Gmail attack shows growing cybercrime sophistication

Discussion in 'other security issues & news' started by Triple Helix, Jun 2, 2011.

Thread Status:
Not open for further replies.
  1. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    Gmail attack shows growing cybercrime sophistication!

    http://edition.cnn.com/2011/BUSINESS/06/02/google.gmail.phishing/index.html

    TH
     
  2. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,232
    Location:
    Texas
    http://krebsonsecurity.com/2011/06/spotting-web-based-email-attacks
     
  3. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    I thought Gmail itself was attacked, not just consumers. The latter I can prevent, but the former I can't do anything.
     
  4. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    98,109
    Location:
    U.S.A.
     
  5. bonedriven

    bonedriven Registered Member

    Joined:
    Jan 14, 2007
    Posts:
    566
    Here's a demo of the phishing attack, in Chinese though.
     
  6. Rmus

    Rmus Exploit Analyst

    Joined:
    Mar 16, 2005
    Posts:
    4,020
    Location:
    California
    Targeted attacks have been around for at least five years, just as sophisticated, IMO.

    Targeted attack: experience from the trenches
    Published: 2006-05-21,
    http://isc.sans.edu/diary.html?storyid=1345
    And, more recently:

    Targeted e-mail attacks asking to verify wire transfer details
    Published: 2009-06-04
    http://isc.sans.org/diary.html?storyid=6511
    Targeted attacks have increased, of course, and use different scenarios, but just because now it's Google/Gmail (and other web mails) seems to be a catalyst for widespread coverage!

    In today's attacks where the victims willingly give out their passwords, the real (almost unsurmountable) problem in organizations is making people aware of the tricks, and informing them of the circumstances when they would be required to reveal their password.

    From the article:

    This type of targeting can happen in many scenarios, not just with webmail.

    regards,

    -rich
     
    Last edited: Jun 5, 2011
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.