<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Teach a Man to Phish&#8230;</title>
	<atom:link href="http://krebsonsecurity.com/2010/05/teach-a-man-to-phish/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2010/05/teach-a-man-to-phish/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Wed, 23 May 2012 21:31:36 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: AlphaCentauri</title>
		<link>http://krebsonsecurity.com/2010/05/teach-a-man-to-phish/comment-page-1/#comment-5998</link>
		<dc:creator>AlphaCentauri</dc:creator>
		<pubDate>Sat, 22 May 2010 02:51:52 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3058#comment-5998</guid>
		<description>It may not all be for personal use. He may be raising money for a military or terrorist organization within Nigeria (where there are frequent attacks against petroleum industry targets) or in neighboring countries.  Being a warlord and feeding an army isn&#039;t cheap.

Also, do we know for certain he&#039;s in Nigeria himself, rather than using a proxy located there?</description>
		<content:encoded><![CDATA[<p>It may not all be for personal use. He may be raising money for a military or terrorist organization within Nigeria (where there are frequent attacks against petroleum industry targets) or in neighboring countries.  Being a warlord and feeding an army isn&#8217;t cheap.</p>
<p>Also, do we know for certain he&#8217;s in Nigeria himself, rather than using a proxy located there?</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-5998" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('5998', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-5998-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-5998" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('5998', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-5998-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Arctic Hare</title>
		<link>http://krebsonsecurity.com/2010/05/teach-a-man-to-phish/comment-page-1/#comment-5907</link>
		<dc:creator>Arctic Hare</dc:creator>
		<pubDate>Tue, 18 May 2010 01:45:01 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3058#comment-5907</guid>
		<description>@BrianKrebs

You are hard to follow here. I agree that the median is a better estimate than the average of what a random small-timer makes. No dispute about that. But if we want to use Hong&#039;s estimate of the median we need to know his sample is unbiased. The fact that it predicts 39 million victims/yr suggests that it is not.

Hong says it&#039;s a longtail phenomenon; but his analysis is based on 1285 sites, which is less than 1% of the sites that APWG reports for 6 mos. How do we know that this 1% is representative? If not, then this median is not a good estimate of the Nigerian guy&#039;s return.</description>
		<content:encoded><![CDATA[<div style="background-color:#FFF0F5 !important"><p>@BrianKrebs</p>
<p>You are hard to follow here. I agree that the median is a better estimate than the average of what a random small-timer makes. No dispute about that. But if we want to use Hong&#8217;s estimate of the median we need to know his sample is unbiased. The fact that it predicts 39 million victims/yr suggests that it is not.</p>
<p>Hong says it&#8217;s a longtail phenomenon; but his analysis is based on 1285 sites, which is less than 1% of the sites that APWG reports for 6 mos. How do we know that this 1% is representative? If not, then this median is not a good estimate of the Nigerian guy&#8217;s return.</p>
</div><div class="CommentRating">Hot debate. What do you think? <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-5907" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('5907', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-5907-up" style="font-size:14px; color:#009933;">4</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-5907" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('5907', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-5907-down" style="font-size:14px; color:#990033;">4</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Rick Zeman</title>
		<link>http://krebsonsecurity.com/2010/05/teach-a-man-to-phish/comment-page-1/#comment-5906</link>
		<dc:creator>Rick Zeman</dc:creator>
		<pubDate>Tue, 18 May 2010 01:35:51 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3058#comment-5906</guid>
		<description>Well, hits don&#039;t necessarily extrapolate to potential victims.  I follow phishing links all the time (on a Mac, of course), usually to just check out its sophistication, or to just fill in the forms with few choice obscenities or three.  :-)</description>
		<content:encoded><![CDATA[<div style="background-color:#FFFFCC !important"><p>Well, hits don&#8217;t necessarily extrapolate to potential victims.  I follow phishing links all the time (on a Mac, of course), usually to just check out its sophistication, or to just fill in the forms with few choice obscenities or three.  <img src='http://krebsonsecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
</div><div class="CommentRating">Well-loved. Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-5906" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('5906', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-5906-up" style="font-size:14px; color:#009933;">8</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-5906" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('5906', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-5906-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: BrianKrebs</title>
		<link>http://krebsonsecurity.com/2010/05/teach-a-man-to-phish/comment-page-1/#comment-5905</link>
		<dc:creator>BrianKrebs</dc:creator>
		<pubDate>Tue, 18 May 2010 01:17:30 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3058#comment-5905</guid>
		<description>The bulk of the phishing scams perpetrated in the last year and measured by the APWG appear to have been the work of a single organized crime gang, and account for 2/3 of the phishing scams out there. 

