April, 2007

Phishing with widgets

Tuesday, April 3rd, 2007

Ironically as I was starting to write this post I had a quick check in my Gmail spam folder and found an email starting:
Dear PayPal customer!

As part of our security measures, we regularly screen activity in the
PayPal system. We recently contacted you after noticing an issue on your
account.We requested information from you for the following reason: …
Well apart from not having a PayPal account, I’m certainly suspicious of anyone asking me to go to something other than the expected url and even if it did I would be very wary. Unfortunately you’re probably familiar with this type of scam and have a similar careful response.

And as if on cue I’ve just received a Security Bulletin from Microsoft which contains a digital signature so that I can verify that it was sent by them.

Phishing has effectively ruled out the use of emails to customers in the …