Latest phishing scam most "devious" ever

Summary:A prominent anti-virus vendor has described the latest e-mail fraud scheme targeted at Westpac bank customers as the most "devious" the company has ever encountered.The e-mail, distributed en-masse to Westpac customers, represents the latest example of "phishing scams," designed to catch the unwary and fool them into divulging their online banking security details.

A prominent anti-virus vendor has described the latest e-mail fraud scheme targeted at Westpac bank customers as the most "devious" the company has ever encountered.

The e-mail, distributed en-masse to Westpac customers, represents the latest example of "phishing scams," designed to catch the unwary and fool them into divulging their online banking security details.

Typically, phishing scam e-mails appear to have been sent from the victim's bank, and contain a link to a fake version of the bank's Web site and instructions to log on to the site to verify their credentials with the bank.

Rob Forsyth, managing director at anti-virus vendor Sophos, believes that the techniques used by online confidence tricksters in the latest Westpac e-mail indicate the scheme is reaching new heights of sophistication.

According to Sophos the scammers have become better impostors, incorporating phrasing and wording into the email that the bank's customers would be familiar with from previous authentic advisories it had issued such as: "Westpac will never ask for your personal or login details by e-mail" -- even though it then proceeds to direct the reader to do just that.

The architects of the latest scam also adopted a more insidious Web re-direction technique to bamboozle victims than Sophos had ever seen before. Activating the link in the e-mail directs the victim to a fake version of the site but also opens an authentic copy of the site in a second browser window behind it.

The fake version of the site asks for the victim's account access details but returns an error message if he or she attempts to use it. The victim is then sent to the real site unaware that they've been duped.

Forsyth fears that the practice of phishing is at risk of being trivialised in the public's mind. He said that the malicious nature of the crime should be acknowledged.

"I think this is not just a scam like the Nigerian scam -- this is actually direct fraud and the perpetrators of the crime should be dealt with severely," said Forsyth.

Andreas Baumhof, chief technical officer, Microdasys, a German-based Internet security company specialising in Secure Socket Layer (SSL) technologies used to protect commercial Web transactions, is also concerned for the well being of online banking customers.

He said that advice given to the public is often wrong, pointing to a recent high profile case of phishing in the US involving ISP Earthlink.

Shortly before the scam the US Federal Trade Commission advised the public to look for an icon depicting a lock in the window of their Browsers when conducting sensitive transactions. The lock icon is associated with SSL Web security technology which involves encryption and security certificates. The FTC issued blanket advice that such communications were definitively "safe".

Baumhof said the advice was wrong and may actually have contributed to the Earthlink incident. In that case the scam's designers used encrypted SSL conections to direct users to their site but fraudulent certificates to persuade victims they were in the right place. Baumhof reasons that the FTC's advice gave the victims a false sense of security.

"You can only see that the session is encrypted but you can't tell who you're talking to unless you've verified the certificate," said Baumhof.

Meanwhile, Sophos said it had conveyed its concerns to the Australian High Tech Crime Centre.

Topics: Browser, Banking, Enterprise 2.0, Malware, Security

Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Related Stories

The best of ZDNet, delivered

You have been successfully signed up. To sign up for more newsletters or to manage your account, visit the Newsletter Subscription Center.
Subscription failed.