Feds Warn of Fake Sites
Computerworld -
A cracker doesn't have to break into a bank's computer to steal account numbers and access codes. It may be enough to set up a spoof Web site that closely mimics a real bank's site, according to a warning issued two weeks ago by the federal Office of the Comptroller of the Currency (OCC).
Some customers have provided financial information to sites that they thought were legitimate Web sites, according to OCC spokesman Dean DeBuck. The fake sites were close - but not exact - copies of the real bank sites, he said.
So far, the only losses that the OCC is aware of involve private information such as addresses, said Clifford Wilke, the agency's director of bank technology. No thefts have been reported yet of personal account information or access codes.
To keep an eye out for fraud, banks should make sure that there aren't any Web sites with similar names that are luring consumers, instead of waiting for customers - who may not realize they've been duped - to complain, said DeBuck.
Companies can take legal action against Web site spoofers, DeBuck said. For example, wwwbankofamerica.com - the same as the real site's address, but without the dot after the "www" - was taken down after a few unsuspecting consumers were taken in, he said.
But banks aren't the only targets. X.com Corp.'s PayPal Web site was spoofed recently with PayPai.com, said Chris Musto, an analyst at Gomez Advisors Inc. in Lincoln, Mass.
According to Vince Sollitto, a spokesman for Palo Alto, Calif.-based X.com, the phony site was shut down "within hours" of going public, and no customers lost money.
Financial
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
The State of PCI DSS Compliance at Organizations Today
Download this resource today!
Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...
Can Heuristic Technology Help Your Company Fight Viruses?
What is Heuristic Technology and how can it help safeguard your business against viruses? Learn more.
Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.
Why Email Must Operate 24/7 and How to Make This Happen
Learn how to avoid an email outage by implementing a hosted email continuity solution.
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Eradicate Spam & Gain 100% Asurance of Clean Mailboxes
Get this paper now!
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Mastering eDiscovery: The IT Manager's Guide to Preservation, Protection & Production
Get this paper now!
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...
