TECF fight to eliminate phishing attempts

Opinion
Mar 7, 20055 mins

* Trusted Electronic Communications Forum

There’s no doubt that phishing, spoofing and other fake or fraudulent electronic communications have become a huge problem.  According to IBM, the fastest-growing online security threat in 2004 was phishing – a method of enticing computer users to submit personal information or fall prey to other Internet deceptions. Such e-mails grew 5,000% last year, with some 18 million phishing attempts recorded. 

I have now received so many e-mails telling me to update my eBay account that I snort at the notices, thinking that the perpetrators of this scam are so unoriginal.  But there are scammers who use original messages with legitimate-sounding scenarios.  Just in late January, for example, the Federal Deposit Insurance Corporation (FDIC) and the FBI issued a joint press release telling the public that a notice that appears to come from the FDIC and asking for verification of bank account information is indeed a hoax.  The clever criminal cites the USA Patriot Act as the reason for needing to verify the information, which, of course, is not going to the FDIC at all.

Such scenarios are truly damaging to the credibility of the individual brands and companies that are misrepresented in the fraudulent communications, as well as to the Internet overall as a commerce medium.  Some people may become so fearful of identity theft or other problems that they shy away from frequently targeted companies like eBay and CitiBank, or even from using the Internet for any type of e-commerce at all.

It is in this atmosphere of rapidly rising online threats that the Trusted Electronic Communications Forum (TECF) was formed in June of 2004.  TECF calls itself “a cross-industry, cross-geographic consortium dedicated to the standardization of technologies, techniques, and best practices in the fight against phishing, spoofing, and identity theft.”  The TECF is comprised of influential knowledge leaders in retail, telecommunications, financial services, banking and technology, who have joined forces to try to eliminate the threat that phishing poses to legitimate e-mail and e-commerce.   

The TECF says it will address all issues related to phishing and spoofing, but in particular, the TECF’s mission is to identify and deploy a standard, industry-wide solution to phishing, and assist in the prosecution of offenders.  The organization has four working groups, each of which is looking at the problem with a distinct focus: technology standards, best practices, social engineering and government affairs. 

Frankly, I’m not sure what this group is doing that is so different from the efforts of the well-established Anti-Phishing Working Group (APWG). The APWG bills itself as “the global pan-industrial and law enforcement association focused on eliminating the fraud and identity theft that result from phishing, pharming and e-mail spoofing of all types.”  Given that the APWG already has more than 700 member companies and agencies supporting its goals, perhaps the TECF should just bring its members and resources into the APWG fold and enjoy the synergy of bringing the brain trusts together.

I’ve written about APWG before (see https://www.nwfusion.com/newsletters/techexec/2004/0809techexec1.html).  This group’s Web site is one that every IT manager should bookmark in order to keep up with phishing trends and the resources to combat the problem.  It also has great advice on how to avoid the phish hook, and should be passed on to each and every one of your users.  Even if you think your users are too smart to fall for these scams, think again.  The scammers are getting smarter and bolder in their approaches, and even a savvy user could take the bait.

For example, yesterday I intentionally opened a phish message that appeared to come from eBay.  I knew it was a scam, but I wanted to see if the bait had gotten any better over the months.  I clicked on a link in the message and saw that my browser went somewhere other than the legitimate eBay site.  I laughed and closed the browser session without entering any information.  Today I had a message in my in-box that appeared to come from eBay’s security department.  The message told me that an illegal attempt was made to enter my eBay account, and that my account would be suspended until I enabled it again.  All I had to do was “click here” to verify my account.  Ding! Ding!  Warning, Will Robinson! Danger! Danger! 

Now I know that no legitimate business will EVER send me an e-mail with a link to verify my account information.  However, there are lots of people who would take the bait on that second message.  You can’t warn people often enough about the dangers of phishing.

I sincerely hope the TECF and/or the APWG are successful in their missions.  It would be nice to put these dangers behind us so we can get back to being productive workers.

Linda Musthaler is vice president of Currid & Company.  You can write to her at mailto:Linda.Musthaler@currid.com