Feeds

One in 200 success rate keeps phishing economy ticking over

Nibbles add up to big haul

High performance access to file storage

Phishers only need to land a minute percentage of victims to make scams worthwhile.

Stats culled from Trusteer's anti-phishing browser plug-in, which is offered by banks to their clients as a transaction security add-on, revealed that 0.47 per cent of a bank’s customers fall victim to phishing attacks each year. The figure comes from the number of users who visited and attempted to enter data onto a known phishing site but escaped because they were using Trusteer's Rapport browser security plug-in.

Half (45 per cent) of bank customers who are redirected towards a phishing site attempted to hand over their login credentials.

The overall response rate to phishing scams translates to between $2.4m-$9.4m in annual fraud losses (per one million online banking clients), according to Trusteer.

Trusteer's report (PDF) is worth considering because it looks at how many would-be marks respond to phishing emails (ie live attack data). Most surveys only look at how many phishing attacks are launched and what brands are targeted, without considering how successful these attacks actually might be.

The security software firm has come to prominence this year after signing up many banks, including NatWest and Alliance & Leicester in the UK, as customers of its transaction security software. Trusteer obviously has a vested interest in talking up the financial losses and danger posed by phishing but that doesn't mean it's necessarily wrong.

Harvesting online bank login credentials before cashing out compromised accounts is a major activity in the underground economy, which is growing more sophisticated and mature. The market has grown to the point where hackers have developed tools to harvest data from phishers, a sort of virtual stick-up.

The cyber equivalent of The Wire's Omar Little have developed an auto-whaling tool designed to harvest logins stored on phishing sites. Such attacks are possible because crooks themselves are making website security errors, as a blog post by FaceTime security researcher Chris Boyd explains. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
Bad PUPPY: Undead Windows XP deposits fresh scamware on lawn
Installing random interwebs shiz will bork your zombie box
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.