728_header.jpg (23748 bytes)
Google  Web AuctionBytes  
eBay Live 2008 Recap
News!
Pictures!
Podcasts!
Blog!

Sponsor

Home
Subscribe
Blog
Podcasts
Forums
AuctionBytes TV
ABU Back Issues

COOL TOOLS

Calendar
Collectors' Links
eBay Promo History
Bookshelf
Fraud Resources
Auction Site Fees
Auction Management
Payment Services
Storefronts Chart
Sniping Chart
Consignment Services
Drop-Off Store Laws
Ecommerce Resources
Photo Tips
Marketing Inserts
Bill the Postman
Yellow Pages
Classifieds

AUCTIONBYTES

Our Writers
Write For Us
Partners
Press
Advertising
About Us
Link To US

Auctionbytes-NewsFlash, Number 809 - July 20, 2004 - ISSN 1539-5065      | Next Story

eBay Users Plagued by Hoax Email 'Phishing' Attacks
By Ina Steiner
AuctionBytes.com
July 20, 2004
AddThis Social Bookmark Button

Fraudsters continue to trick people into revealing personal information and passwords by sending emails appearing to come from legitimate companies. eBay and PayPal are frequent targets of spoof emails, and fraudsters have also posed as banks, ISPs and retailers. The Anti-Phishing Working Group is an industry coalition working to eliminate the problem of phishing and email spoofing attacks by developing and sharing information about the problem, and promoting the visibility and adoption of industry solutions. One of its most useful features is a database of sample hoax emails, found at http://www.antiphishing.org/phishing_archive.html.

In May, Tumbleweed Communications Corp. and The Anti-Phishing Working Group released a report that showed email fraud and phishing attacks grew by more than 180% in April, with an average of 38 new unique attacks sent out to millions of consumers each day. (A copy of the report in PDF format can be downloaded at http://www.antiphishing.org/APWG_Phishing_Attack_Report-Apr2004.pdf.) The company most-targeted by phishing attacks in April was Citibank with 475 unique attacks. This represented the first time that eBay was not the most targeted company.

Spoof email made to look like its coming from eBay usually conveys a sense of urgency, counting on people to panic and reply right away before they have time to think. Some messages include a line like this: "We will shut down your account if you don't immediately verify your account information, click on the link below." Other messages tell recipients they will get a reward, like the one that urged people to click through so they could get 30% off eBay service fees in recognition of earning a feedback star.

eBay created a security center at http://pages.ebay.com/securitycenter/index.html (PayPal has had one for years). eBay also added an indicator to its Toolbar let users know if they are on a legitimate eBay or PayPal site (http://pages.ebay.com/help/find/toolbar.html). But many users dislike toolbars residing on their computers, tracking their movements.

Recent legislation hopes to deter phishing and identity theft by increasing the penalties for those convicted. According to authors of H.R. 1731, known as the Identity Theft Penalty Enhancement Act, "currently under 18 U.S.C. Sec. 1028 many identity thieves receive short terms of imprisonment or probation; after their release, many of these thieves will go on to use false identities to commit much more serious crimes." More information about the bill can be found online at http://digbig.com/4bkmq.

Jahan Moreh, UCLA educator and chief security architect of Sigaba secure messaging (http://www.sigaba.com/products/secure_email), said the bill addresses one aspect of the phishing problem, but there needs to be a technical aspect as well. Sigaba promotes email that authenticates all parties – senders and receivers. However, authentication always requires someone to vouch for the identity of a party. Moreh said he sees organizations like banks and even eBay acting as trusted ID brokers. Banks can bind your ID with your current email address, and provide identity verification. Moreh believes it is inevitable that companies like eBay will use secure email, which Moreh believes is the only solution to phishing problems.

In the meantime, AuctionBytes' recommendation continues to be, never click on a link in an email to log in to a site. Open a browser window, type in the URL of the site, and log in, making sure to use secure sign-in (look for the "https" in the address line).


