Freud and Phishing: The Psychology Behind Internet Scams

38
Freud and Phishing: The Psychology Behind Internet Scams JC Lamkin, CNA, PMP Gypsy Lane Technologies Philadelphia, PA 19144 (215) 843-1039 [email protected] http://www.gltMYpc.com Twitter.com/TechCrusader

description

Freud and Phishing: The Psychology Behind Internet Scams. JC Lamkin, CNA, PMP Gypsy Lane Technologies Philadelphia, PA 19144 (215) 843-1039 [email protected] http://www.gltMYpc.com Twitter.com/TechCrusader. What is Phishing?. Making Money with Phish. 2,000,000 emails are sent - PowerPoint PPT Presentation

Transcript of Freud and Phishing: The Psychology Behind Internet Scams

Page 1: Freud and Phishing: The Psychology Behind Internet Scams

Freud and Phishing:The Psychology Behind Internet

Scams

JC Lamkin, CNA, PMPGypsy Lane Technologies

Philadelphia, PA 19144(215) 843-1039

[email protected]://www.gltMYpc.com

Twitter.com/TechCrusader

Page 2: Freud and Phishing: The Psychology Behind Internet Scams

What is Phishing?

Page 3: Freud and Phishing: The Psychology Behind Internet Scams

Making Money with Phish

2,000,000 emails are sent 5% get to the end user – 100,000 (APWG)

5% click on the phishing link – 5,000 (APWG)

2% enter data into the phishing site – 100 (Gartner)

$1,200 from each person who enters data (FTC)

Our potential reward: $120,000

Page 4: Freud and Phishing: The Psychology Behind Internet Scams

How Much Information?

4.1 million – The number of credit card numbers discovered in ONE phishing blind drop a 4 month period

A typical day Information for 13,677 accounts 3,356 credit cards 255 PayPal account logins 1,038 eBay account logins 93 Bank of America online banking account logins 2,609 Hotmail email account logins

Source: Washingtonpost.com (Security Fix: Brian Krebs)

Page 5: Freud and Phishing: The Psychology Behind Internet Scams

Phish and Spam are Different

Email Characteristics Spam Phishing

How does the email enter your inbox?

Back door – needs a disguise to get past filters

Front door – must look like something users want

What does the email appear to be delivering?

Something you didn’t ask for, but still might want

Information that you should receive

The effectiveness of the email is based on?

What the receiver desiresEstablishing credibility with

the receiver

What’s the most important attribute of the email?

Productcredibility

Brandcredibility

What happens if a user acts on the email offer?

Might actually get the product offered

Lose company, financial, or personal information

What’s the real purpose? Selling Stealing

Page 6: Freud and Phishing: The Psychology Behind Internet Scams

Psychology: Phish ≠ Spam

People treat spam and phish differently

1. Take a Phishing Email and place it in an end users “spam” folder.

10% of the time the user removes the phishing email from the spam folder and places it in their inbox.

2. Take a Phishing Email and place it in an end-users “phish” folder

The user removes the phishing email from the phish folder less than 0.5% of the time.

Page 7: Freud and Phishing: The Psychology Behind Internet Scams

The Tricks of the Trade

Page 8: Freud and Phishing: The Psychology Behind Internet Scams

Fear – You’re Being Naughty

“…payments or donations for obscene or certain sexually oriented goods or services.”

“…your account…limited for: xxxcambabes.com cam shows.”

Page 9: Freud and Phishing: The Psychology Behind Internet Scams

Fear – Account Takeover

“…someone had used your

account to make fake

bids…”

“You must verify …”

“…no choice but to suspend your account.”

Page 10: Freud and Phishing: The Psychology Behind Internet Scams

Fear – Service Deactivation # 1

“…service(s)…will be

deactivated…”

Page 11: Freud and Phishing: The Psychology Behind Internet Scams

Fear – Service Deactivation # 2

“…service(s)…will be

deactivated…”

Page 12: Freud and Phishing: The Psychology Behind Internet Scams

Fear – Service Deactivation # 3

“…service(s)…will be

deactivated…”

Page 13: Freud and Phishing: The Psychology Behind Internet Scams

Fun – eBay Lottery

Page 14: Freud and Phishing: The Psychology Behind Internet Scams

Fun – eBay Conference

Page 15: Freud and Phishing: The Psychology Behind Internet Scams

Fun – eBay Anniversary

LEGIT

Page 16: Freud and Phishing: The Psychology Behind Internet Scams

Fun – Take a Survey

Page 17: Freud and Phishing: The Psychology Behind Internet Scams

Fun – Take a Survey

LEGIT

Page 18: Freud and Phishing: The Psychology Behind Internet Scams

Confusion – Account Change

Page 19: Freud and Phishing: The Psychology Behind Internet Scams

Confusion – Did I Buy This?

