Feeds

Miserly marks get smart to UK phishing fraudsters

Attacks up, but losses down

Internet Security Threat Report 2014

Incidents of phishing targeted against holders of UK bank accounts are up, but losses are down.

UK banking association APACS cites more than 10,000 reported phishing incidents in the first quarter of 2008, a more than 200 per cent rise from the same period last year. Online banking fraud losses, however, decreased by a third from £33.5m in 2006 to £22.6m in 2007.

APACS research shows that although the number of people ignoring phishing email has increased from 75 per cent in 2006 to 82 per cent last year, there are still nearly one in five people who don’t follow these common sense precautions. In addition, although 93 per cent of people have anti-virus software on their PCs, almost one in three people (29 per cent) don’t have any anti-spyware software.

Security firm RSA backed these findings, reporting UK banking brands were the second most attacked in the world over the last 14 months. In addition, the firm found that the number of targeted institutions has gone up 23 per cent year-over-year. So, crooks are widening their nets to target small banks and financial institutions.

Recent reports suggested the increased prevalence of phishing attacks has prompted UK banking code changes that place liability for online banking losses in the hands of customers instead of banks. However, an APACS spokesman said that sections of the 2008 code that placed the onus on bank customers to take reasonable care and make sure that their anti-virus and anti-spyware software are up to date have appeared in the code since 2005. As before, customers may also be held liable for negligence if they hand over online banking credentials in response to phishing emails.

The Banking Code is a voluntary code which sets standards of good banking practice for financial institutions when dealing with personal customers in the UK. The latest version of the code can be found here (pdf).

Historically, UK banks have taken the hit for phishing losses from online bank accounts without questioning whether victims had followed "safe computing" best practices. But provisions in the code give them the right to withhold payments in cases where customers are negligent. ®

Internet Security Threat Report 2014

More from The Register

next story
George Clooney, WikiLeaks' lawyer wife hand out burner phones to wedding guests
Day 4: 'News'-papers STILL rammed with Clooney nuptials
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
PEAK IPV4? Global IPv6 traffic is growing, DDoS dying, says Akamai
First time the cache network has seen drop in use of 32-bit-wide IP addresses
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.