I don&#039;t think you can put the average phisher&#039;s attacks in the same category of sophistication as these organized criminals.

Also, Hong told me and indeed I reported that most of the phishing attacks he tracked had very few victims, between 2 and 7 victims per scam. That&#039;s why stating what the mean and median are in any kind of analysis like that can be so important, because they can be radically different.

Read the next paragraph in the story: 

&quot;That means there are some really “successful” phishing attacks that many people click on, probably either because a huge number of spam e-mails advertising that fake site were sent, or because the phishing e-mails were particularly compelling. However, the majority of phishing campaigns appear to be quite unsuccessful, in that they don’t hook a lot of people, Hong said.&quot;</description>
		<content:encoded><![CDATA[<div style="background-color:#FFFFCC !important"><p>The bulk of the phishing scams perpetrated in the last year and measured by the APWG appear to have been the work of a single organized crime gang, and account for 2/3 of the phishing scams out there. </p>
<p>I don&#8217;t think you can put the average phisher&#8217;s attacks in the same category of sophistication as these organized criminals.</p>
<p>Also, Hong told me and indeed I reported that most of the phishing attacks he tracked had very few victims, between 2 and 7 victims per scam. That&#8217;s why stating what the mean and median are in any kind of analysis like that can be so important, because they can be radically different.</p>
<p>Read the next paragraph in the story: </p>
<p>&#8220;That means there are some really “successful” phishing attacks that many people click on, probably either because a huge number of spam e-mails advertising that fake site were sent, or because the phishing e-mails were particularly compelling. However, the majority of phishing campaigns appear to be quite unsuccessful, in that they don’t hook a lot of people, Hong said.&#8221;</p>
</div><div class="CommentRating">Well-loved. Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-5905" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('5905', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-5905-up" style="font-size:14px; color:#009933;">6</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-5905" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('5905', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-5905-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Arctic Hare</title>
		<link>http://krebsonsecurity.com/2010/05/teach-a-man-to-phish/comment-page-1/#comment-5904</link>
		<dc:creator>Arctic Hare</dc:creator>
		<pubDate>Tue, 18 May 2010 01:07:06 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3058#comment-5904</guid>
		<description>@BrianKrebs
OK, but then there are sanity check problems. Hong finds an average, not median, of 156 hits per site. The APWG found 126k sites for the second half of 2009: http://www.apwg.org/reports/APWG_GlobalPhishingSurvey_2H2009.pdf

So that gives 156 x 126k x 2 = 39 million victims/yr and at $500 each phishing is a $19.6 billion/yr business.

