Wi-Fi phishing scam targets business travelers
Warning to users of airport and hotel access points
Computerworld - Business computer users who frequent airport and other wireless hot spots are being warned of a new, more sophisticated variant of the "Evil Twin" phishing scam that appeared in January.
In a warning today, wireless security and monitoring vendor AirDefense Inc. in Alpharetta, Ga., said the new phishing scam lures victims by setting up fraudulent Web sites that appear to be log-in sites for legitimate Wi-Fi hot spot vendors. When users log in and access the phony sites providing personally identifying information, their computers are hit with as many 45 viruses, according to AirDefense.
The company said wireless users at hot spots in shopping malls and coffee shops aren't believed to be at risk because hackers are targeting more lucrative victims, such as business travelers in hotels and at airports.
"These attacks are being driven by business because so much business, so many transactions, are done over the Internet," said Jay Chaudhry, the chairman and co-founder of AirDefense. "There's a lot of this going on, and business people need to be careful. The average business executive ... has no clue."
"Wireless security is a race with hackers," Chaudhry said in a statement. "Hackers have moved away from the challenge of simply trying to access a device. They are now interested in commercial gain. The most lucrative and easiest place for hackers' commercial gain is business hot spots such as airport lounges, hotels and conferences."
The phishing scam was discovered at several recent wireless technology trade shows, the company said.
The new Wi-Fi phishing variant is a more sophisticated version of the Evil Twin attack that hit the Internet in January. In Evil Twin, also known as the AP (access point) phishing scam, an attacker poses as a legitimate hot spot and tricks victims into connecting to the hacker's laptop or handheld device, according to AirDefense. Once the victim connects, the attacker can attempt to coerce the user into revealing personal and confidential information.
To avoid becoming victims of the latest scam, AirDefense recommends that wireless users take several security steps. When accessing their accounts at hot spots, users should enter passwords only into Web sites that include a Secure Sockets Layer key at the bottom right of the Web browser. Users should also avoid hot spots where it's difficult to tell who is connected, such as at hotels and airport clubs. Hot spots should only be used for Web surfing and not for making online purchases or any other transactions where account numbers or passwords are needed, the company said.
Users should also turn off or remove their wireless cards from their computers when they aren't accessing a hot spot to prevent others from accessing their machines, the company said. Users are also encouraged not to use unsecured applications such as e-mail or instant messaging while at hot spots. All patches for personal firewall and security software should also be continuously updated.
Read more about Mobile and Wireless in Computerworld's Mobile and Wireless Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Digital Transformation: Creating New Business Models Where Digital Meets Physical
- Individuals and businesses alike are embracing the digital revolution. Social networks and digital devices are being used to engage government, businesses and civil...
- Empowering Your Mobile Worker
- Today's most productive employees are mobile, and your company's IT strategy must be ready to support them with 24/7 access to the business...
- An Interactive Guide: Bring Your Own Device
- BYOD presents significant security and management challenges to IT departments who want to take advantage of the trend, but still protect corporate assets....
- Calculating ROI for Mobile Client Acceleration
- As mobile devices continue to expand in business use, ensuring these devices have optimal performance is becoming an IT imperative. This EMA paper...
- Tablet Computing Without Compromise
- This paper provides an overview of how and why that migration-from any old tablet to Windows tablets-came to be. All Mobile and Wireless White Papers
- Live Webcast
North Pole to South Seas: Overcoming the Pitfalls of remote Performance - In today's always-on world, connectivity is a business requirement. You need the tools that allow you to operate as if you were on...
- Supporting Mobile Productivity With A Limited IT Budget
- Join us and hear from Kaseya mobile IT management experts as we discuss core strategies for supporting the mobile revolution on a shoestring...
- North Pole to South Seas: Overcoming the Pitfalls of remote Performance
- In today's always-on world, connectivity is a business requirement. You need the tools that allow you to operate as if you were on...
- Unified Communications 101
- What's the best way to implement a unified communications solution for your organization?
- QNX® and BlackBerry® PlayBook™ Tablet.
- RIM's multi-processor, multi-tasking BlackBerry PlayBook runs a new Tablet OS powered by QNX, a bullet-proof microkernel operating system. This track will take a...
- A Close Look at Tablets
- Learn More All Mobile and Wireless Webcasts