Wednesday, April 25, 2007

Phone Forwarding Phishing

There's a report in "The Register" (here: http://www.theregister.co.uk/2007/04/25/call_forwarding_phish/ ) about phishing attempts that include instructions to dial a special phone number to verify the email.

The 'special phone number' starts with "*72", which (in the US) will forward all incoming calls to the number after the "*72". Once you fill in their form (with all the usual details), forward your phone number so that any future phone calls will go to the phisher.

Although it would seem that one would be able to track the phone number (perhaps not, with services like Skype), it is a way to get information for financial fraud. Forward the number, then start applying for credit cards. Any verification calls will be answered by the phisher.

Sort of a 'man in the middle' attack.

The SecurityDawg's rule: any email asking for personal information gets sent directly to the trash. The Dawg does not give out his credit card number to anyone that asks.

Labels: , , ,