Fraudulent messages - phishing

Last modified by vyv0010 on 27.04.2015 09:02

These are fraudulent e-mail attacks with goal to elicit private information from user as login to the accounts, card PIN etc.

How to recognize fraudulent e-mails:

  • With graphic design of the message attackers are trying to give the impression that the message was send by an organization whose clients are attacked.
     
  • Text can look like information about non-payment, call for verification of the password validity or its change or as client satisfaction research with a service.
      
  • In the message text is a link which should look that it is directed to the websites of the organization (bank) but on closer examination you find out that it is linked to somewhere else and there are fraudulent websites.
      
  • In the browser address line is showed different address than address of the organization whose clients are attacked. Sender address can also be from different domain than websites of the organization (you see it after showing head of an email).
      
  • Message/form encourages you to share information that would not be required by the organizaton.

[source: http://www.hoax.cz/phishing/]

How can you help:

Forward to us every suspicious message by email on abuse@vsb.cz and attach also the source code of the message (see guides for Outlook 2010, Outlook 2007, Thunderbird, Horde).

What can I do to protect security of my account:

  • please, report us suspicious messages immediately on abuse@vsb.cz and leave the message in the mail until you are asked (for case that you won't sent all necessar information),
  • never reply to suspicious messages,
  • don't click on links in suspicious messages,
  • tell nobody and never your login.

I responded to a suspicious message:

  • change disclosed password immediately (see password change),
  • don't be affraid and don't be shame we are happy and willing to help you. Please report us the situation and we also investigate if someone else has been also caught.

Examples:

View message head detail in the email client and check addresses. From and Reply-to. Don´t tell your login and password by email.

Example No. 1

phishing.gif
 

Example No. 2

phishing_2.gif

Example No. 3

phishing_3.png

Example No. 4

phishing_4.png 

Example No. 5

phishing_5.png

Example No. 6

phishing_6.png 

Example No. 7

phishing_7.png

Example No. 8

phishing_8.png

Example No. 9

phishing_9.png