Spamfo

Dec/04

6

When email attacks get personal

Phishing attacks or online identity theft has established itself as the principal threat of 2004, and may signal the beginning of a wave of email security attacks targeted specifically at individual or small groups of companies.This puts business firmly on the front line in the fight against online attacks, according to the annual MessageLabs Intelligence Email Security Report for 2004 (*) released today by MessageLabs, the leading provider of managed email security services to business worldwide.

 


In September 2003 the company intercepted 279 phishing emails (containing a URL to a fraudulent website), by September 2004 that figure had significantly risen to over two million. During the course of 2004, MessageLabs intercepted over 18 million phishing-related emails.


 


The perpetrators of phishing attacks have also developed new techniques in order to increase their chances of success. Recently, phishing emails have been designed to capture online banking details automatically when a user opens the email, rather than when the user clicks on the URL link. Phishers have also attempted to dupe unsuspecting users into becoming middlemen for money laundering operations, by offering employment opportunities with legitimate organisations.


 


Spam and virus ratios have also risen since the end of 2003. In 2004 the virus infection ratio was 1 in 16, in comparison to 2003 when it was 1 in 33. The most widespread outbreak of the year was W32/MyDoom.A, which occurred in January. In addition, the percentage of email identified as spam in 2004 is 73 percent whereas in 2003 it was 40 percent.


 


As well as the rise in phishing, virus and spam volumes, MessageLabs also witnessed tailored malicious activity ranging from Denial of Service (DoS) attacks targeted at blackmailing online gaming sites through to threats that send out child pornography in the name of a particular reputable organisation.


 


There is also evidence to suggest that Trojans and other malicious code have been developed during 2004 specifically to compromise particular organisations. MessageLabs expects this trend to continue.


 


Mark Sunner, Chief Technology Officeat MessageLabscommented:  “Email security attacks remain unabated in their persistence and ferocity. The major development of the year has undoubtedly been the emergence of phishing – in just twelve months it has firmly established itself as a threat to any organisation or individual conducting business online.


 


“We believe that the singling out of certain companies to be the victim of phishing attacks could signal the beginning of a wider trend. Already particular businesses are threatened and blackmailed, indicating a shift from the random, scattergun approach, to customised attacks designed to take advantage of the perceived weaknesses of some businesses.”


 


As well as threats from targeted fraud, MessageLabs believes that the other key issue facing companies in the coming months will be pressure to comply with regulation. Already in place in a number of countries, laws surrounding financial reporting and disclosure of information require companies to have policies for monitoring, securing and storing all business transactions: including email and instant messaging.


 


Mr Sunner added: “Compliance is already a big issue, and many firms have yet to grasp the impact it will have on the administration, management and security of email. Failure to comply could not only result in potential legal problems, but threaten a company’s credibility and reputation as well. 


 


“It is vital to ruthlessly evaluate email management solutions, and consider current and potential future regulatory requirements when deciding how best to ensure compliance.”



 


* The MessageLabs Intelligence Annual Email Management and Security Report 2004.  For a copy, visit www.messagelabs.com/intelligence/2004report


 


The Statistical Monthly Breakdown for 2004:


 
















































































2004 Month


Virus


Spam


Phishing


 


 


 


 


January


1 in 129 (0.1%)


1 in 1.6 (63%)


337,050


February


1 in 19 (5.1%)


1 in 1.7 (60%)


259,014


March


1 in 43 (2.3%)


1 in 1.9 (53%)


215,643


April


1 in 10 (9.5%)


1 in 1.5 (67.6%)


205,953


May


1 in 10 (9.1%)


1 in 1.3 (76%)


247,027


June


1 in 10 (9.3%)


1 in 1.2 (86.3%)


264,354


July


1 in 14 (7.3%)


1 in 1.1 (94.5%)


2,493,734


August


1 in 15 (6.9%)


1 in 1.2 (84.2%)


3,015,685


September


1 in 21 (4.8%)


1 in 1.4 (72.1%)


2,098,012


October


1 in 32 (3.1%)


1 in 1.3 (76.8%)


4,838,962


November


1 in 33 (3%)


1 in 1.4 (73.8%)


4,522,495


 


 


 


 


TOTAL


1 in 16 (6.1%)


1 in 4 (73.2%)


18,497,929


 


About MessageLabs


MessageLabs is the leading provider of managed email security services to businesses based on market share, according to a Yankee Group Security Solutions & Services Report, February 2004.  The company offers industry-leading managed Anti-Virus, Anti-Spam, Image Control and Content Control services to more than 9,000 businesses around the world to combat email threats before they reach corporate networks and without the need for additional hardware or software.  Powered by a global network of data centres spanning four continents, MessageLabs scans millions of emails each day on behalf of clients such as The British Government, The Bank of New York, Bertelsmann, CSC, Diageo, Random House, SC Johnson and StorageTek.  The service is also available through more than 600 channel partners, including BT, Cable & Wireless, CSC, IBM, MCI and Unisys.  For more information on MessageLabs, please visit www.messagelabs.com.

No tags

Comments are closed.

<<

>>