Mobile UPI  |   About UPI  |   UPI en Español  |   UPI Arabic  |   UPIU  |   My Account
Search:
Go

'Whaling' Internet fraud threatens corporate data, executives' safety

|
|
 
  
Published: Aug. 31, 2009 at 7:00 PM
Advertisement

NEW YORK, Aug. 31 (UPI) -- A rash of "whaling" attacks on corporate data threatens sensitive business information and executives' financial security with no apparent foolproof way available to stem identity theft and online scams, industry sources said.

"Whaling" -- suggesting a hunt for "a big one" -- has progressed from scams called "phishing" where individuals are hoodwinked into divulging sensitive private information about their finances or personal data used in financial transactions.

"Whaling" first came to light in 2007, but because of the sensitivity of the fraud perpetrated on corporate individuals it remained cloaked in secrecy or its frequency was suppressed, the sources said.

"With targeted phishing attacks on the rise, it's no surprise that cybercriminals are doing their research and aiming at those with the most to lose -- executives," Network World, provider of information, intelligence and insight for network and information technology executives, reported.

As the threat grew in size and individuals chosen as targets became more top brass than ordinary IT workers, "phishing" became "whaling" with far-reaching damaging consequences for individuals and the corporate entities they worked with, analysts said.

However, as "whaling" incidents multiply, corporate security experts are finding it increasingly hard to deal with the problem because of the walls of silence they encounter when seeking to discuss the threat with senior executives.

VeriSign iDefense Labs, a company specializing in cyber threat analysis based in Sterling, Va., reported targeted social engineering attacks against corporations reached new highs in 2008.

The e-mail-based "spear phishing" and "whaling" targeted senior executives and other high-profile individuals.

"The attacks do not use vulnerabilities in the operating system or applications to install malicious code. Often, anti-virus products do not detect the malicious code involved on the day of the attack," VeriSign iDefense Labs said.

The company cited "staggering" victim counts of 15,000 corporate users in 15 months. "Victims include Fortune 500 companies, government agencies, financial institutions and legal firms. In these attacks, the goal is to gain access to corporate banking information, customer databases and other information to facilitate cyber crime," said the company.

Two groups of attackers are believed to have carried out 95 percent of the attacks monitored by iDefense Labs analysts. Each group installs a unique malicious code and operates independently.

One group installs a Browser Helper Object capable of logging SSL encrypted sessions and performing man-in-the-middle attacks on two-factor authentication systems. Another group installs a full version of the Apache Web server on victims' computers.

The attack involves installing a key logger that is capable of performing attacks on authentication systems.

"Whaling is a new form of phishing which threatens to cripple financial institutions from the top down by targeting executives and other high-level employees," Linda Eagle, president of Edcomm Banker Academy in New York, said in the Chicago Tribune.

Industry analysts have identified different templates used in perpetrating fraud, including Internal Revenue Service, Federal Trade Commission, U.S. District Courts, Department of Justice and pro forma invoices.

The Federal Trade Commission advises potential victims, "If you believe you've been scammed, file your complaint at ftc.gov, and then visit the FTC's Identity Theft Web site at www.consumer.gov/idtheft."

FTC warns, "Victims of phishing can become victims of identity theft. While you can't entirely control whether you will become a victim of identity theft, you can take some steps to minimize your risk," it adds.

© 2009 United Press International, Inc. All Rights Reserved. Any reproduction, republication, redistribution and/or modification of any UPI content is expressly prohibited without UPI's prior written consent.

Order reprints
  
Join the conversation
Most Popular Collections
The 84th Academy Awards winners The breakout star of the Oscars The Daytona 500
Radiohead performs in Miami Ice and Snow Festival in China 2012 Governors Dinner
Additional Security Industry Stories
1 of 32
Marilyn Monroe Cupcake Portrait at Madame Tussauds in New York
View Caption
A one-of-a-kind 8 x 4 foot portrait of Marilyn Monroe made from 2,100 bite sized stuffed cupcakes stands in the lobby next to her wax figure on the eve of Marilyn Monroe's 86th birthday at Madame Tussauds in New York City on May 31, 2012. UPI/John Angelillo
fark
After years of collegiate research, scientists conclude men looking for a one-night stand are more...
How to tell if that voice in your head is God. Is it telling you to kill people? Yep, that's God...
Podiatrist accused of begging a 15 year-old teenage babysitter to have sex with him for pay. However,...
40 of the most powerful photographs ever taken. Subby made it to #36 before it got way too dusty...
I fap, you fap, we all fap *fap fap fap*
The "Miami Zombie" case has "spread to various social media outlets and a wave of dark humor has...