BoxcarMarketing Moving Ideas Online
BoxcarMarketing: Moving Ideas Online

Blog

Tuesday, April 15, 2008

4 tips to detect phishing attempts

Late last week I received an email from Google AdWords at an email address that looked like . Except the email wasn’t from Google AdWords and the originating email address wasn’t really .

It was a phishing attempt. Phishing?

In computing, phishing is an attempt to criminally and fraudulently acquire sensitive information, such as usernames, passwords and credit card details, by masquerading as a trustworthy entity in an electronic communication. eBay, PayPal and online banks are common targets. Phishing is typically carried out by email or instant messaging,[1] and often directs users to enter details at a website, although phone contact has also been used.

Most phishing attempts are pretty easy to spot. Misspellings, fake email addresses and domain names in Russia or some other country extension usually give them away if you know what to look for. But this scam was above average in its execution.

Here’s what the email looked like.

image

And here’s the landing page the link in the email brought up.

Fake Google AdWords landing page from a phishing attempt

Here’s the actual login page for Google AdWords.

I was following along half absentmindedly up to this point. Then I took a closer look at the URL.

adwrods.google.select.wapisbank.cn/select/Login/index.html

The actual domain name is wapisbank.cn, in China. I smelled a rat.

At the same time I was impressed. This was phishing done far better than I had seen before, and for Google AdWords, not common targets like banks, Paypal or eBay.

So how can you spot an attempt at phishing that shows up in your inbox?

  1. Are you expecting an email from the sending organization? If you don’t deal with a bank, they won’t send you email. If you don’t have a Paypal account, they also won’t send you email.
  2. Don’t trust email. The sender email address can be masked or ‘spoofed’ very easily. Email is inherently an unsecure communication. Email messages travel over the open Internet just as they are. A detection program called a ‘sniffer’ can watch the traffic going past and respond to specific words or cues (like passwords or credit card numbers). Don’t email sensitive information. Don’t expect large organizations to email sensitive information.
  3. Watch URLs. The URLs are the address of the web page you’re visiting. Phishing attempts almost always use URLs that mimic the URLs of the organization they’re impersonating, but they can never be that organzation. Here’s a short example of the distinctions between URLs, domain names and registered domains.
  4. Contact the organization sending you the email directly, not through a link in the email. Go straight to their website. Call them. Ask through a channel you’ve used before if you need to do anything to manage your account. Also, be ready to send the phishing email to the organization being impersonated.

Now that you’ve been warned, here’s the phishing webpage in case you need to see it in action.

Posted by James Sherrett | Tell a Friend
Filed under: • ServicesWeb MarketingUnderwire NewsletterOnline Marketing TipsNews | Permalink

Comments

Add a comment

Name:

Email:

Location:

URL:

Remember my personal information

Notify me of follow-up comments?

Submit the word you see below:


blogWhat we’re talking about

Photo
Lab with Leo #132
10 Email Marketing Tips

Lab with Leo episode 132 — Monique Trottier explains her top 5 email marketing tips.

more

image
Vancouver League of Drupalers
6 Email Mistakes to Avoid

Vancouver League of Drupalers — Monique Trottier warns of 6 email marketing mistakes.

more

projectsProject Highlights

Canadian Geothermal Energy Association

Canadian Geothermal Energy Association

"In one week since we launched our new website, we had 3 highly qualified leads come in from the site"

—Craig Dunn, policy director

moreDid you know?

Reuters reports that in 2008 Internet ad spending will surpasses TV ad spending in the U.K to become the #1 advertising medium.

Where do you spend your ad dollars?

(Source: UK Online ad spending to overtake TV this year.)

Latest Blog Posts

Define: Digital Native

Posted by Monique Trottier | 2008 - 11 - 06

IT Department Blocking Access to YouTube? Facebook?

Posted by Monique Trottier | 2008 - 11 - 06

How to Write Good Web Copy

Posted by Monique Trottier | 2008 - 10 - 28

Services

In-house Strategy Consulting

Want an expert to help train your staff?

Search Marketing

Increase your visibility in search results.

Website Design

Update your website design.

About Boxcar Marketing

imageLooking for the bee? Work Industries is now Boxcar Marketing. We don't have a bee, but we're still hardworking.

Vancouver internet marketing strategists
James Sherrett and Monique Trottier are experts
in online marketing strategy. Talk to us about
internet marketing, web design, search marketing and online business strategy.

Contact us.

Subscribe to our blog.
 

Home | About | Services | Projects | Blog | QuickLearn | Free Resources | Privacy | Site Map | Contact

© Boxcar Marketing — Moving Ideas Online

Boxcar Marketing | Suite 302, 70 East 2nd Avenue | Vancouver BC | V5T 1B1
Phone and Email | Subscribe