Picture of a PayPal security key fob
The PayPal key fob sends users a password that changes every few seconds

PayPal slashes fraud attacks

Internet payment firm reduces phishing with layers of defences

Written by Tom Young

The proportion of worldwide phishing scams targeting PayPal has dropped from three-quarters to less than two per cent in just 18 months.

Phishing ­ where criminals send emails purporting to be from a financial institution to obtain customers’ details ­ cost the UK alone £33.5m in 2006. And the internet payments firm’s vast user base of more than 153 million accounts was proving an attractive target.

But PayPal’s work with industry and law enforcers has taken back the initiative, chief information security officer Michael Barrett told Computing.

“Such a huge drop is due to the fact that we have implemented a layered series of defences, including both technical and educational measures,” he said.

The company has an agreement with web-hosted email servers that only “digitally signed” emails from PayPal will be accepted by account inboxes ­ drastically reducing the number of bogus mails reaching users.

The firm has tackled phishers’ practice of redirecting customers to a fake site by working with major internet browsers to introduce an authentication marker that turns the address bar green or red, depending on whether or not an address is trusted.

PayPal also offers users security keys which issue a one-time password that changes every few seconds, thus preventing criminals from accessing accounts.

Working with other firms has been crucial, said Barrett.

“Industry co-operation is always better than trying to solve the problem alone,” he said. “We have also developed deeper relationships with law enforcement agencies.”

But the growing sophistication of the criminals means the problem will never be solved.

Phishers will always target the “low-hanging fruit”, said Peter Cassidy, secretary general of the Anti-Phishing Working Group. “In 2004 there were only a dozen targets, now there are more than 170,” he said.

The phishing figures were collected by anti-spam company ClearMyMail.

reader comments

related articles

Picture of the eBay logo

eBay enjoys 50 per cent boost to profits

Results for second quarter show record leap in revenue 19 Jul 2007

 

UK e-crime tactics questioned

House of Lords Committee says a national cyber crime strategy is crucial 05 Apr 2007

Online banking fraud rises sharply

Total card fraud is down but online fraud is up 14 Mar 2007

PayPal to block old browsers

Payment service will warn and block old browsers as part of attempts to stop phishing attacks 21 Apr 2008

Abbey most targeted by phishers

UK bank takes the lion's share of attacks 23 May 2008

OFT fights the scammers

Awareness month to focus on help and advice for the elderly 01 Feb 2008

related whitepapers

today's top stories

Solid as a rock - business continuity in a global manufacturer

From power supply problems in Nigeria to email availability in Stockport, PZ Cussons is prepared for anything 02 Dec 2008

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

IT staff desperate to keep their jobs

Most would work longer hours for less pay 02 Dec 2008

VMware View 3 enhances virtual desktops

Virtual clients now take up less storage space and can be 'checked out' to a laptop 02 Dec 2008

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Parcel being packedFeatures

Case study: eSpares and business continuity

Online electricals business has managed to decrease its downtime 02 Dec 2008

Royal Blackburn HospitalFeatures

NHS trust recovers from server overdose

Virtualisation technology breathed new life into East Lancashire's cost-intensive system 02 Dec 2008

Advertisement

Primary Navigation