SAN FRANCISCO — Google and Yahoo! on Tuesday joined a growing roster of Web-based email service providers with users duped by hackers into betraying passwords to accounts.
A day after Microsoft blocked access to thousands of Hotmail accounts in response to hackers plundering password information and posting it online, the list of victims was growing to include users of an array of email services.
"We recently became aware of a phishing scheme through which hackers gained user credentials for Web-based mail accounts including a small number of Gmail accounts," Google said in response to an AFP inquiry.
"As soon as we learned of the attack, we forced password resets on the affected accounts. We will continue to force password resets on additional accounts if we become aware of them."
Cyber-crooks evidently used "phishing" tactics to trick users of free Web-based email service into revealing account and access information.
"We are aware that a limited number of Yahoo! IDs may have been made public," Yahoo! said in a statement to AFP. "Online scams and phishing attacks are an ongoing and industry-wide issue."
Time Warner subsidiary AOL, in response to an AFP inquiry, said it is "closely monitoring the situation."
"Our guidance to users is to keep your wits about you: do not click on live links, or insert any details into input fields in emails, pop-ups or Web pages if you are not sure where they come from."
Microsoft said Monday that it learned of the latest problem during the weekend after Hotmail account information of "several thousand" users, many of them reportedly in Europe, was posted at a website.
The unconfirmed list of Hotmail accounts compromised by "phishing" has grown into the tens of thousands.
"We are aware that some Windows Live Hotmail customers' credentials were acquired illegally by a phishing scheme and exposed on a website," Microsoft said. "We have taken measures to block access to all of the accounts that were exposed and have resources in place to help those users reclaim their accounts."
Phishing is an Internet bane and involves using what hackers refer to as "social engineering" to trick people into revealing information online or downloading malicious software onto computers.
Phishing tactics include sending people tainted email attachments that promise enticing content such as sexy photos of celebrities and luring people to bogus log-in pages that are convincing replicas of legitimate websites.
Microsoft, Google, and Yahoo! stressed that hackers did not breach their databases, but rather email users were conned into revealing information.
"Phishing is an industry-wide problem... exercise extreme caution when opening unsolicited attachments and links from both known and unknown sources, and install and regularly update anti-virus software," Microsoft said.
Google advises Gmail users not to "click through" on warnings browsers may raise about certificates nor sign in at Web addresses that don't start with google.com/accounts.
Web-based email users who suspect their accounts have been compromised should change passwords and check to make certain any secondary email or texting options in accounts have not been changed.
"We encourage users to be very careful when asked to share their personal information," Google said.
The email service providers urged people to visit pages at their websites with advice and tools for protecting accounts.
AFP
Showing posts with label Phishing websites. Show all posts
Showing posts with label Phishing websites. Show all posts
Tuesday, October 6, 2009
Thursday, October 1, 2009
Phishing websites, rogue antivirus skyrocket in 2009
The number of unique phishing websites reached a high of nearly 50,000 in June, the second highest on record since more than 55,000 phishing websites were recorded in April, 2007. Meanwhile, the number of people downloading and installing rogue antivirus programs is also on the rise, providing a cash cow to cybercriminal gangs. In the first quarter of 2009 alone, more new strains of rouge antivirus were created than in all of 2008, according to the APWG Phishing Trends Report.
The organization, an industry association of security vendors, individual businesses and business trade associations, started in 2003 and has monitored phishing and email spoofing with the goal of finding ways to reduce and ultimately eliminate the problem. The report includes data collected by security vendors Websense Inc. and Panda Security, as well as brand jacking information from Mark Monitor Inc.
Rogueware, phishing:
Panda reports fast-spreading rogueware antivirus fraud rakes in millions: Rogueware fake antivirus strains are increasing at a stunning rate. Panda Security reports that this cyber crime bilks users out of about $34 million every month.
Can mutual authentication beat phishing or man-in-the-middle attacks? What's the best way to prevent phishing and man-in-the-middle attacks? IAM expert David Griffeth explains the benefits of mutual authentication over one-way SSL.
Phishing, identity theft keeps law enforcement, researchers occupied: An expert on cybercrime and online scams, Derek Manky, is one of the members of the Fortiguard research team
Rogue antivirus displays fake pop-up warnings and launches messages in the task bar warning of a possible infection. Once downloaded, the program typically conducts a fake scan of a victim's system and then provides results showing fake infections.
In June, the number variants of rogue antivirus programs increased above 152,000, according to the APWG. The number of rogue antivirus variants detected was four times as many samples as in all of 2008.
Luis Corrons, technical director of PandaLabs, the research arm of Panda Security, said the lucrative business model has attracted new cybercriminal gangs that are helping fuel the increase in rogue antivirus. Panda estimates that victims are shelling out $34 million per month worldwide for rogue antivirus programs. There are currently more than 200 different gangs being tracked by researchers. Ten gangs are responsible for more than 77% of the rogue antivirus samples, he said.
"Unlike with banking Trojans, where you have to infect the user, steal the data, then hire some money mule with rogueware they only have to wait for users to pay," Corrons said. "The user is the one willing to pay in order to disinfect their computer." SearchSecurity radio:
According to security experts, the rogueware has been spreading by less sophisticated means. They rely on rouge antivirus-touting website visitors to download and install the program. But phishers have been successful in avoiding detection by legitimate antivirus programs, according to the APWG report. Each downloaded rogue antivirus program contains a slightly different binary file, which tricks signature-based antivirus. In addition, Corrons said the programs themselves don't act maliciously on computers, other than displaying false information, which helps them evade detection from antivirus engines.
Search Security
Props to my buddy Eric Cissorsky on this one too!
Subscribe to:
Posts (Atom)

