Skip to main content icon/video/no-internet

Several high-profile deceptions have used e-mail as a medium, including the Nigerian (419) scam and the advance fee scam. One of the most prevelant is phishing, which refers to an attempt by deceivers to solicit private information from individuals by posing as a legitimate company. The request is transmitted via a computer-mediated message (frequently e-mail) and often employs social engineering methods to dupe the message recipient. Security experts estimate that businesses and individuals experience over $2 billion in losses a year globally because of phishing efforts.

Phishing

The homonym “phishing” is a metaphor for a technique often used by deceivers, the “bait and hook” technique. In this context, the bait is the message itself. Most commonly, the message describes an urgent problem that the recipient must address by divulging private information, such as account usernames and passwords, credit card numbers, and Social Security numbers. The message supplies recipients with a hyperlink to a falsified Web site (the “hook”) that allows its visitors to enter the desired information, essentially resulting in identity theft. Some of the counterfeit Web sites are instructed to surreptitiously install spyware, like keystroke loggers, on the recipient's computer.

Phishers engage in deceptive techniques in appearance, content, and architecture of their messages to improve their chance of success. The e-mail message and the associated Web site commonly contain elements that aid in their appearance of legitimacy, such as logos, slogans, and word marks used without the permission of the authentic company. The core of the e-mail message itself describes a fabricated problem or event, and it is often accompanied by deceptive phrasing intended to encourage the recipient to take a rash course of action. This includes social engineering tactics like adding an element of urgency needed for a response (in order to avoid dire consequences resulting from the fabricated problem), or promising the message receiver a prize for responding.

Finally, phishing Web sites tend to be extremely temporary in nature, only existing on a remote Web server for a few days. Their fleeting nature necessitates a provisional uniform resource locator (URL) and fictitious return e-mail address. Phishing messages and Web sites tend to lack digital signatures or certificates of authentication, and Web sites are most likely to be registered using a “subdomain” hosting account, with the co-opted company name appearing beneath the top level domain in the URL hierarchy. In some instances, legitimate Web sites have been hacked and hijacked in order to exploit the Web site's authenticity for URL-naming purposes.

In terms of the deceptive communication between the phisher and the target, phishing attacks are rarely accompanied by repeated or prolonged interaction. The attack is limited to a single message requesting a response, and phishers do not commonly reply to requests for more information about the problem. However, phishers are able to employ mass e-mailing (spamming) as a method for initiating contact with multitudes of people at no additional cost. Message recipients are chosen at random, either through lists of valid e-mail addresses that have been collected using automated search agents (spiders or Web crawlers), or by attempting to send messages to random strings of characters representing the e-mail usernames on a particular domain. Phishing attempts have been observed to target tens of thousands of potential recipients at a time.

...

  • Loading...
locked icon

Sign in to access this content

Get a 30 day FREE TRIAL

  • Watch videos from a variety of sources bringing classroom topics to life
  • Read modern, diverse business cases
  • Explore hundreds of books and reference titles

Sage Recommends

We found other relevant content for you on other Sage platforms.

Loading