Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Saturday, October 14, 2006

Your Federal Reserve Bank account has been accessed! Again!

Phishing is an ever-growing problem. Even if you realize the website to which you are directed is not the one from your bank, you are still vulnerable to a number of things. Check out my previous post for the serious side of things.

For some of us, it is one of growing amusement as well. I have a list of email addresses from various companies I forward phishing email to. ("Your Citi account has been violated!" yeah right.) Since I never get just one, I put the report-phishing email addresses in my addressbook. I've got one for the head of security at a credit union. The second time I sent him something, he sent back a thank you, as he hadn't seen that one or the website they were operating from. The last time I sent him something, I said any time he wanted me to stop, just let me know. Haven't heard a thing. I hope some yah-hoo doesn't decide that I'm this great world traveler, based on the "accounts" I have all over. According to the email I get, I have accounts in Alaska, Alabama, Kansas, Indiana, Texas and Tennessee. Oh, and two different accounts in Hawaii.

Man, do I travel a lot, or what?

And with Citi, BofA, Chase, Amazon.com (my credit card with Amazon had been accessed - does Amazon have a credit card?), an assortment of credit unions, the National Credit Union Association (they don't have accounts - I'm waiting for the one about my account with the Federal Reserve Bank), Visa (visa doesn't have individual accounts either), and a host of others.

I choose to be amused. And fight back. To report phishing or spam, these email addresses are useful:

reportphishing@antiphishing.org

spam@uce.gov

Wednesday, June 14, 2006

Your Federal Reserve Bank account has been accessed!

Phishing is an ever-growing problem. Even if you realize the website to which you are directed is not the one from your bank, you are still vulnerable to a number of things.

  • The most common vulnerability, of course, is entering your username and password. The phisher now has that, and can access your account(s) at will.
  • You can, and often do, get cookies containing malicious code from these phishing websites. Since most sites require you to be able to have cookies enabled to be able to use the site, most people accept most cookies. Most are harmless marketing tools. Those few that aren't, however, can contain software called "key loggers," that logs all keystrokes you make and then forwards them to the phisher. This means every time you type in your username and password, the phisher gets it. For every account you access. Personally, I delete my cookies once a day, and more often if I've gone to a web store to buy something. If I get popups, I very definitely delete my cookies. Most are harmless, but I can't tell which are which. And don't want to take the time to learn.
  • And since Microsoft makes its software so very helpful, Internet Explorer will easily accept what is called a "browser helper object," to help make your browsing experience friendly and helpful. Your Yahoo or Google browser bar is a browser helper object, one you chose to add. And Yahoo and Google want to continue to have your business, so they aren't going to do anything to ruin their reputations. Going to the wrong website and clicking on the wrong thing will get you malicious, possibly invisible BHOs. Your virus software often does not catch these. Try searching for "spyware removal" software, which can get rid of most of these. I spent two weeks and several phone calls working with spyware removal companies, to find one such. The hackers had changed its name and changed where it was saved on the system. I found it, finally, and reported it.

I have a list of email addresses from various companies I forward phishing email to. ("Your Citi account has been violated!" yeah right.) The two you will find most useful are:

reportphishing@antiphishing.org

spam@uce.gov

Just so you know, the Federal Reserve Bank doesn't have individual accounts.