Unless we believe that there were 39 million victims last year either the APWG numbers are way off, or there&#039;s a large bias in what Hong looked at.</description>
		<content:encoded><![CDATA[<p>@BrianKrebs<br />
OK, but then there are sanity check problems. Hong finds an average, not median, of 156 hits per site. The APWG found 126k sites for the second half of 2009: <a href="http://www.apwg.org/reports/APWG_GlobalPhishingSurvey_2H2009.pdf" rel="nofollow">http://www.apwg.org/reports/APWG_GlobalPhishingSurvey_2H2009.pdf</a></p>
<p>So that gives 156 x 126k x 2 = 39 million victims/yr and at $500 each phishing is a $19.6 billion/yr business.</p>
<p>Unless we believe that there were 39 million victims last year either the APWG numbers are way off, or there&#8217;s a large bias in what Hong looked at.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-5904" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('5904', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-5904-up" style="font-size:14px; color:#009933;">4</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-5904" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('5904', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-5904-down" style="font-size:14px; color:#990033;">3</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: KFritz</title>
		<link>http://krebsonsecurity.com/2010/05/teach-a-man-to-phish/comment-page-1/#comment-5902</link>
		<dc:creator>KFritz</dc:creator>
		<pubDate>Mon, 17 May 2010 20:57:19 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3058#comment-5902</guid>
		<description>My favorite graphic, at least since Security Fix became KrebsonSecurity! Love the treble hook.</description>
		<content:encoded><![CDATA[<div style="background-color:#FFF0F5 !important"><p>My favorite graphic, at least since Security Fix became KrebsonSecurity! Love the treble hook.</p>
</div><div class="CommentRating">Hot debate. What do you think? <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-5902" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('5902', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-5902-up" style="font-size:14px; color:#009933;">6</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-5902" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('5902', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-5902-down" style="font-size:14px; color:#990033;">3</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: KFritz</title>
		<link>http://krebsonsecurity.com/2010/05/teach-a-man-to-phish/comment-page-1/#comment-5901</link>
		<dc:creator>KFritz</dc:creator>
		<pubDate>Mon, 17 May 2010 20:55:04 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3058#comment-5901</guid>
		<description>Agreed. OP&#039;s skepticism seems automatic, ad hominem.
That said, 1)Phishlabs concept is excellent, 2)they exercised due diligence reporting their work to officialdom and enterprise,3) but they&#039;re not criminologists or financial analysts, so the monetary estimates can&#039;t be considered gospel.
Also, whether individual or group, it&#039;s plainly a day job for person/people w/ regular work habits.</description>
		<content:encoded><![CDATA[<div style="background-color:#FFFFCC !important"><p>Agreed. OP&#8217;s skepticism seems automatic, ad hominem.<br />
That said, 1)Phishlabs concept is excellent, 2)they exercised due diligence reporting their work to officialdom and enterprise,3) but they&#8217;re not criminologists or financial analysts, so the monetary estimates can&#8217;t be considered gospel.<br />
Also, whether individual or group, it&#8217;s plainly a day job for person/people w/ regular work habits.</p>
</div><div class="CommentRating">Well-loved. Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-5901" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('5901', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-5901-up" style="font-size:14px; color:#009933;">6</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-5901" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('5901', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-5901-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Brandon</title>
		<link>http://krebsonsecurity.com/2010/05/teach-a-man-to-phish/comment-page-1/#comment-5900</link>
		<dc:creator>Brandon</dc:creator>
		<pubDate>Mon, 17 May 2010 19:41:40 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3058#comment-5900</guid>
		<description>Something to keep in mind, while its one guy in Nigeria, there is nothing to show he is the one keeping the money. He might be a very busy person who is good at creating fishing sites but he may only be getting 1%-2% of the total income, if that. He very well could be part of a larger crime syndicate.

I agree with you that its very doubtful he is getting all of the proceeds from his work. Even half would make him extremely noticeable by the local governments and authorities.  

Its hard to make an educated guess of the structure beyond the stats gathered in this study, I still find the study interesting and informative but its hard to say beyond what this person does, what sort of organization is behind this, if this truly a one guy operation and how much he actually gets from the proceeds.</description>
		<content:encoded><![CDATA[<div style="background-color:#FFFFCC !important"><p>Something to keep in mind, while its one guy in Nigeria, there is nothing to show he is the one keeping the money. He might be a very busy person who is good at creating fishing sites but he may only be getting 1%-2% of the total income, if that. He very well could be part of a larger crime syndicate.</p>
<p>I agree with you that its very doubtful he is getting all of the proceeds from his work. Even half would make him extremely noticeable by the local governments and authorities.  </p>
<p>Its hard to make an educated guess of the structure beyond the stats gathered in this study, I still find the study interesting and informative but its hard to say beyond what this person does, what sort of organization is behind this, if this truly a one guy operation and how much he actually gets from the proceeds.</p>
</div><div class="CommentRating">Well-loved. Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-5900" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('5900', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-5900-up" style="font-size:14px; color:#009933;">12</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-5900" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('5900', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-5900-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: QQ</title>
		<link>http://krebsonsecurity.com/2010/05/teach-a-man-to-phish/comment-page-1/#comment-5899</link>
		<dc:creator>QQ</dc:creator>
		<pubDate>Mon, 17 May 2010 19:16:31 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3058#comment-5899</guid>
		<description>If cybercrime did not pay people would not commit it.

I find it truly hard to believe that 1 guy is making 4 million US dollars a year while living in Nigeria. 4M$ in Nigeria is probably equal to 40-50M in USA, Having this sum in such a country means you can forget all your financial worries for good. Why keep going for 15 months? 