Email this story to a friend.

| Next Story

Related Stories
  • Time Looks at eBay - January 29, 2001, Issue #8
  • Ever Wonder what eBay Looks Like? - February 03, 2001, Issue #31
  • eBay Move May Impair Auction Management Tools - May 23, 2001, Issue #88
  • eBay to Redesign Home Page - May 28, 2001, Issue #90
  • Are eBay's Shortcomings Symptoms of a Fatal Disease? - November 28, 2001, Issue #211
  • Business Week Looks at eBay - November 29, 2001, Issue #212
  • Is eBay Too Big for Its Britches? - December 16, 2001, Issue #222
  • Editorial: Can eBay Do More to Stop Serial Offenders? - January 20, 2002, Issue #62
  • Newsweek Cover Story: The United States of eBay - June 10, 2002, Issue #333
  • eBay Promotes Head Techie to COO - June 26, 2002, Issue #345
  • eBay Introduces New Buyer's Toolbar - June 27, 2002, Issue #346
  • eBay Makes New Form Default for Sellers - July 02, 2002, Issue #349
  • Standard & Poor's Adds eBay & UPS to S&P 500 Stock Index - July 11, 2002, Issue #356
  • eBay Holds Penny-Gallery-Day Promotion - September 13, 2002, Issue #392
  • Recent eBay News Roundup - May 19, 2003, Issue #540
  • Identity Theft Up Nearly 80 Percent, Gets National Attention - July 22, 2003, Issue #579
  • Amazon.com Files Lawsuit to Combat Email Forgeries - August 27, 2003, Issue #598
  • Hoax Emailers Broaden Attempts to Steal Identities - September 15, 2003, Issue #608
  • eBay to Launch New Sign-In Function for Increased Security - November 18, 2003, Issue #649
  • Scammers Go Phishing on Amazon.com - January 16, 2004, Issue #683
  • eBay Holds Sale on Subtitle Feature for Sellers - January 27, 2004, Issue #689
  • Update: PayPal Payment Wizard Raises Phishing Concerns - February 06, 2004, Issue #696
  • Scammers Impersonate UPS in New Twist on eBay 'Fake Escrow' Fraud - February 12, 2004, Issue #699
  • Former PayPal CEO Creates Solution to Hoax-Email Scams - February 25, 2004, Issue #707
  • eBay: Scammers Obtained Customer Data from PayPal Merchants - March 15, 2004, Issue #718
  • eBay Hoax Email Alert: Win a Great Prize - April 06, 2004, Issue #733
  • New Hoax: 'Donate $1 and pay no more eBay fees for 2004' - April 28, 2004, Issue #749
  • eBay Denies Report of Database Hack - July 27, 2004, Issue #814
  • Amazon.com and Microsoft Sue Spammers and Phishers - September 29, 2004, Issue #858
  • eBay Signs up for Phish Report Network - February 15, 2005, Issue #954
  • Phishers Use New Bait to Trick eBay Users - March 04, 2005, Issue #967
  • eBay CEO Stays Put, Speculation Continues - March 16, 2005, Issue #975
  • eBay Announces Phase 2 of My Messages, Citing Phishing Concerns - June 02, 2005, Issue #1031
  • eBay Adds Shipping Cost Averages in SYI Form - June 03, 2005, Issue #1032
  • Ten-Cent Listing Day on eBay Is a Fraud - July 26, 2005, Issue #1071
  • PayPal Launches Identity-Protection Resources - August 02, 2005, Issue #1076
  • Auction Software FAQ: How can I tell if I'm being phished? - November 06, 2005, Issue #154
  • IRS Warns of Email Scam about Tax Refunds - December 02, 2005, Issue #1164
  • Meg Makes it Official: Stepping Down as eBay CEO - January 23, 2008, Issue #1711



  • Discuss this story in our forums.

    Ecommerce Podcasts

    Site Index
    Copyright 1999-2008. Steiner Associates LLC. All rights reserved