Welcome | Sign In
ECommerceTimes.com
Internet

Phishers Latch Onto VoIP Systems

Print Version
E-Mail Article
Reprints
Phishers Latch Onto VoIP Systems

It is not surprising that phishers have turned their attention to VoIP connections, Ron O'Brien, security analyst with Sophos, told TechNewsWorld. "We do consider it an emerging threat."


Time to upgrade your existing phone system?
Which solution will best suit your business? This free 4-part guide will help you evaluate whether your current phone system is suitable for your needs and how it may impact future growth. Learn more.

Phishers are targeting potential victims through yet another channel: voice over IP systems.

Cloudmark, a provider of messaging security applications, this week discovered two separate e-mail schemes that direct recipients to VoIP systems in an effort to steal their personal data.

The scam works like this, according to Adam J. O'Donnell, senior research scientist at Cloudmark: "The target receives an e-mail, ostensibly from their bank, telling them there is an issue with their account and to dial a number to resolve the problem."

Callers are then connected over VoIP to a PBX (private branch exchange) running an IVR (interactive voice response) system that sounds exactly like their own bank's phone tree and directs them to specific extensions.

The fake phone system then prompts the caller to enter his or her account number and PIN.

Consumers should not dial phone numbers received in e-mails from institutions, Cloudmark advises -- just as they shouldn't click on links provided by banks and other financial service providers in e-mails.

The Next Thing

The scam is particularly ingenious because it is so cheap for the phisher to run. One reason for VoIP's rapidly growing adoption, after all, is its low cost. As Cloudmark points out, VoIP-based services allow phishers to cheaply add and cancel phone numbers that are harder to trace than conventional numbers.

It is not surprising that phishers have turned their attention to VoIP connections, Ron O'Brien, security analyst with Sophos, told TechNewsWorld. "We do consider it an emerging threat," he said.

"Anytime you have an open port, you have a vulnerability -- and there will always be someone willing to try to capitalize on that vulnerability."

Same Pattern

While the this particular type of attack may be novel at the moment, O'Brien said other scam artists with a technical bent are likely to follow suit.

"These things tend to follow the same pattern," he noted. "One or two people try it out, meet with reasonable success Download Free eBook - The Edge of Success: 9 Building Blocks to Double Your Sales, and then it eventually becomes another way for criminals to generate revenue."

Consumers have to learn to think of all electronic peripherals as potentially vulnerable -- if not from phishers, then from hackers intent on stealing data they could not otherwise trick a user into revealing, O'Brien cautioned.

This wariness is necessary "especially at the end point," he said. "There are a number of devices that link with PCs, and it is essential to protect those vulnerable areas."

Over the last few years, proof of concept viruses and other malware have specifically targeted mobile phones and other handheld devices via instant messaging systems. Now VoIP joins the list of compromised channels.


Print Version E-Mail Article Reprints More by Erika Morphy


Related News Alerts

Sophos Activate Alert | Search Archives

More by Erika Morphy

Google Bends a Little Toward Nexus One Customers
February 09, 2010
Google appears to be taking some customer objections to the Nexus One seriously, although its overtures may not be enough to warm customers to its new business model. For one thing, it has reduced the fee it would charge for early termination to $150, but customers would have to pay T-Mobile an ETF as well. It has also set up a direct support line for orders -- but not for tech support.
Does 'Nimble' Pricing Suggest iPad Won't Move?
February 09, 2010
Indications that Apple may lower the price of its new iPad have surfaced -- even though its not yet available for sale -- suggesting that the company may not be certain it hit the sweet spot for consumers. One big inhibitor for a lot of prospective buyers is the extra monthly charge for WiFi and 3G connectivity.
Report: iPad Will Propel Tablets Into Mainstream Use
February 08, 2010
Will Apple's iPad do for tablets what its iPod did for MP3 players? Quite possibly. The tablet market will grow quickly on the heels of the iPad's release, according to In-Stat, which forecasts 50 million of the devices will ship in 2014. Others are less optimistic, though. Notably, consumer interest in buying an iPad did not increase as a result of the product's unveiling, according to a Retrevo survey.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Free eBook: Secure Your Datacenter
Click here to download today.
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network