Phishing and Identity theft
Deception used to steal credentials and identities.
5-mark Exam Answer
Phishing is any deceptive, online attempt by a third party to obtain confidential information for financial gain. It typically relies on social engineering — the exploitation of human fallibility and gullibility — and is closely tied to identity fraud.
- 1.Phishing definition
- 2.Social engineering technique
- 3.Nigerian letter and spear phishing
- 4.Spoofed websites capture credentials
- 5.Identity fraud: unauthorized use of personal data
Social engineering relies on human curiosity, greed, and gullibility to trick people into taking an action that results in the downloading of malware or disclosure of information. Phishing is any deceptive, online attempt by a third party to obtain confidential information for financial gain. Phishing attacks typically do not involve malicious code but rely on straightforward misrepresentation and fraud.
One popular phishing attack is the Nigerian letter e-mail scam, in which a rich foreign official claims to need a bank account to stash millions and offers a share. Thousands of other phishing attacks pretend to be eBay, PayPal, or Citibank writing for account verification — known as spear phishing, which targets a known customer of a specific bank.
Clicking a link takes the user to a website controlled by the scammer, where they are prompted to enter confidential information. Phishers create (or 'spoof') a website that purports to be a legitimate financial institution and con users into entering financial information, or the site downloads malware such as a keylogger to the victim's computer.
Phishers use the gathered information to commit fraudulent acts such as charging items to credit cards or withdrawing funds — in other words, to 'steal your identity' (identity fraud). Identity fraud involves the unauthorized use of another person's personal data for illegal financial benefit. Total dollar losses from identity fraud were approximately $15 billion in 2015.
An email pretending to be from Citibank asks a known customer to verify account details via a link. The link leads to a fake Citibank site that captures the victim's credentials, which the attacker uses to drain the account — a typical spear-phishing-driven identity fraud.
Phishing exploits human trust to obtain confidential information that enables identity fraud, causing billions of dollars in losses annually; defenses include user awareness and email authentication systems like DMARC.
The exam interface follows the university paper pattern: Section A & B carry 5-mark questions; Section C carries objective questions.