Could phishing attempts be coming down?

Opinion
Feb 28, 20073 mins

* RSA’s latest consumer online fraud survey

In the run-up to the RSA Security conference, the host company (which is now called “RSA, The Security Division of EMC” – quite a mouthful!) released the results of its fourth annual Financial Institution Consumer Online Fraud Survey.

The online survey took place in December 2006 and 1,678 adults from eight countries participated. Highlighted in the press release were:

* 91% of account-holders answered that they are willing to start using a new authentication method, beyond the standard ‘username-and-password’, if their banks decided to offer stronger security.

* 73% commented that they would like their financial institution to use risk-based authentication.

* 69% of account-holders believe that financial institutions should replace username-and-password login with stronger authentication for online banking.

* 58% of account-holders believe that financial institutions should deploy stronger authentication for telephone banking.

* 82% of account-holders would like their banks to monitor online banking sessions and telephone banking sessions for signs of irregular activity or behavior – similar to the way that credit card transactions are monitored today.

The entire survey document, including all questions, demographics, etc. can be read online (or downloaded) here.

One area of the survey I found interesting had to do with the practice of “phishing.”

When asked if they’d ever heard of the term, two-thirds of the respondents said they had. When asked if they’d ever received a phishing e-mail, only 43% answered yes! (Yet I can’t think of anyone I know who has never received a phishing e-mail.) And more of the respondents said they’d seen a decrease in the amount of phishing e-mails (36%) rather than an increase (28%) recently. The balance (36%) claimed to not notice a change in the amount of phishing e-mail they got.

Now it may well be that as organizations continue to deploy better e-mail filtering services to prevent phishing attacks from reaching the user’s inbox – that certainly could skew the results as compared to earlier years. My opinion, though, is that “phishing” – like “spam” or “pornography” – is defined quite differently by different people and that’s what accounts for the year-to-year differences. Another important point when comparing this survey to the previous ones is the makeup of the respondents. For the current survey the respondents included approximately 200 adults from the United States, United Kingdom, Germany, France, Spain, Australia, Singapore, and India. Previous surveys included U.S. residents only.

In any case, the survey and its results make interesting reading – especially if your employer is a financial institution, or a vendor selling to financial institutions.