Picture of hook

New phishing technique discovered

Hovering mouse over link will no longer give away fradulent URL

Written by Tom Young

A new ‘undetectable’ phishing tactic has been hijacking the web pages of a major UK bank, according to security vendor Envisional.

Until now customers have been able to check a link in an email by moving the mouse over it, thus revealing a fraudulent URL addresses. But this new method shows the legitimate web address of the bank in question.

'This is a completely new and very dangerous threat,' said Envisional’s chief executive officer, Michael Wheatley. 'Even wary, sophisticated online banking customers will be caught out by this latest form of attack.'

The new approach exploits a vulnerability in the web site of the bank, allowing a link to look like it directs the user to the legitimate site. Actually the link sends the user to a framed mock-up of the bank's page that is really part of the phisher’s web site.

Gartner analyst John Pescatore says the attack is a variant of existing phishing techniques.

'There's big risks there for sure. I think it's a clever variation on things that have been done before, taking advantage of a vulnerability on a legitimate site to embed some malicious code,' he said. 'Any site that wants to make sure it’s a trusted commerce site has to make sure it doesn't leave these vulnerabilities there.'

But PayPal chief information security officer Michael Barrett says these emails will be much less of a threat if users are educated.

'You could argue that if you could educate all of your users then there would be no such crime as phishing,' said Barrett. 'Firstly if you get emails out of the blue wait a few days. Typically if it’s a phishing site it will have come and gone by then. Secondly just don't click on links in emails. Those two rules on their own will get you out of 98 per cent of the problems.'

What do you think? Email us at: feedback@computing.co.uk

Further Reading:

PayPal tackles UK phishing concerns

Fraudsters using new phishing tactics

International phishing gang arrested

Publicise the phishing facts

reader comments

related articles

 

PayPal slashes fraud attacks

Internet payment firm reduces phishing with layers of defences 31 Jan 2008

Hackers step up website attacks

Security forecast for 2008 makes grim reading 20 Feb 2008

Phishing attacks hit six-month high

The number of banks targeted rose to 188 last month, the highest since August 2007 17 Mar 2008

related whitepapers

today's top stories

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Got the Knowledge?

Last week the civil service published a new strategy to help government seize the opportunities and meet the challenges of managing knowledge... 01 Dec 2008

Q&A - ntl:Telewest Business managing director Stephen Beynon

The cable provider's chief talks about the future of next-generation broadband access in the UK 28 Nov 2008

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

India will remain open for business - but that's not the real story

One of the duties I have to fulfil as a director of the National Outsourcing Association is to talk to the media... 28 Nov 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

ntl:Telewest's Stephen BeynonAnalysis

Q&A - ntl:Telewest Business managing director Stephen Beynon

The cable provider's chief talks about the future of next-generation broadband access in the UK 28 Nov 2008

cowboyFeatures

Guns for hire

David Neal explores the world of interim CIOs and discovers why more firms are turning to them to spur on IT-led change 27 Nov 2008

Advertisement

Primary Navigation