The hook and line of Phishing

Windows Live Staff
Phishing
It's easy to get caught in a phishing scam if you don't know how to spot the bait!

Got something in your inbox that just doesn't look right? Getting hooked by a phishing scam is one of the biggest risks online, make sure you know how to spot one.

While the branding at the top might look familiar, if you were to have taken the bait and replied to this e-mail, chances are your personal details (including your user name and password for your Hotmail account, along with your date of birth and country of residence) would have almost immediately fallen into the hands of an online criminal engaged in a "phishing" operation.

Phishing scams are run across the world by cybercriminal operations. They vary greatly in size and skill, from amateur one-person shows to sophisticated and highly resourced gangs of professionals. Sometimes they utilise networks of hundreds of thousands of hacked, "zombie" computers to send off bogus e-mails to "phish" for users' details, which can then be sold to gain access to a victim's bank or credit account, or used in various other types of fraud.

This recent phishing campaign, operating under the Windows Live Hotmail banner attempts to dupe users by claiming that a large number of "unused" Hotmail accounts have been deleted to free up space on the network, requiring the user to confirm their details to avoid having their account deleted.

"This is classic social engineering," says James Turner, security advisor at research group IBRS. "If it contains something where you have a vested interest in replying then it's all the more likely that the e-mail is not on the level.

"Access to your e-mail account can become something like a honey pot for phishers. Given that a lot of users share the same password across any number of different sites and platforms, it doesn't take a great stretch of the imagination to see how someone could start making some serious money at your expense if your banking details are linked to something like eBay or Amazon."

Although there is a fair amount you can do to secure your inbox, there's no way to stop every single suspicious e-mail from sneaking through. So the best way to protect yourself is to know how to spot a nasty.

"If you receive an e-mail like this, asking you to do something like this, you should go to the point of origin and check it there," says Turner. A recent Windows Live security announcement takes this a step further, claiming "no legitimate company" will ever ask you to provide a user name, password, date of birth or country of origin via e-mail. Nor will a legitimate company ever issue an ultimatum or warning like the one shown here.

By and large, scam e-mails tend to be poorly written, and conventional wisdom suggests that this alone can be a dead giveaway. But Turner believes users should be on the lookout for more than just sloppy grammar: "The sad fact is that a lot of e-mails from major organisations are going out with really poor spelling and expression anyway," he says.

In other words, stay smart.

Got a phishing story? Why not share it with us below.

SHARE:
MESSENGER
FACEBOOK
MORE
Blog on Spaces
Add to delicious
Add to Digg
Share on MySpace
?
Share, bookmark, and save your favourite ninemsn articles and features.  Learn more.
User comments

Write a comment
Email: *
Your email will not be shared with any third parties or published with your comment.
Nickname: *
Location: *

Subject:
*
Comment:
*
Maximum characters 1000

Comment guidelines
Avoid using:
  • Personal attacks
  • Irrelevant comments
  • HTML tags
  • Personal information
  • Offensive language
  • Text in ALL CAPITAL LETTERS
See full comment guidelines
Comment guidelines X
Thank you for sharing your opinions with other users of NineMSN. People will find your comments more helpful if you include relevant information and avoid some common pitfalls.
Please note: All reviews and comments submitted are subject to moderation, NineMSN reserves the right to alter and / or remove any content that does not comply with usage guidelines.
What to include in your comment:
  • A title that briefly summarizes the opinion expressed in the comment.
  • Additional comments adding more detail.
  • Comparisons to other similar products, if this is relevant.
  • To create a new paragraph, press the Enter key twice.
What not to include:
  • Information that will quickly go out of date.
  • Comments on other comments or commenters.
  • Language that other users may find offensive.
  • comments of one sentence or less. Provide information to support your opinion.
  • Personal information like your email address or telephone number.
  • HTML coding. Tags like <b> or <i> will not be recognized.
Express yourself to your world, with blogs, videos, photos and more to share — from one location.
advertisement
What's new with Windows Live
Emoticon World has arrivedFrom Twilight to the buddy classics, you can get all your free emoticon packs here! Windows Live MessengerTime to upgrade MessengerIt''s a big heads up from us — to continue using Messenger you''ll need to upgrade to the latest version soon. Bank vaultCheck out our Online Safety HubThe Windows Live Online Safety Hub is here to offer tips on how to protect yourself and your family online.

Other ninemsn businesses: iSelect RateCity
© 1997-2009 ninemsn Pty Ltd - All rights reserved