Phishing attacks are email scams that attempt to defraud consumers of their personal information, such as bank account details or social security numbers, by pretending to have been sent by a trustworthy entity such as a bank or credit lender.
The survey revealed that:
- 42% of respondents surveyed feel that the trust in a brand would be greatly reduced if they received a phishing email claiming to be sent by that brand.
- 41% of those surveyed felt that their trust in a bank would be greatly reduced if they received a phishing email claiming to be from that company, compared to 40% who felt the same for an ISP, 36% for an online shopping site and 33% for a social networking site.
- 26% of those surveyed feel that they are the party most responsible for protecting themselves from phishing attacks, with 23% believing their Internet Service Provider (ISP) or email service provider is the most responsible and 17% thinking that the sender's ISP and email service provider holds the greatest responsibility.
"Phishing is a highly sophisticated and well orchestrated form of crime. The gangs behind these attacks work to compromise financial information via e-mail scams and then propagate that information into a highly stratified and efficient economy, selling the data on to those who will profit from the accounts," commented Neil Cook, UK technology chief at Cloudmark. "Earlier this year we conducted research into the effect that phishing has on the individual that found consumers were still extremely concerned about falling victim to such a scam. What is interesting to note from these results is that well-known brands are also suffering, with phishing attacks having a detrimental effect on their reputation. This knock-on effect will be particularly worrying for the banks, who rely on a high degree of trust with their customers."
In addition to the YouGov survey, Cloudmark's own research team today released results showing that Natwest Bank was the most phished brand in the UK during October 2007. The research was collected using Cloudmark's user base, which consists of 260 million mailboxes. Cloudmark's research also indicates that across Europe, the majority of unique phishing websites are created using the top level domain associated with the United Kingdom, .uk.
"Not only are we seeing evidence of more .uk phishing URLs, but also a shift in phishing techniques. Vishing is a good example of this where the scammers use cheap VoIP call centre systems as the back end to their phishing attacks, which changes the whole dynamic of trust," commented Cook. "The example we've seen on our database was a message attack that appeared to be a notification from the recipient's bank requesting they ring customer services to deal with a problem. If the recipient makes the call, it gets routed to a cheap VOIP answering system, which may have been set-up on a compromised host. The system captures the user ID and pincode to sell on to the highest bidder, who then has full access to your account. All the while the call seems very genuine. The reassurance of speaking to an individual rather than working online will lead to many instances of consumers falling foul to such threats."
"Whilst awareness to the problem is essential, it is unrealistic to expect businesses to be able to secure themselves fully against such sophisticated criminal activities. The increasingly dynamic and transient nature of the latest threats requires a combination of desktop protection at the client level, and accurate message filtering from ISPs. By including comprehensive phishing detection ISPs will help ensure protection against the latest threats and outbreaks," commented Nigel Stevens, Product Director, THUS plc.
Cloudmark uses an innovative way of stopping spam and phishing attacks, through a combination of intelligent algorithms and a global threat network of trusted reporters in 163 countries. By using this approach, Cloudmark is able to detect and block many attacks and variations automatically, without the need for manual rule writing, as required by other systems. The automation in the system means that the entire Cloudmark network can be protected against new threats within minutes of them first being detected.
For the top 10 tips on how to avoid malware and protect yourself from dangerous online behaviour, please visit www.cloudmark.com/....
About the Survey:
All figures, unless otherwise stated, are from YouGov Plc. Total sample size was 1,960 adults. Fieldwork was undertaken between 12th - 14th November 2007. The survey was carried out online. The figures have been weighted and are representative of all GB adults (aged 18+).
About THUS
THUS plc provides communications solutions to business customers throughout the UK under the THUS and Demon brands. In an industry punctuated by inexperience THUS can draw upon a knowledge base established over more than a decade in the delivery of data, telecoms and Internet services.
Delivering both standard and bespoke solutions THUS endeavours to address customers' existing business needs and works hand in hand with customers to develop new business opportunities. THUS' record in the creation of innovative new services is complemented by an award winning focus on quality and full certification of its internal processes and procedures under the ISO9001 standard.
THUS is listed on the London Stock Exchange. For further information visit http://www.thus.net and http://www.demon.net.