Statistics often lie and do not represent the reality, There are very few people (if any at all..) that made millions with spam,fake AVs, botnets,trojans or for this case phishing.

It is likely possible to make a living with the income of being full time cybercriminal in a big cybercrime gang, but 1 guy in Nigeria, doesn&#039;t sound true to me.</description>
		<content:encoded><![CDATA[<div style="background-color:#FFF0F5 !important"><p>If cybercrime did not pay people would not commit it.</p>
<p>I find it truly hard to believe that 1 guy is making 4 million US dollars a year while living in Nigeria. 4M$ in Nigeria is probably equal to 40-50M in USA, Having this sum in such a country means you can forget all your financial worries for good. Why keep going for 15 months? </p>
<p>Statistics often lie and do not represent the reality, There are very few people (if any at all..) that made millions with spam,fake AVs, botnets,trojans or for this case phishing.</p>
<p>It is likely possible to make a living with the income of being full time cybercriminal in a big cybercrime gang, but 1 guy in Nigeria, doesn&#8217;t sound true to me.</p>
</div><div class="CommentRating">Hot debate. What do you think? <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-5899" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('5899', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-5899-up" style="font-size:14px; color:#009933;">8</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-5899" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('5899', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-5899-down" style="font-size:14px; color:#990033;">5</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: John LaCour</title>
		<link>http://krebsonsecurity.com/2010/05/teach-a-man-to-phish/comment-page-1/#comment-5898</link>
		<dc:creator>John LaCour</dc:creator>
		<pubDate>Mon, 17 May 2010 18:25:57 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3058#comment-5898</guid>
		<description>@InfoSec Pro -
When we first noticed this fraudster, PhishLabs reported the criminal&#039;s email address and name to the federal cyber-police in the country containing most of the affected banks.   Unfortunately, we did not receive a response.    

One of the conclusions of our study is that phishing attacks, with some exceptions such as those related to the Avalanche botnet, tend to be treated as unique events when in fact an attack is often perpetrated by one of a small number of prolific phishers.    The result is that phishing incidents are often not pursued by law enforcement (and not reported to law enforcement by the affected organization).

Regarding notification of hacked site owners and shutting down phishing sites, we did report many of them to the affected site owner or service provider, but resource constraints dictate that we focus on the  anti-phishing, anti-malware and other cyber-defense services we provide to our clients.    Also, most of the attacks were independently discovered and pursued for shutdown anyway.     That said, we do believe in doing as much as we can to help secure the Internet.   Over the course of our history we have shutdown thousands of scam sites for free and recovered and reported literally millions of stolen banking credentials and compromised email accounts to the affected companies - also without charge.</description>
		<content:encoded><![CDATA[<div style="background-color:#FFFFCC !important"><p>@InfoSec Pro -<br />
When we first noticed this fraudster, PhishLabs reported the criminal&#8217;s email address and name to the federal cyber-police in the country containing most of the affected banks.   Unfortunately, we did not receive a response.    </p>
<p>One of the conclusions of our study is that phishing attacks, with some exceptions such as those related to the Avalanche botnet, tend to be treated as unique events when in fact an attack is often perpetrated by one of a small number of prolific phishers.    The result is that phishing incidents are often not pursued by law enforcement (and not reported to law enforcement by the affected organization).</p>
<p>Regarding notification of hacked site owners and shutting down phishing sites, we did report many of them to the affected site owner or service provider, but resource constraints dictate that we focus on the  anti-phishing, anti-malware and other cyber-defense services we provide to our clients.    Also, most of the attacks were independently discovered and pursued for shutdown anyway.     That said, we do believe in doing as much as we can to help secure the Internet.   Over the course of our history we have shutdown thousands of scam sites for free and recovered and reported literally millions of stolen banking credentials and compromised email accounts to the affected companies &#8211; also without charge.</p>
</div><div class="CommentRating">Well-loved. Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-5898" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('5898', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-5898-up" style="font-size:14px; color:#009933;">38</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-5898" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('5898', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-5898-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 7/22 queries in 0.004 seconds using memcached
Object Caching 939/953 objects using memcached

Served from: krebsonsecurity.com @ 2012-05-23 18:38:02 -->
