Latest Phishing Victim
Lost ˘24 Million
A young woman is the
latest reported case of
a victim of "phishing"
losing ˘24 million
colones (us$46.500) from
her Banco Nacional
account.
The state bank has been
running a publicity
campaign for the past
two weeks warning
customers to be wary and
avoid becoming a victim
of this type of fraud.
Notwithstanding, in
total there have been 14
cases reported in Costa
Rica of this type of
internet fraud, that can
easily fool a bank
customer in thinking
that they are divulging
confidential banking
information to the bank,
while the information is
actually being used by
thieves to clean out the
persons bank account.
In the case of the young
woman whose identity was
kept confidential,
thieves withdrew money
from account over a
period of six days,
after she responded to
an email supposedly
coming from the Banco
Nacional.
The director of the
Organismo de
Investigación Judicial (OIJ),
Jorge Rojas, said that
they have been warning
people of this type of
fraud and every bank
customer is a potential
victim.
Rojas added that they
are following the trail
left behind by the
internet thieves, who
are trying to appear to
be based in Spain and
operating throughout
Central America,
however, are believed to
be a Costa Rican
organization.
Rojas said that they
will have the group in
their hands in a very
short time.
Phishing is a criminal
activity that attempts
to fraudulently acquire
sensitive information,
such as usernames,
passwords and credit
card details, by
masquerading as a
trustworthy entity.
Online banks are common
targets in addition to
eBay and Paypal
customers.
Phishing is typically
carried out by email
directing users to give
details at a website
The potential victim
clicks on the link
contained in the email
and is taken to a
website that appears to
be exactly the same as
that of the financial
institution of the
victim. URL masking and
other internet
techniques provide
confidence.
Once the information is
entered, the thieves now
have the required login,
passwords and other
vital information to
access the bank account
and withdraw or transfer
funds to another
account.
To avoid being a victim
of phishing, do not
respond to a link
contained in an email.
If you need to verify
that your financial
institution requires an
update of your personal
information - your first
clue that something is
not right - go directly
to the financial
institution's website by
typing in the URL
yourself or from your
saved bookmarks.
Mispelled domain names
are one common practice
by "phishers", that can
also include javascript
contained in the
redirected webpage that
presents the correct URL
on the address bar, but
in fact it is only a
mask, hiding the real
website address of the
phishing page. |
|