Feds Warn of Fake Sites
Computerworld -
A cracker doesn't have to break into a bank's computer to steal account numbers and access codes. It may be enough to set up a spoof Web site that closely mimics a real bank's site, according to a warning issued two weeks ago by the federal Office of the Comptroller of the Currency (OCC).
Some customers have provided financial information to sites that they thought were legitimate Web sites, according to OCC spokesman Dean DeBuck. The fake sites were close - but not exact - copies of the real bank sites, he said.
So far, the only losses that the OCC is aware of involve private information such as addresses, said Clifford Wilke, the agency's director of bank technology. No thefts have been reported yet of personal account information or access codes.
To keep an eye out for fraud, banks should make sure that there aren't any Web sites with similar names that are luring consumers, instead of waiting for customers - who may not realize they've been duped - to complain, said DeBuck.
Companies can take legal action against Web site spoofers, DeBuck said. For example, wwwbankofamerica.com - the same as the real site's address, but without the dot after the "www" - was taken down after a few unsuspecting consumers were taken in, he said.
But banks aren't the only targets. X.com Corp.'s PayPal Web site was spoofed recently with PayPai.com, said Chris Musto, an analyst at Gomez Advisors Inc. in Lincoln, Mass.
According to Vince Sollitto, a spokesman for Palo Alto, Calif.-based X.com, the phony site was shut down "within hours" of going public, and no customers lost money.
Financial
Additional Resources



White Papers & Webcasts
Share our Strength
Download Now
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Top 10 Things to Know about Data Protection
Download Now
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...
Ponemon Study: The Business Risk of a Lost Laptop
Download Now
Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.
Airport Insecurity: The Case of Lost Laptops
Download Now
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...
