Picture of michael barrett

PayPal acts to stamp out phishing attacks

Online payment site will fight fraud with two-factor system

Written by Tom Young

PayPal’s decision to introduce an optional two-factor authentication system highlights the increasing concern of banks and online payment organisations over phishing.

The amount of money lost to online banking fraud in the UK increased 55 per cent to £22.5m in the first half of 2006, according to figures from banking industry body Apacs – and all the signs indicate this amount will continue to rise.

Most phishing emails now target PayPal and eBay customers, largely because they are such a huge demographic – 123 million customers at the end of 2006 – but also because PayPal is designed to make it easy to move money around, predisposing it to being phished.

Surprisingly, however, phishing is not a large financial problem for PayPal or its customers.

Michael Barrett, chief information security officer at PayPal, says the problem with phishing has more to do with perception than reality.

‘Financially, phishing is not even in the top five of categories that we suffer from fraud–wise. But when you say you work for PayPal, people say: ‘Oh I get all these emails from you. What are you doing about that?’ People perceive that there is an issue, so there is an issue,’ he said.

Customers receiving phishing emails lose confidence, so PayPal’s two-factor efforts should help with some of these worries.

‘Security is, of course, about relatives and risk assessment, and not absolutes. What we are seeing at the moment is a period of experimentation where different companies are trying different solutions,’ said Barrett.

Recent research by security vendor RSA shows that 91 per cent of bank account holders are willing to use stronger authentication methods, while more than half (52 per cent) are ‘less likely’ to sign up for or use online banking than they were.

As well as introducing two-factor, PayPal is responding to this drop in public confidence by introducing a new green light system where users of Internet Explorer 7 will see the browser flash green if the site is safe.

‘One of the other things we are doing is heavily pushing digital signature and email signing technologies so that all PayPal and eBay outbound email is digitally signed,’ said Barrett.

‘It is incumbent on us to set an example and say these technologies will help once they reach a critical mass,’ he said.

Peter Cassidy, secretary general of the Anti-Phishing Working Group, says nothing is absolute.

‘None of these solutions will stop online payment systems being attacked; criminals will just up their game. But two-factor systems will also get attention because consumers are experiencing something novel,’ he said.

What do you think? Email us at feedback@computing.co.uk

Further Reading:

Fraudsters use phishing tactics

Bank victiom of record phishing strike

International phishing gang arrested

  • Have your say
  • Send to a friend
  • Print this
  • Share

reader comments

related articles

 

Online banking fraud rises again

MasterCard SecureCode and Verified by Visa proving succesful but malware attacks on banking customers rise 07 Oct 2009

Fraud leads to huge rise in online banking losses

Cybercriminals turning to cleaning out people's bank accounts 07 Oct 2009

Financial advisers convicted in £2m VAT scam

Fake companies set up to trade in zero-rated goods reclaimed VAT on false business expenses 22 Oct 2009

related whitepapers

today's top stories

Telepresence: coming to a screen near you?

Telepresence systems enable organisations to hold boardroom-style meetings with far-flung participants without the hassle and expense of arranging travel and accommodation. But while the technology is impressive, it does not come cheap, as Martin Courtney discovered when he sat in on a virtual meeting with executives from Philips 10 Mar 2010

Users give their verdict on Azure

Some of the first wave of UK adopters met in London recently to air their views on Microsoft’s cloud computing platform. Dave Bailey listened in 10 Mar 2010

Protests greet new Digital Economy Bill amendment

ISPs, digital rights groups and Liberal Democrat supporters cry foul 05 Mar 2010

Publishing special - Publishers innovate to survive

1) IT could hold the key to the future of publishing 2) Case Study: The Guardian harnesses social and mobile apps 3) How publishers are reacting to the iPad 02 Mar 2010

IT Leaders' Forum in association with IBM

A unique opportunity to hear from expert speakers and engage in a debate about the future of the CIO job function 29 Jan 2010

Advertisement

Keys to successful Service‐Oriented Architecture implementation

This white paper explores best practices and general design patterns for service oriented architecture (SOA).

The Roadmap to IT Maturity — Matching Strategy to Infrastructure for Business Success

This paper defines a roadmap for matching infrastructure strategy to business success.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

NHS centralised data

NHS centralised data

Do you think the NHS can be trusted to safely look after personal data electronically?

View poll results

Latest audio and video articles

Video

HP unveils S Series notebooks

'Prosumer' line overhauled 01 Mar 2010

Web Seminar Listings

Preparing for enterprise-scale Windows 7 migration

The web seminar on 18 Feb will discuss how Windows 7 migration can increase IT efficiency in large enterprises, freeing up budgetary and personnel resources to focus on business innovation. Our panel of experts will examine the strategies, tools and services IT leaders can use to migrate successfully and reap the rewards of increased efficiency. 19 Feb 2010

Latest in-depth articles

LaboratoryFeatures

Finding the right formula

Drug and food testing company Eclipse Scientific wanted to make its internal communications system easier to manage and more responsive to the needs of employees and customers. Nicola Brittain reports 16 Mar 2010

Videoconference on a laptopFeatures

Get ready to roll

Moving staff over to a unified communications platform can have a huge impact on their working practices. Rachel Fielding explains how IT leaders can ensure the transition goes smoothly 16 Mar 2010

Primary Navigation