The messages may look quite authentic, featuring corporate logos and formats similar to the one used for legitimate messages. Typically, they ask for verification of certain information, such as account numbers and passwords, allegedly for auditing purpose.
Let's use Citibank for example:
important to note, however, that it is very simple to change the "from" information in any
e-mail client.
2. The e-mail will usually contain logos or images that have been taken from the Web site of the
company mentioned in the scam e-mail.
3. The e-mail will contain a clickable link with text suggesting you use the inserted link to
validate your information. In the image you will see that once the hyperlink is highlighted, th
bottom left of the screen shows the real Web site address to which you will go. Note that the
hyperlink does NOT point to the legitimate Citibank Web site URL.
In this instance, the text you click is "here". However, this may also state something like "Log-in to Citibank" or "www.citibank.com/secure" to be even more misleading. This clickable area is only text and can be changed to anything the sender wants it to read.
Additionally, you may spot some of these elements that did not appear in this particular scam:
Logos that are not an exact match to the company's logo, spelling errors, percentage signs followed by numbers or @ signs within the hyperlink, random names or e-mail addresses in the body of the text, or even e-mail headers which have nothing to do with the company mentioned in the e-mail.
The golden rule to avoid being phished is to never ever click the links within the text of th
e e-mail. Always delete the e-mail immediately. Once you have deleted the e-mail then empty the trash box in your e-mail client as well. This will prevent "accidental" clicks from happening as well. If, for some really odd reason you have this nagging feeling that this could just possibly be a legitimate e-mail and nothing can convince you otherwise, you still need to adhere to the golden rule and not click the link in the message. Beside that, e-mail is not a secure method of transmitting personal information. If you initiate a transaction and want to provide your personal or financial information through an organization's website, look for indicators that the site is secure.
Generally speaking, people become victims of phishing scams simply because they do not know how such scams operate. You can help by ensuring that friends and colleagues are aware of such scams and what to do about them. The power of such "word-of-mouth" education is substantial. You CAN make a difference by sharing your knowledge of phishing scams with other Internet users.

No comments:
Post a Comment