Skip to main content

Phishing Attacks Reach All-Time High

The Anti-Phishing Working Group, a pan-industry association aimed at eliminating identity theft and fraud through phishing, pharming, and email spoofing, is reporting November 2005 marked a new high in email fraud attacks (PDF), with the organization identifying nearly 17,000 unique phishing attempts and over 4,600 unique phishing sites active during the month. The number of unique phishing attacks was nearly double those identified during November 2004 and marks an all-time high.

Phishing attacks are attempts to steal sensitive or personally identifying information like credit card numbers, passwords, account numbers, and more, usually through a combination of social engineering and technical trickery. A typical phishing scheme will employ a “spoofed” email which appears to be from a bank, reputable company, or other institution requesting users verify or update their account information. Of course, the message is fake, and either transmits any collected information to a site controlled by the scammers, or (in a so-called pharming attack) directs users to a Web site which looks like the real institution, but is operated by the scammers solely to collect sensitive information. Once collected, these details are used to obtain unauthorized access to accounts or services, or sold to criminals for that purpose. Scammers also use Trojan horse programs and spyware to obtain sensitive information directly by scanning a user’s files and/or monitoring their keyboard activity.

Recommended Videos

The Anti-Phishing Working Group found that the number of brand names exploited in phishing attacks increased from 64 to 93 during the last year, and now more regularly includes names like Google, Apple, PayPal, and eBay in addition to large financial institutions and credit card companies.

Contrary to some popular belief, the AFWG found during November 2005 that nearly one third of active phishing sites were hosted within the United States with South Korea and China accounting for 11.3 and 8.04 percent respectively. Phishing sites remained online for an average of five and a half days, although some remained online and running for the entire month.

The APWG also found 165 unique password-stealing applications were active during November 2005, and more than 1,000 sites knowingly (or unwittingly) hosted password-stealing trojan horses. Phishing methods are also becoming more sophisticated, including programs which rewrite a computers DNS server information to route specific requests through rogue DNS servers operated by the scammers.

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
The price might not be the problem with Nvidia GPUs after all
The RTX 5090 sitting on a pink background.

European markets are seeing dips in prices of the Nvidia RTX 50-series GPUs as the exchange rate between the euro and the dollar has become stronger. This has allowed Nvidia to slash the prices of some of its current graphics cards by approximately five percent.

According to Videocardz, Nvidia has updated the pricing for its Germany sector webpage, changing the price of the RTX 5090 to €2,230 from its launch price of €2,330. The RTX 5080 has dropped from €1,170 to €1,120. The RTX 5070 has dropped from €650 to €620. Notably, the RTX 5070 Ti maintains its €880 pricing, likely because it is the only graphics card to be released without a Founders Edition variant.

Read more
Watch out for this phishing scam impersonating Booking.com
Woman pulling out credit card in front of laptop.

If you work in hospitality and find an email in your inbox from Booking.com claiming to be an angry guest, then watch out -- it may well be part of a phishing scam. Microsoft has warned that a phishing campaign has been underway sending fake emails from Booking.com which lead users to download malicious software.

In a blog post about the issue, Microsoft Threat Intelligence writes that this is an ongoing campaign which has been around since December last year, and uses a social engineering technique called ClickFix. The victim receives an email which appears to come from Booking.com and which can vary widely in its content -- from guest complaints to requests for information from potential guests to account verification -- and which includes a link (or attaches a PDF with a link) that claims to take the user to Booking.com to deal with the issue.

Read more
I was struck by OpenAI’s new model — for all the wrong reasons
Announcement artwork for GPT 4.5 AI model

Sam Altman has shared a snippet from a new OpenAI model trained for creative writing. He says it's the first time he's been "struck" by something AI has written but the comments section is a total mess of extreme agreement and disagreement.

https://x.com/sama/status/1899535387435086115

Read more