spacer
 HOME PAGE
Today’s columns, news and more
 BASICS
Build your financial know-how
 INVESTING
Tips and tools for your portfolio
 YOUR FINANCES
Latest rates and money-saving tips
 PLANNING
Put your financial goals into action
 SPENDING
Research home, car and other purchases
 TOOLS
Calculators for financial decisions
 COLUMNS
Advice and commentary from Kiplinger's experts
 COMMUNITY
Ask a question or answer one
 EMAIL UPDATES
Sign Up!
 PUBLICATIONS
Subscribe, renew, buy books and software
 CONTACT US
Customer service, feedback, letters to the editor
 ABOUT US
Company privacy and advertising info
 

BOOST YOUR 401(K)
New online course
from Kiplinger helps
you make the most
of your savings.
See how...

Try a Free IssueKiplinger Store:
Give a Gift Subscription
for Just $10

Your Finances:   YIELDS & RATES   CREDIT & BANKING   TAXES   INSURANCE  
MAGAZINE
 

February

February 2005

bullet Magazine
bullet Contents
bullet Web Links
bullet Past Issues
bullet Try a Free Issue
bullet Customer Service
bullet Feedback

GETTING STARTED
bullet Pocket the Best Plastic
bullet How to Fix a Credit Report Error
bullet How to Adjust Your Withholding
bullet Life Insurance Made Simple
bullet Fill the Holes in Your Homeowners Insurance
bullet More...
TOOLS
bullet Search for the best credit card
bullet Should I pay off debt or invest in savings?
bullet How much life insurance do I need?
bullet 2004 survey of state tax burdens
bullet The true cost of paying the minimum
bullet Research your bank
spacer
WHICH SITE IS PHISHY?
 Think you can spot a phony? Take our phishing quiz and find out. We'll show you two sites side by side. Select the site you think is a fraud. When you're done, we'll point out the subtle tells of phishy Web pages.
  Email this  Print this
License or reprint this article

SCAMS
Can you Smell the Phish?
(Page 4 of 4)

Avoiding the hook

As phishing attacks get more dangerous, banks and other online businesses that have invested heavily in making customers comfortable with online commerce have more to lose. In addition to eating the losses, many companies are investing money and effort in reducing customers' vulnerability. Banks and credit-card issuers lost an estimated $1.2 billion to phishing last year, according to Gartner, a market-research firm in Stamford, Conn.

PayPal, for instance, has a dedicated "spoof team" that handles reports of bogus e-mails and works with ISPs to shut down fraudulent sites. (The average life of a spoofed Web site is about six days.) Because the sites usually go up before the e-mails go out, many companies have developed programs that search the Web for fake sites that bear their names, in hopes of shutting them down before they snag victims. In addition, PayPal monitors user accounts for extraordinary activity and will verify or stop unusually large transactions.

Longer term, authenticated e-mail may be a solution. Currently, the average computer user can't tell whether the "from" line in an e-mail is fake or real. But with an authentication system, your e-mail program would accept only Citibank e-mails that come from Citibank's own server. It may be a while, however, before major players in the online community can agree on a standard for authenticated e-mail.

Meanwhile, it's up to you to keep up your guard against e-mails that aim to delve into your financial accounts. "All the verities of computer hygiene are more important than ever," says Peter Cassidy, secretary general of the Anti-Phishing Working Group. That means having a firewall plus antivirus and anti-spyware programs running on your computer. (The popular programs include Norton Personal Firewall, McAfee Personal Firewall Plus and Zone Alarm, which will keep intruders from hijacking your computer; Norton AntiVirus and McAfee Virus Scan, which will keep your computer virus-free; and Spybot-S&D and Ad-Aware, which zap spyware.) In addition:

Ignore e-mails urgently requesting personal information. If PayPal really needs to update your expired credit-card number, for instance, you'll be able to take care of it the next time you make a transaction. "If you're suspicious, just delete it," says Sara Bettencourt, a spokeswoman for PayPal. "We'll get to you some other way."

Never go to an online site by clicking a link in an e-mail. Open your browser and type in the company's home-page address.

Be wary of e-mail offers that seem too good to be true, such as merchandise with unusually low prices and "free" items with small shipping fees. They, too, could be credit-card-number traps.

Change your passwords frequently so that they'll be out of date if it takes weeks or months for thieves to use your data or sell it to others.

Check your statements regularly and report fishy transactions right away. Theft from online accounts generally falls under Federal Reserve Regulation E, which says that financial institutions must limit your liability to $50 if you report a loss within two days of receiving your statement and to $500 if you report it within 60 days. In practice, most banks (as well as providers of electronic transfers, such as PayPal) reimburse customers in full when their accounts are raided in a phishing fraud.

If you've taken the bait, call the company that's been spoofed (your bank or ISP, for instance) and report the incident right away. If you're prompt, you can normally change your password or account number in time to stop unauthorized transactions.

--Research: Joan Goldwasser

 BACK      1  2  3  4  

ADVERTISEMENT

  Find This Article Helpful?
  Sign up for email delivery of our columns and site updates.

  There's plenty more where that came from.
  Subscribe to Kiplinger's Personal Finance magazine at a low introductory rate.

  SPONSORED LINKS

Customer Service | Subscribe by phone:  800-544-0155
All contents © 2005 The Kiplinger Washington Editors, Inc.