London, 26 November 2007 - Cloudmark Inc., the global leader in carrier-grade messaging security, today announced the results of a survey conducted on its behalf by YouGov, which revealed that public confidence in consumer brands is dramatically affected by phishing attacks, with 42% of people surveyed feeling that their trust in a brand would be greatly reduced if they received a phishing email claiming to be from that company. The survey also showed that the majority of consumers feel that the responsibility for protection against phishing attacks lies with themselves, their service provider and the service provider that transported the phishing emails.
Phishing attacks are email scams that attempt to defraud consumers of their personal information, such as bank account details or social security numbers, by pretending to have been sent by a trustworthy entity such as a bank or credit lender.
The survey revealed that:
"Phishing is a highly sophisticated and well orchestrated form of crime. The gangs behind these attacks work to compromise financial information via e-mail scams and then propagate that information into a highly stratified and efficient economy, selling the data on to those who will profit from the accounts," commented Neil Cook, UK technology chief at Cloudmark. "Earlier this year we conducted research into the effect that phishing has on the individual that found consumers were still extremely concerned about falling victim to such a scam. What is interesting to note from these results is that well-known brands are also suffering, with phishing attacks having a detrimental effect on their reputation. This knock-on effect will be particularly worrying for the banks, who rely on a high degree of trust with their customers."
In addition to the YouGov survey, Cloudmark's own research team today released results showing that Natwest Bank was the most phished brand in the UK during October 2007. The research was collected using Cloudmark's user base, which consists of 260 million mailboxes. Cloudmark's research also indicates that across Europe, the majority of unique phishing websites are created using the top level domain associated with the United Kingdom, .uk.
"Not only are we seeing evidence of more .uk phishing URLs, but also a shift in phishing techniques. Vishing is a good example of this where the scammers use cheap VoIP call centre systems as the back end to their phishing attacks, which changes the whole dynamic of trust," commented Cook. "The example we've seen on our database was a message attack that appeared to be a notification from the recipient's bank requesting they ring customer services to deal with a problem. If the recipient makes the call, it gets routed to a cheap VOIP answering system, which may have been set-up on a compromised host. The system captures the user ID and pincode to sell on to the highest bidder, who then has full access to your account. All the while the call seems very genuine. The reassurance of speaking to an individual rather than working online will lead to many instances of consumers falling foul to such threats."
"Whilst awareness to the problem is essential, it is unrealistic to expect businesses to be able to secure themselves fully against such sophisticated criminal activities. The increasingly dynamic and transient nature of the latest threats requires a combination of desktop protection at the client level, and accurate message filtering from ISPs. By including comprehensive phishing detection ISPs will help ensure protection against the latest threats and outbreaks," commented Nigel Stevens, Product Director, THUS plc.
Cloudmark uses an innovative way of stopping spam and phishing attacks, through a combination of intelligent algorithms and a global threat network of trusted reporters in 163 countries. By using this approach, Cloudmark is able to detect and block many attacks and variations automatically, without the need for manual rule writing, as required by other systems. The automation in the system means that the entire Cloudmark network can be protected against new threats within minutes of them first being detected.
For the top 10 tips on how to avoid malware and protect yourself from dangerous online behaviour, please visit www.cloudmark.com/backtoschool/.
All figures, unless otherwise stated, are from YouGov Plc. Total sample size was 1,960 adults. Fieldwork was undertaken between 12th - 14th November 2007. The survey was carried out online. The figures have been weighted and are representative of all GB adults (aged 18+).
THUS plc provides communications solutions to business customers throughout the UK under the THUS and Demon brands. In an industry punctuated by inexperience THUS can draw upon a knowledge base established over more than a decade in the delivery of data, telecoms and Internet services.
Delivering both standard and bespoke solutions THUS endeavours to address customers' existing business needs and works hand in hand with customers to develop new business opportunities. THUS' record in the creation of innovative new services is complemented by an award winning focus on quality and full certification of its internal processes and procedures under the ISO9001 standard.
THUS is listed on the London Stock Exchange. For further information visit http://www.thus.net and http://www.demon.net.
Cloudmark is a trusted leader in intelligent threat protection against known and future attacks, safeguarding 12 percent of the world’s inboxes from wide-scale and targeted email threats. With more than a decade of experience protecting the world’s largest messaging environments, only Cloudmark combines global threat intelligence from a billion subscribers with local behavioral context tracking to deliver instant and predictive defense against data theft and security breaches that result in financial loss and damage to brand and reputation. Cloudmark protects more than 120 tier-one service providers, including Verizon, Swisscom, Comcast, Cox and NTT, as well as tens of thousands of enterprises.