CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image Press Release: Information Security Forum Warns Against Increase In Trojan Phishing image
Trojans
webitpr writes "Information Security Forum Warns Against Increase In Trojan Phishing And The Use Of ‘Moles’

ISF phishing report also puts education above two-factor authentication

27 September 2005: A new report from the Information Security Forum (ISF) warns that Trojan-based attacks will take over from email phishing in the US and Europe as Trojans become more sophisticated and harder to stop. The ISF – a not-for-profit organisation with 260 members including half of the Fortune 100 – also highlights the increasing use of ‘moles’ placed in organisations to gain access to high-worth customers.

The rapid use of phishing by organised criminals is reflected in a survey of ISF members that shows that over a third of members have been affected by phishing attacks. Furthermore, over 30% of these have experienced more than 20 attacks.

The ISF report provides a detailed five-point strategy to tackle the threat of phishing attacks. But while two-factor or even three-factor authentication is seen as a strong preventative measure, the report suggests that savings from direct fraud alone do not currently justify the expenditure. Organisations should consider other factors such as reputational damage, regulatory intervention or loss of competitive advantage.

Significantly, the report points to better education of customers about phishing and identity theft as being a more immediate requirement. This should be supported by a strong anti-phishing policy, continuous Internet monitoring to identify phishing activity and brand misuse, and better internal protection. In particular, with criminal gangs planting and grooming company ‘moles’, the need to secure customer databases from internal attack is becoming increasingly important.

“We believe that email phishing will move away from English speaking regions to Asia, China and the Middle East, to be replaced by a surge in sophisticated and well-organised Trojan attacks,” said Andrew Wilson of the Information Security Forum. “Often, the first time an organisation knows that it is under attack is when customers notice money missing from their accounts, so it will become vital to put early warning mechanisms in place. These can include closely monitoring customer complaints and feedback for signs of attack, regular checking of web sites for the unauthorised use of logos and brand names and open-source intelligence gathering for indications of planned attacks.”

“Improving user awareness of Internet risks is key to fighting online fraud, but in a manner that does not risk losing customer-confidence in ecommerce and online banking,” adds Andrew Wilson.

The ISF report along with over 150 authoritative reports on information security issues is available to ISF members. Further information on the ISF can be found at www.securityforum.org.
"
Posted on Tuesday, 27 September 2005 @ 14:05:32 UTC by Paul (1452 reads)
[ Trackback ]
image

"Press Release: Information Security Forum Warns Against Increase In Trojan Phishing" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Intel
· SuSE
· HotScripts
· W3 Consortium
· More about Trojans
· News by Paul


Most read story about Trojans:
Newest WMF Exploit Patch Saves the Day

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer