#12unit 1online security and payment system

Phishing and Identity theft

Deception used to steal credentials and identities.

Learning Objectives

  • Define phishing and social engineering.
  • Explain how phishing attacks work using the Nigerian letter scam and spear phishing.
  • Define identity fraud (identity theft).
  • Describe defensive measures such as DMARC.

Explanation

Phishing is when attackers trick users into revealing confidential information via fake emails or websites. Identity fraud is using someone's stolen personal data for illegal financial gain. Phishing often uses social engineering — exploiting human gullibility rather than technology.

Social engineering relies on human curiosity, greed, and gullibility to trick people into taking an action that will result in the downloading of malware. Kevin Mitnick, one of America's most wanted computer criminals, used simple deceptive techniques to obtain passwords, social security, and police records without any sophisticated technology.

Phishing is any deceptive, online attempt by a third party to obtain confidential information for financial gain. Phishing attacks typically do not involve malicious code but instead rely on straightforward misrepresentation and fraud — so-called 'social engineering' techniques. One of the most popular phishing attacks is the e-mail scam letter: a rich former oil minister of Nigeria is seeking a bank account to stash millions of dollars, and requests your account number where the money can be deposited, in return for a million dollars. This is popularly known as a 'Nigerian letter' scam.

Thousands of phishing attacks use other scams, some pretending to be eBay, PayPal, or Citibank writing for account verification (known as spear phishing — targeting a known customer of a specific bank). Clicking a link takes the user to a website controlled by the scammer, where they are prompted to enter confidential information. Phishers create (or 'spoof') a website that purports to be a legitimate financial institution and con users into entering financial information, or the site downloads malware such as a keylogger.

Phishers use the gathered information to commit fraudulent acts such as charging items to credit cards or withdrawing funds from bank accounts — in other words, to 'steal your identity' (identity fraud). Identity fraud involves the unauthorized use of another person's personal data for illegal financial benefit. According to Javelin Research & Strategy, total dollar losses from identity fraud were approximately $15 billion in 2015.

Key Points & Important Terms

Key Points

  • Phishing = deceptive online attempt to obtain confidential information.
  • Phishing relies on social engineering, not necessarily malicious code.
  • Common forms: Nigerian letter scam, spear phishing.
  • Phishers spoof legitimate websites to capture credentials.
  • Identity fraud = unauthorized use of personal data for financial gain.
  • Defenses include DMARC for email authentication.

Important Terms

Phishing
Any deceptive, online attempt by a third party to obtain confidential information for financial gain.
Social engineering
Exploitation of human fallibility and gullibility to distribute malware or obtain information.
Spear phishing
Phishing that targets a known customer of a specific bank or business.
Nigerian letter scam
A common email phishing scam claiming a foreign official needs an account to stash millions.
Identity fraud
The unauthorized use of another person's personal data for illegal financial benefit.