Home > Microsoft Exchange News > Companies see a surge in phishing attacks
Microsoft Exchange News:
EMAIL THIS

Companies see a surge in phishing attacks

By Bill Brenner, News Writer
06 Jul 2005 | SearchExchange.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Two new reports offer insight into how the digital underground is using its vast array of botnets. If the last two months are any indication, the standard weapon of these zombie armies is a phishing rod.

The first indication of that comes from IBM's Global Business Security Index Report, a monthly roundup of potential security threats based on data the company collects from 2,700 security professionals and half a million monitored ((Content component not found.)) devices around the world. Based on the most recent data, the New York-based company said attempted phishing attacks in May were up 226% over the previous month. IBM's security analysts attributed this to the rapid proliferation of botnets -- armies of hijacked machines used to blast out massive amounts of the scam e-mails at the heart of most phishing attacks.

The second indication comes from Redwood City, Calif.-based security firm Postini. According to its records, the company said it protected customers against 16,667,444 phishing attempts in June -- a 71% increase per day compared to May. Postini said it was the second-highest number of attempted attacks since it started keeping a monthly score. March stands out as the month with the most attempts so far this year, the firm said.

"IT systems have become so crucial to today's business operations, work productivity and customer service that even a small disruption can have serious impact on business operations," Cal Slemp, IBM Global Services' vice president of security and privacy, said in a statement. "Loss of data integrity or confidentiality can lose a customer base that took years to build. Security is now something that companies can no longer afford to be without."

While both companies have seen a dramatic spike in attempted phishing attacks in the last two months, their research differs when it comes to the level of other attacks.

Postini sees fewer virus e-mails
Postini saw a decrease in the number of virus-infected e-mail messages for June. The number of directory harvest attacks [DHAs] against corporate networks also decreased in June, compared with the month before. The company saw a 23% drop in the average number of DHA attacks per day against enterprise networks.

Postini said the top 10 viruses for June were:

  • Mytob, 42,564,787 detections
  • Netsky, 9,678,418 detections
  • Mime, 5,204,341 detections
  • Bankfraud, 4,166,861 detections
  • Bagle, 2,984,403 detections
  • Zafi, 1,397,793 detections
  • Downloader-abl, 1,311,393 detections
  • Mydoom, 1,049,130 detections
  • Lovgate, 1,025,157 detections
  • Klez, 218,789 detections

IBM sees more viruses
By comparison, IBM reported that more than 30% of e-mails in May contained some form of virus -- a 33% increase from the previous month. In many instances, the virus traveling by e-mail infiltrated a computer's hard drive and then forwarded itself to the user's entire address book.

"In May, one in 32.2 [3.12% of all e-mail] e-mails contained some form of virus or Trojan attack, a significant increase over the past month of 33%," IBM said in a statement. "To combat malware such as Sober, Mytob and other variants of these viruses, IBM advises organizations to keep antivirus signatures up to date and keep current with Windows patches."

IBM also found that application hacking accounted for 90% of system compromises in May.

"Two critical points in Web application security are the creation and management of sessions and filtering all data input," IBM said. "These types of compromises from a Web application can lead to exposure of banking information, private sensitive data like credit card information, and competitive intelligence information."

This article originally appeared on SearchSecurity.com.



Tags: Phishing and Email Fraud ProtectionEmail Policy ManagementAntivirus Software and Virus ProtectionVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Exchange Server Security
OWA 'Loading' problems with Internet Explorer security zones
New Exchange Server tools named as Products of the Year
Beware of bare linefeeds in Exchange Server email
Top 10 Exchange Server administration tips of 2006
Enabling protocol logging for Exchange Server
Eliminate annoying Microsoft Outlook security warnings with ClickYes Pro
Forefront beta secures SharePoint collaboration
Dell, Symantec simplify Secure Exchange for SMBs
Tutorial: How to determine which ports Exchange Server is using
Unsecured devices worry IT professionals
Exchange Server Security Research

Phishing and Email Fraud Protection
Exchange 2007 out-of-office (OOF) feature adds usability and security
Microsoft Outlook and Exchange Server 2003 Email Security Guide
A Microsoft Outlook email security tutorial -- 8 tips in 8 minutes
Microsoft Office 2007's native security and antiphishing tools
New tools fight fraud and phishing
Phishing protection primer
Phishing: A whale of a problem for enterprises
Three ways phishers are hooking you
New phishing threat outpaces Netsky-P
PhishTank casts its net for malicious email

Email Policy Management
Changing email address formats in Exchange Server 2003
Configuring the default recipient policy in an Exchange 2003 environment
Microsoft Exchange Server email archiving tutorial
Setting up email disclaimers and signatures in Exchange Server
Use the OWA Admin tool to 'segment' Outlook Web Access 2003 features
Why are .PST files a security threat to Exchange Server mailboxes?
Customizing Outlook Web Access (OWA) in Exchange Server 2007
Managing Microsoft Outlook search folder functionality
Moving mobile user mailboxes from Exchange 2003 to Exchange 2007
How to set up Exchange 2007 message classifications

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
greylist  (SearchExchange.com)
Sender ID  (SearchExchange.com)
Vouch by Reference (VBR)  (SearchExchange.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



E-mail Security - Spam Filtering, Anti Virus, Password Management, Exchange Server Permissions
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2004 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts