Don’t Be “Phooled” By Phishing Federal Trade Commission National Consumers League Microsoft Corporation March 31, 2005
Susan Grant Director, National Consumer League’s National Fraud Information Center and Internet Fraud Watch Program
Phishing Statistics #4 Internet Fraud #10 Telemarketing Fraud – National Fraud Information Center / Internet Fraud Watch, National Consumers League, 2004 43% or 91 million U.S. adults have received a phishing contact Of those 5% or 4.5 million U.S. adults have provided personal information to phishers – STAR/First Data, November 2004
Can You Spot a Phish? Jacqueline Beauchere Business Strategy Manager Microsoft Corporation
Deceptive Address Source code reveals actual mail from address as msn-network.com Deceptive Link Source code reveals that the actual address linked to is href= msnupdate.com/?sess=qCKWmHUBPPZwT8n 4GEMNh7owHDEGt40IHKG5tAGiqGOjNeovRc msnupdate.com/?sess=qCKWmHUBPPZwT8n 4GEMNh7owHDEGt40IHKG5tAGiqGOjNeovRc The difference between these two URLs could be a sign that the message is fake. (However, even if the URLs are the same, don't let down your guard, because the pop-up could be a trick, too.) Alarmist Message Criminals try their best to create a sense of urgency so you'll respond without thinking. Also, look for misspellings, grammatical errors, and typos--such as “…an access to MSN services for your account…” Unpersonalized Messages Be wary if a company you regularly do business with fails to address you by name.
Know the Company eBay generally does not send out s to customers containing login links. Look carefully at the status bar for all links and URLs—the URL in the status bar for the login link is not eBay.com. Differences between links or URLs in an and the status bar should make you suspicious. If you receive an like this one, open a new browser window, type in the URL yourself and login into your account to see if there are any real account problems. PHISH
Look carefully at the link. See sign? This is a common phishing trick. In some browser applications, when a URL uses sign, everything to the left of sign is disregarded and the browser only reads to the right of sign. When you see or suspect trick, be suspicious. If you think that the sender of the has no legitimate association with the domain you see there, suspect a phish. PHISH
Aaron Kornblum Internet Safety Enforcement Attorney Microsoft Corporation
MSN Billing Phishing Case 3 Subpoenas identified ISP in Austria 5 Subpoena to Qwest and investigations identified Jayson Harris in Iowa, US 1 MS filed John Doe lawsuit in WA 6 Referred to FBI and obtained $3 million Default Judgment 2 Issued subpoenas to web hosts in CA 4 Austrian ISP identified IP address registered to Qwest in the US
Lydia Parnes Acting Director, Bureau of Consumer Protection Federal Trade Commission
Tip Number 1 : If you get an or pop up message that asks for personal or financial information, don’t reply, and don’t click on the link in the message. Legitimate companies don’t ask for this information by Tip Number 2 : Don’t personal or financial information. Tip Number 3 : Read your credit card and bank account statements as soon as you receive them to spot any unauthorized charges Tip Number 4 : Use anti virus software and a firewall, and keep them up-to-date. Tip Number 5 : Report suspicious activity to the FTC.