Phishing is Old School – Now it’s Vishing

November 20, 2007 – 6:23 am

Phising is an attempt to fraudulently acquire sensitive information such as user names, passwords and creditcard numbers by posting links to websites which appear to be authentic electronic commerce sites, but are in fact just a method to gather personal data.  A user, for example, might receive an email which states that their user information must be updated with their bank along with a link to what appears to be their bank’s website.  When the user follows the link, a more-or-less authentic looking webpage appears.  When the user tries to log in, in fact they have just provided their information to the bad guys.

Vishing is similar only the user is directed to a phony phone number.  A victim may receive an email which states that their creditcard has been disabled due to possible fraud.  The victim is then directed to call the credit card company.  The phone number given is a direct line to the bad guys.  In some variations of the scam, the bad guys even call the victim.  The bad guys can even use voice over IP technology to send a fake Caller ID to the victim’s telephone, making the victim think that the call is legitimate.

Regardless of the source, never give out your personal information and report any suspicious attempts to gather your personal data.

You must be logged in to post a comment.