詳細検索

Phishing scams and anti-phishing measures! What users and service providers should do

by Marcelo Mesquita
4 min read
Tags biz

Phishing scams and anti-phishing measures! What users and service providers should do
Translated from Português (Brazil) • View original

Have you ever heard of "Phishing"?" Phishing" is one of the cybercrimes. Today I will explain about this scam and show you how to avoid it. What type of scam is **** phishing? Phishing is a cybercrime, where hackers impersonate real organizations, such as a large mailing site or bank, and use fake websites or emails to steal important personal information, such as credit card information and login passwords. If this information is stolen, it can be misused, impersonating someone, making a large amount of purchases, illegal shipments, and so on. As time goes on, the risk of this phishing scam is increasing as the number of people buying products on the internet increases more and more. What is a phishing scam? There are several methods of phishing scams, but email is a typical technique.

  • "We've introduced new security features."
  • "Personal information leaked."
  • "We have confirmed the access of a third party".

By sending a warning email, you are taken to an invalid URL to enter the information. Recently, there are cases where not only emails but also shopping websites are created and directed to them. Note that they are very well made, making the fake websites as close to the real thing as possible, often with exactly the same structure. When buying something on the Internet, make sure to check the URL of the website carefully to make sure it is safe before entering the information. What should I do to avoid phishing? (User side) To avoid phishing scams, keep the following in mind when shopping or entering personal information on the Internet: (1) To****cease the correct URL

  • ・Check the sender of the email to see if they are suspicious.
  • ・ Make sure the destination URL is not suspicious or actually exists, and do not click on the URL described in the email.
  • ・ Make sure you are accessing a different page than usual

(2) Be careful with fake emails********

  • ・ If you receive a suspicious email, check the content of the service on the real website.

(3) Check the security of your device (PC, mobile, etc.)

  • ・ Keep the software up to date
  • ・ Actively utilize the security functions of service providers (two-factor authentication, security software, etc.)

You can also take anti-phishing measures, so keep in mind the above points. What should I do to avoid phishing? (Service provider side) Of course, user-side measures are necessary. However, if a fake email or website is created and a victim appears, it can lead to a reliability problem and deterioration of credibility on the service provider's side, so it is necessary for the service provider's side to take action as well. "Mamoru PUSH" is a recommended solution as a countermeasure against phishing. Why is "Mamoru PUSH" strong in phishing? I would like to introduce three points. Point 1: Block unauthorized access with standby function! You will not receive push notifications unless you give permission in the smartphone app before logging in. Therefore, even if a malicious third party obtains an ID/password through phishing, all access can be blocked. Only a person with legitimate login information logs in with a clear intention. It is also effective as a countermeasure against restoration attacks that try to log in to a website by listing illegally obtained IDs and passwords. Point 2: Detect unknown threats! If the access is from an environment where you have never previously logged in, a warning will be displayed. Only after accepting the warning will the normal approval screen be displayed. When the login is approved, two types of highly encrypted tokens are generated in the background and combined. Point 3: Supports phishing scams that cannot be prevented with one-time passwords There is a way to authenticate with a password that can only be used once (one-time password), but recent phishing scams are increasing the number of ways to crack one-time passwords. One-time passwords are not a good anti-phishing measure. That's why introducing two-factor authentication is effective as a defensive measure against phishing. Mamoru PUSH is a two-factor authentication using ID and terminal. Even if the user enters an ID/password on a fake website and a hacker tries to log in to the real website based on this information, a warning message is displayed on the user's terminal when an authentication request is issued from an environment that has never been authenticated. In the unlikely event that you enter information on a phishing website and allow unauthorized access, you can block unauthorized access remotely when the user notices. Mamoru PUSH for anti-phishing measures**!** Mamoru PUSH is a passwordless authentication and is designed to be easy to use not only for service providers but also for users. Colorkrew, which has been providing billing and authentication services for more than 10 years, offers highly satisfactory authentication services with reliable operational results and expertise. Original post - https://mamoru-secure.com/security\_articles\_18.php?source=biz\_en

Related Articles