News
News
7/27/2005
02:10 PM
50%
50%

Small Banks Become New Phishing Targets

The newest twist is more targeted phishing, now aimed at smaller banks and credit unions than in the past.

In the seemingly endless world of security threats, yet another cause for concern has emerged. In June, Websense, a provider of employee Internet-management solutions, released a statement saying that phishing scams are increasingly being directed at smaller, more targeted groups, such as local banks and credit unions, a practice it calls "puddle phishing."

Traditional phishing is when spammers send users official-looking e-mail messages to request such data as social-security numbers or passcodes, and threaten to deactivate, block or restrict users' accounts if they do not update their personal information. Until now, the practice has largely been directed at customers of large, multinational banks. But according to Websense Security Labs, which reports on Internet security threats, the number of small credit unions targeted by puddle-phishing scams have tallied more than 30 since the beginning of the year. At least one of the community banks targeted has only 11 branches, while another puddle-phishing attack targeted a credit union that serves employees and staff of the White House.

Dan Hubbard, senior director of security and technology research at Websense, says that even though smaller banks don't have a high volume of customers, the puddle-phishing attacks are working. "The fact that we are seeing more and more of the smaller financial outlets being targeted by phishing attacks may indicate that this is a highly profitable scam," Hubbard said in a statement.

The similarity of puddle-phishing attacks to large-scale attacks suggests that the phishers might be sharing tools, or that a small number of offenders is behind the puddle-phishing incidents, Hubbard believes.

Comment  | 
Print  | 
More Insights
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Tech Digest, Dec. 9, 2014
Apps will make or break the tablet as a work device, but don't shortchange critical factors related to hardware, security, peripherals, and integration.
Video
Slideshows
Twitter Feed
InformationWeek Radio
Archived InformationWeek Radio
Join us for a roundup of the top stories on InformationWeek.com for the week of December 14, 2014. Be here for the show and for the incredible Friday Afternoon Conversation that runs beside the program.
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.