Tuesday, April 25, 2006 2:00 PM PT Posted by Narasu Rebbapragada
Cloudmark, an anti-spam company, put the word out about a new type of email phishing scam targeting banking customers. These fake emails don't provide a URL for you to click--you're much too smart for that. Rather, they provide a phone number, which calls into a voice mail system that asks for your account number.
According to
Cloudmark, what's new here is the criminal use of VoIP and PBX (private branch exchange) software to set up a voice-mail system that sounds like your bank. The process is cheap and easy, thanks to VoIP and open-source PBX software such as
Asterisk. The same low-cost setup that's enabling small businesses to sound professional is enabling small-time scam artists to do the same.
"The convergence of the Internet with the phone system allows someone with VoIP to do what the big boys used to do," says Adam J. O'Donnell, Ph.D., senior research scientist at Cloudmark.
Cloudmark's enterprise spam filters found two such phishing scams, one targeting a small bank in a large U.S. city. Cloudmark says more than 1000 such messages were received over a three-day period. The scam artists set up a toll-free number and a number with area code.
Just like we warn you against clicking a URL in an email, we warn you against calling a phone number included in an email. Just like you're to enter your bank's Web site through the front door, O’Donnell says to only call the number on the back of your ATM card.
Yeah, yeah, yeah. Easier said than that--so simple! Don't trust that phone number from e-mail! EVER!!! Need I say more?
If I get a phishing e-mail, as a security measure, I will have to scan through headers and do a WHOIS lookup before I view the e-mail. If mismatched (e-mail, link, phone number, etc.), those e-mails will be reported to SpamCops and CastleCops.
But not everyone (average joe, to be more specific) wanted to do that (spotting fraud, reporting phishing fraud, etc.) on behalf for making Internet a better place for everyone to use...
Oh, and one more thing that I'd like to say to the phisher community:
"Sorry phishers, you can forge an e-mail address, but you can't hide!"
:) I think I should set up something like this on my site :) Wish you many live and quality visitors!
Take care of it and keep it on the road!
Keep it going, thanks. I found exactly the information.
Nice resource, good colors& design) So, you are good ;)
A resource for VOIP is at VoIP Provider http://www.1-satellite-tv-facts.com/VoIP.html
A compliment to VoIP is PBX phone systems and T1 Internet Service. More information about these services can be found at
http://www.1-satellite-tv-facts.com/T1-Internet-Service.html
http://www.1-satellite-tv-facts.com/Phone-Systems.html