Page 20: Freud and Phishing: The Psychology Behind Internet Scams

Assistance – My Refund?

Page 21: Freud and Phishing: The Psychology Behind Internet Scams

Assistance – We’re Here to Help

Page 22: Freud and Phishing: The Psychology Behind Internet Scams

Assistance –Fraud Detection

Page 23: Freud and Phishing: The Psychology Behind Internet Scams

Assistance – Buy Safely

LEGIT

Page 24: Freud and Phishing: The Psychology Behind Internet Scams

Poll-time Possibilities

LEGIT??...Only for Poll Workers

Page 25: Freud and Phishing: The Psychology Behind Internet Scams

Compassion – No Scruples

Page 26: Freud and Phishing: The Psychology Behind Internet Scams

Other Email Tricks

Multi-Stage Attacks Email 1 – “We’ll be updating all our accounts this

weekend” Email 2 – “We discovered a problem with your

account” Multi-channel Attacks

Email contains both Phishing URL Phishing phone number (typically VOIP based)

Page 27: Freud and Phishing: The Psychology Behind Internet Scams

The Domain Name Game

citibank-validate.info earthlink-reactivation.net services-bankofamerica.com sales-aol.net secure-ebay.com msn-reactivation.net secure-usbank.info service-visa.net verification-e-gold.com customer-verification.com banking-account-renewal.com

Phishers SSL Certificate

>> citibanhk.de <<

Duplicated Registrar Info

>> credltlyonaisse.com <<

Registering a Cyrillic “a”

>> paypal.com <<

Hall of FameHall of Fame

Page 28: Freud and Phishing: The Psychology Behind Internet Scams

Web Site Tricks

We arrive at the website. Is something phishy?

Page 29: Freud and Phishing: The Psychology Behind Internet Scams

Web Site Tricks

There is no address bar!

Page 30: Freud and Phishing: The Psychology Behind Internet Scams

Web Site Tricks

Now there’s two!

Page 31: Freud and Phishing: The Psychology Behind Internet Scams

More Web Site Tricks

Search Engine Listings Common URL misspellings

www.mailfrontier.com

www.mailfronteir.com

www.malefrontier.com

Page 32: Freud and Phishing: The Psychology Behind Internet Scams

Tips on Protecting Yourself from Phishing

Page 33: Freud and Phishing: The Psychology Behind Internet Scams

Protect Yourself

Know your senders Is this someone I do business with? Is this something I was told I’d receive? Look for other ways to respond

Page 34: Freud and Phishing: The Psychology Behind Internet Scams

Protect Yourself

Stay on guard Look for clues – improve your PhishingIQ Don’t be afraid to ask Know how your system is updated Protect your system Check your records Check your sources, snopes.com

Page 35: Freud and Phishing: The Psychology Behind Internet Scams

Not Just a Consumer Issue

Operations Microsoft Updates, RSA SecurID

Corporate credit cards American Express, Visa, MasterCard

Purchasing and Payments Ebay, PayPal

Network Services Verizon, Earthlink

Web Services DNS Name Registration, Hosting Companies

Page 36: Freud and Phishing: The Psychology Behind Internet Scams

Protect Your Brand

Cut-and-Paste links, minimize links Use personal information where possible Provide non-email ways to verify Use standard company domain names Identify your partners Set and follow standard communication

practices

Page 37: Freud and Phishing: The Psychology Behind Internet Scams

Phishing - Don’t Take the Bait

Preemptive Phishing is different than spam – think Virus

Technology Its more than a consumer issue Multi-faceted solution – No silver bullet

Psychology Educate your customers/employees/yourself Improve their PhishingIQ Email is still Good! Really it is!

Page 38: Freud and Phishing: The Psychology Behind Internet Scams

JC Lamkin, CNA, PMPGypsy Lane Technologies

Philadelphia, PA 19144(215) 843-1039

[email protected]://www.gltMYpc.com

Twitter.com/TechCrusaderSpecial thanks to infosecurity.com

Freud and Phishing:The Psychology Behind

Internet Scams