mozilla Open-Xchange Outlook phishing POP3 productivity reMail review SaaS security social network spam T-Mobile threadsy Thunderbird Tips Twitter VMware Windows Live Yahoo Zenbe Zimbra


Archives

  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009

Connect with us!

  • Suggest an article
Got feedback, questions? Contact us. Advisory information only. Data may not be current or correct, prices and terms are based on our best interpretation of relevant user agreements. Database includes both affiliated and non affiliated providers. © 2009 WireLoad, LLC