<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CounterMeasures -  A Security Blog » Vishing</title>
	<atom:link href="http://countermeasures.trendmicro.eu/category/phishing/vishing/feed/" rel="self" type="application/rss+xml" />
	<link>http://countermeasures.trendmicro.eu</link>
	<description>Trend Microâ€™s Rik Ferguson blogs about current security issues.</description>
	<lastBuildDate>Tue, 07 Feb 2012 17:51:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>SMiShing Time, wish you were here!</title>
		<link>http://countermeasures.trendmicro.eu/smishing-time-wish-you-were-here/</link>
		<comments>http://countermeasures.trendmicro.eu/smishing-time-wish-you-were-here/#comments</comments>
		<pubDate>Tue, 25 Aug 2009 11:01:11 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[data leakage]]></category>
		<category><![CDATA[SMiShing]]></category>
		<category><![CDATA[Underground Economy]]></category>
		<category><![CDATA[Vishing]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[nuisance calls]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[SMS]]></category>
		<category><![CDATA[telephone]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1266</guid>
		<description><![CDATA[Earlier this summer, CIFAS, the Fraud Prevention agency warned about a rise in the threat from SMiShing, this warning has recently been echoed by the Guardian Newspaper. Â  SMiShing reports date back to around 2006 when this threat started to become noticeable. Spoofed or otherwise faked SMS messages areÂ used as baitÂ to lure victims to responding [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/smishing-time-wish-you-were-here/' addthis:title='SMiShing Time, wish you were here! '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p>Earlier this summer, CIFAS, the Fraud Prevention agency <a title="Fraud threats change but the damage remains" href="http://www.cifas.org.uk/default.asp?edit_id=903-57" target="_blank">warned </a>about a rise in the threat from SMiShing, this warning has recently been <a title="Phishing: How not to get reeled in" href="http://www.guardian.co.uk/money/2009/aug/22/phishing-online-scams" target="_blank">echoed by the Guardian</a> Newspaper.</p>
<p>Â </p>
<p>SMiShing reports date back to around 2006 when this threat started to become noticeable. Spoofed or otherwise faked SMS messages areÂ used as baitÂ to lure victims to responding via SMS to premium rate services, visiting a malicious website or calling a telephone number. The SMS messages are not malicious in themselves but often require the recipients attention for something which must be completed <em>immediately</em> or <em>urgently</em>,&#8221;confirming&#8221; or &#8220;activating&#8221; account or credit card details, cancelling non-existent subscriptions or confirming imaginary purchases.</p>
<p>Â </p>
<p>The threat from SMiShing sometimes works in conjunction with VishingÂ (voiceÂ phishing) when the recipient is required to call a telephone number,Â orÂ with more traditional PhishingÂ when the recipient is directed to visit a particular website, SMiShing messages have also been known to direct recipients to malicious websites designed to infect them.</p>
<blockquote><p>&#8220;<em>Someone posted your full personal and banking information at insert-bad-url-here website you must remove it now</em>&#8221;</p>
<p>Â </p>
<p>&#8220;<em>Notice &#8211; this is an automated message from insert-bank-name-here, your ATM card has been suspended. To reactivate call urgent at +##-####-####</em>&#8221;</p>
<p>Â </p></blockquote>
<p>In the case of Vishing, if the victim callsÂ the number, an automated system (<a href="http://en.wikipedia.org/wiki/IVR">IVR</a>), or occasionally aÂ real person,Â will prompt them for things like credit card number, CVV code (the number on the back of your credit card), expiry date or bank account details and even card PIN numbers. Criminals will also often seek to elicit personal information such as date of birth, personal identification numbers (SSN, National ID etc.). Click <a title="SMiShing Scam Audio Sample" href="http://www.fightidentitytheft.com/blog/smishing-scam-audio-sample" target="_blank">here </a>for an audio capture of such a system.</p>
<p>Â </p>
<p>If the phishing threat is web-based the stolen information can be more extensive and include items which are more difficult to enter on a telephone keypad, such as mother&#8217;s maiden name and email address. These items are then used to create faked credit cards or sold on as ID packs for others to do the carding.</p>
<p>Â </p>
<p>Â </p>
<p>Concurrently we are also seeing a rise in speculative outbound vishing calls. These kinds of calls exploit the trust that people have in the traditional and the familiar telephone system.Â Advances in technology, specificallyÂ  the use of the internet to make and take telephone calls (<a title="Wikipedia - Voice over Internet Protocol" href="http://en.wikipedia.org/wiki/VoIP">VoIP</a>) has really simplified the process of spoofing or faking your caller ID and makingÂ the scammer much more difficult to trace and to block.Â This threat has grown established to the extent where <a title="Cybercriminal Call Centres?" href="http://countermeasures.trendmicro.eu/cybercriminal-call-centres/" target="_blank">telephone based cybercrime-as-a-service outfits are already in business</a>.</p>
<p>Â </p>
<p>VishingÂ calls arrive with a spoofed caller telephone number and often come from outside the country of residence of the victim. An example is detailed in an earlier blog <a title="Dial 0308-PHISH" href="http://countermeasures.trendmicro.eu/dial-0308-phish/" target="_blank">here</a>.</p>
<p>Â </p>
<p>If you receive a communication that you were not expecting, whether it be by telephone, email, SMS or carrier pigeon, and that communication is asking you to give up sensitive information, *<strong>do not respond</strong>*. Do not reply to the email or SMS, do not talk to the person on the end of the telephone or click on any links provided to you. Instead, note the name of the company the communication is supposedly from and contact them directly to find out if they indeed have something they wish to tell you. Contrary to some advice I have seen, I would not advise immediate deletion of the SMS or mail as the contents of it may be helpful to the organisation that is being impersonated.</p>
<p>Â </p>
<p>If you need SMS anti-spam technology, then <a title="Trend Micro Mobile Security" href="http://uk.trendmicro.com/uk/products/enterprise/mobile-security/index.html" target="_blank">look no further</a> (it&#8217;s in the <a title="TIS Pro 2009" href="http://uk.trendmicro.com/uk/products/personal/internet-security-pro-2009/index.html" target="_blank">Pro version</a> of the consumer product too)&#8230;</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/smishing-time-wish-you-were-here/' addthis:title='SMiShing Time, wish you were here! '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/smishing-time-wish-you-were-here/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

