Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 28th, 2004, 07:26 PM
the mul's Avatar
the mul the mul is offline
Very Frequent Poster
 
Join Date: Jul 2003
Location: scotland
Posts: 1,709
Default Fake e-mails fool users 28 percent of the time

Consumers still falling for phish
Fake e-mails fool users 28 percent of the time, study finds

July 28, 2004

Confused by what's arriving in your inbox? You're not alone. Nearly one out of three Internet users was unable to tell the difference between fraudulent e-mails designed to steal their identities and legitimate corporate e-mail, a new study finds.

advertisement

Anti-spam firm MailFrontier Inc. showed 1,000 consumers examples of so-called "phishing" e-mail as well as legitimate e-mail from companies such as eBay and PayPal. About 28 percent of the time, the consumers incorrectly identified the phishing messages as legitimate.

What's more, the legitimate e-mails were often dismissed as potential fraud. An e-mail message from the Federal Trade Commission was dismissed as a fraud by 50 percent of the consumers.

"We knew we'd fool a few people, but we're pretty surprised by 28 percent," said Anne Bonaparte, CEO of MailFrontier. "A number of (the phishing e-mails used in the study) have been around for a while."

'We are losing on both ends'
One reason the look-alike e-mails continue to fool consumers: the people behind them are getting much better at their craft.

"We've definitely seen quite an improvement in grammar, for example," Bonaparte said. "Early versions wouldn't have fooled too many people. Now, they fool a number of us. We did the test here at work and some people had embarrassing results."

One very well-distributed PayPal look-alike e-mail, which claimed credit card information needed to be updated, fooled 31 percent of users surveyed, she said.

"That one was written widely about. You would not have thought that would have fooled people," she said.

Meanwhile, a simple note from PayPal indicating that a payment had been made, which asked for no personal information, was described as a fraud by 20 percent of those studied.

"We are losing on both ends right now," said Dave Jevens, chairman of the Anti-Phishing Working Group, a consortium of companies fighting the problem. He said he wasn't particularly surprised by the results of the study.

"I've seen professionals who work in the industry fall for these. As we can see from this report, it's hard to tell bad mail from good mail. ... It's undermining the ability of people to communicate."

(Think you'd do better at sniffing out the real McCoy? MailFrontier has published a "fair or phish" test similar to the one it used in its study on.

http://www.mailfrontier.com/


The mul
__________________
OUTPOST BETA TESTER

WINDOWS 7 PRO 64 BIT, SP1, DUO CORE 2 OVERCLOCKED 3.4 GHZ 4 Gb PC6400 RAM 800MHZ
AVIRA ANTIVIRUS PREMIUM 2013 - Outpost PRO 8.0(4164.652.1856) - MBAM PRO V 1.70 - WINPATROL PLUS V 26.0 - HITMAN PRO 3.7.0
  #2  
Old July 28th, 2004, 09:26 PM
snowbound snowbound is offline
Retired Moderator
 
Join Date: Feb 2003
Location: The Big Smoke
Posts: 8,727
Default Re: Fake e-mails fool users 28 percent of the time

hmm....6 out of 10.

A little disturbing.


snowbound
  #3  
Old July 28th, 2004, 10:32 PM
GlobalForce's Avatar
GlobalForce GlobalForce is offline
Regular Poster
 
Join Date: Jun 2004
Location: Garden State, USA
Posts: 3,581
Default Re: Fake e-mails fool users 28 percent of the time

hmmm, seventy percent. A bit more than a little, disturbing.
__________________
"No matter what, no matter where ~ it's always home when love is there!"
  #4  
Old July 29th, 2004, 12:27 AM
MikeBCda MikeBCda is offline
Very Frequent Poster
 
Join Date: Jan 2004
Location: southern Ont. Canada
Posts: 1,540
Default Re: Fake e-mails fool users 28 percent of the time

Hmm, 70 percent here too.

The PayPal ones were easy in one way -- totally aside from the links, PayPal has emphasized that any legit email from them will always address you by full name, never as "Dear customer" or the like.

I mis-guessed one or two of the legit ones -- and my reaction in those cases was that, given what we (should, anyway) know about phishing, those operations are operating very sloppily. More and more legit operations will no longer under any circumstances use email to ask for an acount verification, relying instead on snailmail or even phone calls.
__________________
Intel Atom D2700, 2 gig RAM, Win 7 x64 SP1 & IE-10, Firefox 21.0 (default). 320 gig HD, 6Mb DSL, Win firewall, Avast 8.0.1489 free, SpywareBlaster, MBAM
---
My name is Any Key. Please don't hit me.
  #5  
Old July 29th, 2004, 10:08 AM
GlobalForce's Avatar
GlobalForce GlobalForce is offline
Regular Poster
 
Join Date: Jun 2004
Location: Garden State, USA
Posts: 3,581
Default Re: Fake e-mails fool users 28 percent of the time

Quote:
Posted by MikeBCda: PayPal has emphasized that any legit email from them will always address you by full name, never as "Dear customer" or the like.
Thanks for pointing that out Mike, makes sense. I suppose if you know who you're dealing with, just be thorough when checking, hmmm?
__________________
"No matter what, no matter where ~ it's always home when love is there!"
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:00 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums