Welcome!
If you have an account, please:
Log in
Stay Informed
Recommendations

Here's something that


I, Jeremy Duffy, actually recommend and think is worth checking out.
No web-bugs, no bs, just a legit recommmendation that I have personally evaluated before allowing it to be listed here:

Think something's here that shouldn't be? contact me!

How can I help you?
Contact Jeremy

Phishing

Phishing is an extension of an old scam where someone would call you pretending to be from your bank or the hospital and try to scare you into giving them information.

"Mrs. So-and-so, I'm Bill from the bank. Your account has been emptied and we're concerned that it wasn't actually you who did it. We can replace the funds, but we'll need to verify your identity. Please tell me your name, address, phone number, social security number, mother's maiden name, blood type, the time and duration of your last period (etc. etc.).

Here are some of the various types of phishing and what to do about them:

Account Phishing

Say a bad guy gets an e-mail from his bank warning of scams going around and to be careful not to fall for them. By copying the letter and just changing the end to list a link "for more information", he can easily have a very authentic looking e-mail to mass-distribute and hopefully con people with.

A fake e-mail...
...that leads to a fake website

Regardless of the form of the e-mail, the content tends to be very similar. Something's wrong with your account and you better log in quickly to find out what it is. The problem is that if you follow the link, the site you go to might look exactly like the real site, but it's actually a fake under the control of the bad guy.

Once you enter your name and password, you'll be redirected to the real site and will probably never realize that you just handed someone your login name and password. So when they told you that your account was empty, they were lying, but because you fell for their trick, soon it will be.

A phishing e-mail that's trying to get you to open an attachment. Don't fall for it!

Prevention

The simple solution is to never follow any link from an e-mail that claims to have come from your bank, your social sites, or anywhere else you have an account. Instead, open a browser window and go to that site or service directly (but make sure to use my search engine trick if you don't have it bookmarked). If the information in the e-mail about your "account being suspended" or whatever is true, you'll be able to find out by logging in normally or just calling the company.

The same goes if they want you to download an attachment, call a phone number, or make security changes to your computer. All of these can hurt you and help them if you don't verify the information before acting!

Spear Phishing

It's pretty easy to ignore an e-mail from a bank you don't even bank with. But what if the fake e-mail used your actual bank and addressed you by name? They might even refer to a recent communication you had with a real bank representative. Most people are far more likely to fall for a con that starts with authentic information.

Prevention

There are many ways bad guys can get that kind of data and you should do your best to prevent that, but the simple solution is the same as before:

When asked to call a number, follow a link, download a tool or attachment, or any other similar activity in an e-mail, just validate the message before acting on it!
Guide Navigation
prev: E-mail Viruses|INDEX|next: Nigerian Scam

E-mail Dangers

Until we find out who the people are who actually buy things from spammers and kick them off the Internet, you're going to have to learn how to deal with and prevent spam.
E-mail Viruses - Learn how viruses are spread through e-mail and how to stop them
Phishing - Spot and avoid lures that pull you into the dark side of the web
Don't be one of those people that loses thousands of dollars to the classic Nigerian Scam.

E-mail Etiquette

Use CC only when necessary and BCC the rest of the time.
Use Reply-All when you mean to and never when you don't.
Practice proper E-mail Forwarding to protect privacy and make e-mails more readable.
Always personalize your e-mails to make it obvious to your recipient that it's valid.

E-mail Tips and Tricks

Using E-Mail Aliases Properly - Be careful about using sensitive data (like your real name) in an e-mail account.
Remember to treat your e-mail account with the security it deserves.
Use a decoy e-mail account to keep your main e-mail account free of spam.
Avoid using any Internet provider's default e-mail.

Share This

Have a Comment or Question?

2 Comments to “Phishing”

» Comments RSS Feed

is it possible to make som kind of phishing security, where u have to be ip-recognized. so that all web-sites should ask for permission to become a real web-site?

    It definitely is possible though that would require cooperation between certain large companies and the mail systems. However, I’ve already seen some of this in Hotmail, but I stopped tracking it when Hotmail started getting worse and worse with every update. Stupid Hotmail.

If you want to learn more about my professional background, click here to learn more. Otherwise, let’s get started - how can I help?

Online learning
On-site learning
Read my blog