ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Automated phishing on the rise, experts say

Dan Ilet ZDNet.co.uk

Published: 23 Nov 2004 13:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Fraudsters are achieving higher levels of automation for phishing scams, using software tools and botnets to increase the reach of their work, research has found.

Security experts from the Anti-Phishing Working Group (APWG) have witnessed massive increases in the number of phishing Web sites, which they say suggests that scammers are improving their techniques.

"It was almost like the phishers had a holiday in August and September then came back harder in October," said Dave Brunswick, technical director of Tumbleweed and member of the APWG. "We had speculated this had levelled off, but this has showed us that it's not the case. We're still seeing a similar concentration on the banks being attacked."

Most of the Web sites targeted were outside of the US, the group said. It found that the number of sites being hosted on broadband computers had risen to more than 50 percent. Brunswick said the researchers had also found an increase in blended attacks.

"One concerning thing we've seen lately is some of the Trojans that are specifically attacking the banks. There is a blurring of edges between Trojans, viruses and phishing [scams]. I think we're seeing more sophistication in terms of what we predicted."

The group also found that 1,142 active phishing sites were reported in October, and that between July and October, the number of phishing sites grew by a monthly growth rate of 25 percent. Fraudsters hijacked 44 brands in that month and six of those comprised the top 80 percent of phishing campaigns. The group also found one Web site that functioned for 31 days, but it added that 6.4 days was the average time a site stayed active.

The APWG's members include representatives from law enforcement, banks, ISPs and a range of security companies. The group has more than 930 members worldwide from 590 companies.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
96 out of 181 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

3 comments

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

1 comment