Dear Action Line: I got an e-mail, apparently from my bank, about “suspicious activity” on my account. Before giving the information it requested I called my bank and was told the e-mail was a “phishing attack.” What the heck is this? — Mrs. S.O., Tulsa.
Phishing: This work is abbreviated Internet jargon for “password fishing” — an attempt by criminals to obtain credit card, bank account, routing and ID numbers so they can steal from you. Most often they appear to originate at banks or credit unions.
APWG: The Anti-Phishing Working Group Web site — tulsaworld.com/APWG — says the “number and sophistication of phishing scams reaching consumers continues increasing dramatically.” While online banking and e-commerce is very safe, as a general rule you should be careful about giving out your personal financial information over the Internet.
Digital signatures: The group compiled a list of recommendations for avoiding such scams, warning us to be suspicious of e-mails bearing urgent requests for our personal financial information. Unless the e-mail is digitally signed — see S/MIME digital signatures at tulsaworld.com/DigitalSignatures — you can’t be sure it wasn’t forged or “spoofed” — constructed to mimic.
Getting personal: Phishers typically include upsetting or exciting (but false) statements in e-mails to elicit immediate, impulsive reactions. They ask for user names, passwords, credit card numbers, Social Security numbers, dates of birth, etc. Phishing attacks are not usually personalized, but they can be. Valid messages from your bank or e-commerce company generally are personalized (addressed to you, using your full name or the name you sign your accounts with). Always call to check if you are unsure — don’t just assume the communication is real and type in what it asks for.
No links: Don’t use the e-mail links or information from an instant message or chat room to get to any Web…