Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Ex-Bay Networks CEO: Nortel's enterprise group could do well on its own
Net neutrality advocates score big win with broadband stimulus rules
Security guard charged with hacking hospital systems
Cisco looks to accelerate virtualization deployments
Apple patching serious SMS vulnerability on iPhone
Could Cisco take on Microsoft with office app service?
Nortel enterprise data chief wants to bring back Bay Networks
Government releases $4 billion in broadband stimulus funds
Why the iPhone can't be 'killed'
IBM bundles x86 servers with VMware, offers special financing
Users note virtualization foot-dragging among app vendors
Five slick search engines you should know about
FTC opens all out assault on economic cyber-scammers
Happy birthday! The Walkman turns 30
Cisco won't take on Amazon in cloud
Security /

Fake bank Web sites trick consumers into giving up personal data

Today's breaking news
Send to a friendFeedback

Advertisement:


A hacker doesn't have to break into a bank's computer to steal account numbers and access codes. It may be enough to set up a "spoof" Web site that closely mimics a real bank's, according to a warning issued last week by the Office of the Comptroller of the Currency (OCC).

Some customers have provided financial information to sites that they thought were legitimate Web sites, according to OCC spokesman Dean DeBuck.

The fake sites weren't exact copies of the real bank sites, DeBuck said, though some did look somewhat like the originals.

Companies can take legal action against Web site spoofers, said DeBuck. For example, wwwbankofamerica.com-just like the real site's address, but without the dot after the "www"-has

already been taken down, but not until after a few unsuspecting consumers were taken in, DeBuck said.

So far, the only losses that the OCC is aware of are of private information such as addresses, said Clifford Wilke, the agency's director of bank technology, with no thefts yet reported of personal account information or access codes.

That doesn't mean it can't happen.

"I'm telling banks to be careful and be aware that other people are out there registering similar names," Wilke said.

To keep an eye out for fraud, some banks regularly check to make sure that there aren't Web sites with similar names luring consumers.

"We are on the lookout," said Scott Scredon, a spokesman for Charlotte, N.C.-based Bank of America Corp.

Waiting for customers to come and complain may not be enough. Some may never know they were duped.

According to Richard Bell, an analyst at Needham, Mass.-based TowerGroup, a Web site spoofer may put up a front end identical to the real bank's, then send the customer back to the real Web site once the personal information is collected.

"The most secure way for consumers to protect themselves is to deal with an institution with a strong commitment to security and one that uses some sort of certificate system that the user participates in," he said.

Not only banks are targets. X.com Corp., owner of the PayPal Web site, was spoofed recently with PayPai.com, said analyst Chris Musto at Lincoln, Mass.-based Gomez Advisors Inc. Users were diverted to the fake site with a link that spelled PayPai with a capital "i" at the end, making it look identical to PayPal on many computer screens.

Musto suggested that companies can take a two-part approach to security-educate consumers to make sure that they're doing business at the correct Web site, and buy up possible alternative domain names.

For more enterprise computing news, visit Computerworld online. Story copyright © 2000 Computerworld, Inc. All rights reserved.

RELATED LINKS


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.