Feeds

UK punters lose faith in phished brands

Collateral damage

High performance access to file storage

Email phishing attacks tarnish the reputations of targeted firms, according to a new UK survey. Two in five UK adults (42 per cent) quizzed feel that their trust in a brand would be "greatly reduced" if they received a phishing email purporting to represent it.

Despite this, the majority of respondents to YouGov's online survey reckon the responsibility for protection against phishing attacks lies with ISPs and individuals themselves, rather than the brands targeted by fraudulent emails.

One in four (26 per cent) of 1,960 adults surveyed reckon the main responsibility for protecting against phishing attacks lies with themselves, with a similar percentage (23 per cent) responding that their ISP ought to bear the brunt of filtering spam emails. A further (17 per cent) think the sender's ISP and email service provider holds the greatest responsibility in combating scam emails.

Phishing attacks commonly take the form of forged emails that attempt to trick consumers into disclosing their login credentials in response to bogus warnings that prospective marks need to respond to a "security check".

Many high street names have bought in technologies or developed internal systems to identify and take down websites associated with phishing attacks. Preventing fraudulent emails reaching users' inboxes in the first place would involve measures such as promoting free or discount security and email filtering packages.

The YouGov phishing survey was sponsored by anti-spam firm Cloudmark, which reports that .uk domains are the single most common target of phishing attack across Europe.

Security experts at ISPs said it was unfair for consumers to hold the targets of attacks responsible for the crud hitting their inboxes.

"Whilst awareness to the problem is essential, it is unrealistic to expect businesses to be able to secure themselves fully against such sophisticated criminal activities. The increasingly dynamic and transient nature of the latest threats requires a combination of desktop protection at the client level, and accurate message filtering from ISPs," said Nigel Stevens, product director at THUS.

Gone Vishing

Cloudmark reports that would-be fraudsters are taking advantage of VoIP systems to develop more convincing attacks. One recent email scam, for example, poses as a notification from a recipient's bank requesting that they ring customer services to deal with a problem.

"If the recipient makes the call, it gets routed to a cheap VoIP answering system, which may have been set-up on a compromised host," explained Neil Cook, UK technology chief at Cloudmark. "The system captures the user ID and pincode to sell on to the highest bidder, who then has full access to your account. All the while the call seems very genuine. The reassurance of speaking to an individual rather than working online will lead to many instances of consumers falling foul to such threats." ®

High performance access to file storage

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
NSA denies it knew about and USED Heartbleed encryption flaw for TWO YEARS
Agency forgets it exists to protect communications, not just spy on them
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
HP ArcSight ESM solution helps Finansbank
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.