The BlackHat community is well known for its ability to quickly communicate new ideas within the population for wreaking havoc on the Internet. Hence it can be a safe assumption that this the new targeted Phishing attack methodology will spread quickly across the Internet.
For individuals that are targeted in these attacks the typical steps to protect yourself from ordinary ID Theft still apply with minor modifications to meet the additional risks imposed with targeted ID theft:
- Be certain your PC's operating system is up-to-date with the latest security patches as well as your Anti Virus and Firewall software.
- No matter how official it looks never click on an embedded URL contained in any email even when it appears to come from your own organization. Manually enter the URL in your browser address bar for your banking and credit card websites.
- Do not fill in forms contained within email including those that may appear to come from within your own organization. Your personal financial information should never be sent by email. Only send your personal financial information via a secure website - verify that the URL contains https:// and that the closed lock appears on the lower right hand side of the browser for a secure website connection.
- Never click on an email attachment unless you know the sender and you were, in fact, expecting to receive the attachment.
- Monitor your banking and credit card accounts online and check for illegitimate transactions regularly.
- Use an online credit monitoring service that offers alerts when there are any changes to your credit report (i.e. new accounts and purchases).
- Register with a credit card security system that requires a password to authorize transactions, such as Verified by Visa or MasterCard SecureCode.
- Do not use the auto- fill facility on websites for credit card and other personal details.
- Use alternative secure online payment systems such as PayPal.
- Finally, common sense is your best defense-- if it looks too good to be true then it probably is.
For the organizations that are the subject of these attacks, beyond the typical best practices for network security, consider the following additional suggestions as additional risk mitigation for targeted ID theft: