Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Finance
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

Digital PhishNet launched to combat phishing scams

Major industry players and federal law enforcement agencies are involved
 

Sign up to receive Security Resource Alerts

December 09, 2004 (Computerworld) -- A collaborative initiative involving several major industry players and law enforcement agencies was formally launched yesterday in an effort to deal with the growing problem of online phishing scams.
The antiphishing group, called Digital PhishNet, includes companies such as Microsoft Corp., America Online Inc., VeriSign Inc. and EarthLink Inc., as well as government agencies such as the FBI, the U.S. Secret Service and the U.S. Postal Inspection Service.
The group hopes to improve the flow of information between industry and law enforcement agencies about phishing attacks, said Dan Larkin, unit chief at the FBI's Internet Crime Complaint Center.
Because phishers are able to create and dismantle phony sites rapidly, "the key to stopping them is to identify and target them quickly," Larkin said. "Our industry partners have a unique perspective regarding these schemes, and how they look early on, that we in law enforcement don't always have."
Having technology players working closely with law enforcement agencies is a good approach to dealing with phishers, said Avivah Litan, an analyst at Stamford, Conn.-based research firm Gartner Inc. "Law enforcement is not really equipped to deal with these cybercriminals," she said. "They don't have the technical skills or the staff."
As a result, technology companies will have to "spoon-feed them" with a lot of the data and the evidence needed to go after phishers, she added.
Phishing scams are designed to lure people into parting with personal information such as credit card and driver's license numbers and typically involves spoofed e-mails that appear to come from reputable companies.
Industry groups such as the Anti-Phishing Working Group have reported sharp increases in phishing scams over the past year. Between July and October alone, the number of phishing sites grew by an average of 25% a month, with 1,142 active phishing sites reported active in October. According to Gartner, for the 12-month period that ended last April, phishing attacks cost victims $1.2 billion -- with U.S. companies bearing most of the costs.
The newly formed coalition should help industry and law-enforcement formulate a better response to the growing menace, said Judy Lin, an executive vice president at Mountain View, Calif.-based VeriSign. "The goal is to create a safe place for participants to share information, including the nature of scams, the contacts that are necessary to shut down the scams, as well as techniques and best practices for combating these types of activities," she said.
Apart from sharing information with law enforcement, the group will also be investigating ways of legally "leveraging technology to bring down sites" that are being used to launch phishing attacks, Lin said.
"The reason this alliance was formed is not just to raise awareness of the problem but to take a proactive stance in tracking [scammers] and shutting them down," said Dave Alampi, vice president of marketing at Digital River Inc., an Eden Prairie, Minn.-based company that builds and manages e-commerce sites.
Because of the cross-border nature of the problem, the FBI is working on garnering support from law enforcement agencies in other parts of the world, Larkin said. "The message here is that industry is taking the problem very seriously and is committed to working with law enforcement" to stop phishing, he said.




Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
"It's IT Blogwatch: in which Grisoft, maker of the AVG anti-virus package, backs down in its attempt to DDoS the..." Read more...
Read more Security posts or See all Blogs
Google gives away home-cooked Web application security scanner
HP eyes move of support facilities out of Colorado Springs
Microsoft trumpets security additions in upcoming IE8
More top stories...
How much is too much? Upgrade your notebook without going over the line
French ruling on counterfeit goods could have far-reaching effects for eBay
Apple cuts price of high-end SSD MacBook Air by $500
All it takes is a couple hours and about $125 to breathe new life into an old laptop. Here's how.
Is Microsoft's Golden Age over? What are Gates' most memorable quotes? Find out in Computerworld's complete coverage of the end of the Bill Gates era at Microsoft.
There are some things your CIO definitely doesn't want to hear. Also don't miss the flipside, Five things you should always tell your boss.
With its latest version, Mozilla's browser continues to raise the bar for what Web browsers should be.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Business Continuity Zone
Data Center Management Zone
Enterprise-Class Security Zone
The File Data Management Zone
Grid Computing on Windows Zone
Security Management Zone
ITIL Best Practices Zone
The SAS Zone
Storage Virtualization Zone
Business Intelligence and Analytics Zone

Ads by TechWords

See your link here
Why SaaS is Vital to Email and Web Security
Why SaaS is Vital to Email and Web Security
Download this webcast, free, compilments of Webroot Software
Go to the webcast 
Computerworld Executive Bulletin: Building a Robust Antivirus Defense
Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs.
(Source: MessageLabs) Antivirus software alone isn't enough to prevent today's speedy, sophisticated virus attacks. Security managers should consider multitiered approaches that include behavior scanning, appliances that check e-mail for worms, and restricting user access to dangerous Web sites. Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs, to learn more.
Download this executive briefing download
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Deploying Virtualized NetWare on Linux Whitepaper
Toward More Flexible, Next-Generation Collaboration Solutions
Driving Business Success Through Workgroup Choice and Flexibility
View more whitepapers 
How to Offer the Strongest SSL Encryption
Get this white paper now!
(Source: Verisign) Learn all the facts about guaranteeing maximum SSL strength to every Web site visitor, regardless of browser type or operating system. Stronger encryption levels keep your business safe from online threats and allow your customers to feel safe transacting on your site.
Download this white paper go