Voice Phishing - A New Type of E-mail Scam

By: Debbie Jacobsen
Submitted: 2007-01-17 13:43:57
Print this article | Tell a friend | For publisher | Social Bookmarking
Rating:
 

Be on the lookout for an interesting new type of Phishing scam that involves the use of telephone numbers as opposed to email hyperlinks that take you to a bogus website.

Two big incidents involving spam emails urging people to call a phone number to verify account information have been discovered within the past two weeks, indicating that “voice phishing” may soon become a popular new tool for internet criminals.

The first of these voice phishing scams was reported on June 23, 2006 by Santa Barbara Trust, when people started receiving forged emails with the subject line "Message 156984 Client's Details Confirmation (Santa Barbara Bank & Trust)." Unlike the traditional phishing email that includes a hyperlink leading to a fake website, this one urged customers to call a certain phone number to verify account details. When victims dial the phone number, a recording requests that they enter their account number. Since the phone number belongs does not belong to the bank, users who key in account details are handing this confidential information to the thief.

On July 7, 2006 a similar scam involving fake e-mail from PayPal. Identity thieves sent out spam email messages warning people that their PayPal account has been compromised. Instead of the usual “click here and log on to your account” phishing link in the email, these messages urge the recipient to call a phone number to verify their account details. Just like the earlier case involving Santa Barbara Trust, callers are greeted with a recording that says something like “welcome to account verification, please enter your 16 digit account number”.

Both phone numbers appearing in these scam emails were a Southern California (805) area code, but there could very well be others.

When something like this starts a lot of “copycats” usually follow, so watch out for this type of scam in your inbox.

Protecting yourself from traditional e-mail phishing scams as well as the new “voice phishing” scam is mainly a matter of learning what to do. Most people know not to click on links in emails that appear to be from financial institutions or other companies they may have an account with. Now we need to learn not to call any phone numbers included in an email.

As always, the best thing to do if you are concerned is to open up a web browser and manually enter the company’s address to log on and verify your account is ok. If you’d rather call, get the phone number from the company’s official website or from a phone directory.

E-mail phishing scams are really just spam messages with a criminal purpose, so a good way to keep these dangerous emails out of your inbox is to install anti-spam software.

Spam blocking programs keep spam out of your inbox by using a combination of “blacklists” (list of known spamming websites) as well as special algorithms and filters designed to detect junk by analyzing the content. Spam blockers are pretty effective at stopping junk, which really helps keep crime-mail out of your inbox.

Debbie is an information technology professional and author of the following sites covering information technology topics:
Computer Security for Everyone
Antivirus, Firewall and Spyware Resources
For more information on e-mail security

Article source: Expert Articles

Most Recent Articles in Security category

  • Essential Tips For Secure Online Trading - By: Liam Derbyshire
    Conducting business on the internet is fraught with numerous perils. From identity theft to elaborate scamming schemes, criminals are out there in cyberspace trying their best to rob you out of your hard earned cash. A few simple tips give you all the protection you need from the vile schemes of these con artists.
  • Discover the joys of anonymous proxy servers. - By: Kulveer Singh
    As Google Adwords and Google Adsense becomes more mainstream, the rate of fraud from self-clicking (commonly called Google-bation), and click-draining (clicking on competitors ads), will increase exponentially. The problem is that the electronic antichrist has an obvious conflict of interest in eliminating fraud. Like most web site owners running Google Adsense, you probably are tempted to just "test" ads to make sure all the html you have embedded on your site is working. In some markets these little "tests" can reward the web site owner over $20 per click. Drugs, bank loans and obesity cures pay pretty well I'm told.
  • Stepping Up Your Security - By: Scott Jarvis
    Many online businesses have been using this method of security for over ten years and still have not upgraded to a better form of online security. Though many smaller businesses have yet to adopt a more advanced technology, several high profile companies have begun using some form of two factor authentication both on their websites and in their offices.
  • You Can't Do Without Search Engine Optimization - By: Naman Jain
    No websites can ignore the importance of search engine optimization to their website. It is the most essential tool, which will helps them grow their Online business.
  • Identity Theft - Don't blame The Internet - By: Kavita B
    Identity theft - also known as ID theft, identity fraud and ID fraud - describes a type of fraud where a criminal adopts someone else's identity in order to profit illegally. It is one of the fastest growing forms of fraud in many developed countries.
  • AllAnonymity - anonymous browsing solutions - By: Ionel Orza
    In our days identity protection has become increasingly important, because any time someone could be watching what you do on your computer through online spying. Someone like your boss, someone trying to hack your system, or even the government may be on your track while you peacefully surf the web.
  • 8 Simple Ways to Defend Against Evil Doers Both Online and Off - By: Dan Preston
    There once was a time when the only option people had when shopping was to either call in or snail mail in a catalog order form or to jump in the family car, fight through traffic, and wait in long checkout lines to complete the purchase.Well, nowadays there’s still a few major mail order catalogs floating around and we all still visit our local retail outlets, but time has also introduced the internet as one of our options to shop from the comforts of home.The internet has made shopping at home a breeze and along with it has unfortunately brought the so called ”Evil Doers” who I believe have such little happiness in their own lives that they must leech pleasure from the hardworking and innocent individuals of our wonderful and surrounding nations.
  • Dirty Little Computer Viruses and How To Protect Yourself - By: Dan Preston
    Whether you have learned your lesson from a past experience with a nasty computer virus or have been pressing your luck by surfing the web and downloading various files or opening those email messages sent to you by people you don’t know without any real understanding of just how vulnerable you really are each time you log onto your computer you now have the opportunity to discover what steps you can take to avoid such an annoying and many times destructive infestation.Listed below are some of the guidelines you can follow in order to keep those nasty viruses from making a mess out of your computer and your life.•Purchase and install a well respected antivirus software program and be sure to set it up so that it automatically runs when the computer starts up each time.
  • Protect Your Little Black Book - By: Rick Cooper
    The movie Little Black Book features a young woman, Stacy, who is frustrated when her boyfriend refuses to share information about his past relationships. When his PDA, a Palm Tungsten C, falls into her hands, she is faced with a conundrum. Does she give it back, or does she explore it?
  • Can I Guess Your Password? - By: David Congreave
    We all know that it’s dangerous to use the same password for more than one program. If you sign up for a program run by someone of low moral fibre, what is to stop them running through various programs with your username and password to see what they can access? But of course remembering all the different passwords can be a headache.