Feeds

Phishing losses overestimated - survey

Small fry

  • alert
  • submit to reddit

High performance access to file storage

Fraud losses from email phishing attacks will hit $137m globally in 2004, according to a study from research and consulting firm TowerGroup. The figure is much lower than previous estimates. For example, a September survey commissioned by TRUSTean, an online privacy non-profit organization and NACHA, an electronic payments association, put US phishing losses to date at $500m.

TowerGroup reckons previous studies have overstated financial losses while underplaying the potential impact of phishing on lost consumer confidence. Phishing attacks are successful in fooling only a very small fraction of the online population and are, to many consumers, a nuisance like spam. TowerGroup reckons other analysts have overestimated response rates.

Beth Robertson, senior analyst in the global payments research service at TowerGroup and co-author of the research, said "Phishing attacks can allow criminals to fraudulently obtain consumer data, but they do not as commonly result in an actual fraud event in which accounts are accessed or funds are stolen."

Scam emails that form the basis of phishing attacks often pose as 'security check' emails from well-known businesses. These messages attempt to trick users into handing over their account details and passwords to bogus sites. The collected details are used for credit card fraud and identity theft. First seen more than a year ago, phishing emails are becoming increasingly sophisticated, directing users to bogus websites which accurately reproduce the look and feel of legitimate sites.

Like most observers TowerGroup agrees that phishing is on the rise but it reckons other surveys underreport the actual level and mix of phishing attacks. It estimates the number of phishing attacks will top 31,000 globally in 2004, reaching 86,000 next year as fraudsters begin to target customers of smaller financial institutions and a wider range of online merchants.

Phishing attacks are becoming more sophisticated as "organized crime rings have taken over much of its development" TowerGroup notes. "Not only has the quality of fake emails improved, but more effective targeting is increasing the efficiency of phishing attacks. Phishers are also integrating their scams with malicious software (or "malware") downloads, as well as complex new variants better classified as 'malware attacks' than as phishing - making the threat from these attacks more dangerous and more difficult to detect and prevent," it said.

The cost of managing phishing losses will be "far greater" than the cost of direct fraud. George Tubin, senior analyst at TowerGroup and co-author of the research, said: "One of the greatest liabilities is the potential loss of customer confidence in the Internet as a channel for provisioning financial services, not to mention loss of trust in financial institutions themselves. This is a critical issue, given the rising importance of the online channel in the retail financial services delivery mix."

The TowerGroup research report titled, A Phish Tale? Moving From Hype to Reality, catalogues the increasing sophistication of phishing and related internet scams. A companion report, No Phishing Zone: Vendor and Industry Initiatives to Curb E-Mail Fraud, looks at how the financial services industry is fighting the problem. ®

Related stories

Phishers tapping botnets to automate attacks
Fraudsters recruit phishing middlemen
Trojan targets UK online bank accounts
Consumers hit by net security jitters
Four charged in landmark UK phishing case
UK banks launch anti-phishing website
US phishing losses hit $500m

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
HP ArcSight ESM solution helps Finansbank
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.