I am writing this letter after a gap of two months so I must first
apologize to my Anti-phishing group members. These two months have kept
us on our feet with an unprecedented rise in Phishing scams across
various geographies and victim companies. As I write this the first
phishing scam in India has claimed ICICI Bank as its victim and Japan
has arrested its first phisher.
We have now added a news section to our website www.gralicwrap.com with
an automated RSS Feed about phishing scams and the like. A Live Chat
Support software has been added for people who are having Technical
difficulties with our software. Please send us your suggestions and
comments about what you think about these new features.
We have been mentioned in a news report in a Switzerland newspaper 'Le
Matin'. You can see this article here:
http://www.lematin.ch/nwmatinhome/nwmatintendances/le_matin0/freeware...
Well getting down to brass tacks, the phishing database which we have
been updating 24/7, has now got over 2000 uniqe phishing entries. At
the last count (as on 12th of February 2006) the Gralicwrap Fraud Alert
tally is as follows:
AF Bank - 4
Affinity Plus FCU - 1
AIB Bank - 1
Amazon - 85
AOL - 29
Apple - 1
Bancorp South - 7
Bank of America - 45
Bank of Montreal - 1
Bank of Oklahoma - 6
Bank of the West - 1
Barclays Bank - 131
Capitol One Bank - 14
Central Bank - 2
Chase Bank - 209
Citibank - 9
City County Credit Union - 1
Colonial Bank - 5
Comcast - 1
Commercial Federal Bank - 14
Commonwealth Bank - 1
Credit Union - 54
Credit Union of Texas - 6
Deutsche Bank - 14
Dresdner Bank - 6
Ebay - 415
F&M Bank - 2
First Chatham Bank - 1
First Credit Union - 9
First Merit Bank -1
First Tennessee Bank - 11
Flagstar Bank - 13
Fulton Bank - 2
Halifax Bank - 36
HSBC Bank - 14
IRS - 2
Johnson Bank - 1
Key Bank - 1
Lloys TSB Bank - 13
M&T Bank - 1
Markle Bank - 2
Mastercard -1
MBNA Bank - 7
Merill Lynch - 1
MSN - 1
National Credit Union - 6
Natwest Bank - 17
Navy FCU - 1
Northfork Bank - 2
North Jersey FCU - 1
Ohio Savings Bank - 1
Paypal - 698
People PC - 2
Postbank - 2
RBC Centura Bank - 2
Regions Bank - 1
Royal Bank of Canada - 12
SCE Federal Credit Union - 1
Scotiabank - 1
SouthTrust Bank - 8
Southwest Airlines - 1
Stormpay - 1
Teachers FCU - 2
Tennessee Teachers Bank - 1
Tinker FCU - 1
UK Banks Association - 1
University of Colorado FCU - 1
US Bank - 1
USAA - 8
Visa - 2
Visions FCU - 1
Volksbanken - 1
Wainwright Bank & Trust - 1
Washington Telephone FCU - 1
Wells Fargo Bank - 88
Western Federal Credit Union - 3
Western Union - 6
As you can see above Paypal and Ebay combined still account for over
50% of all phishing scams in our database. Both Ebay & Chase Bank has
seen an alarming increase over the last 2 months. We have several new
entries in the list which is a very disturbing trend. IRS (Internal
Revenue Service) is now on the infamous list of phishing victims.
We had 42 phishing victim companies in our last post dated 13th
December. We now have 77 of them. As phishing attacks become more
broadbased, fighting them will not only be more difficult but also more
expensive.
First reports of the new Microsoft Vista mention new security features
integrated into their operating system and browser. Eric Lai of
Computerworld says in his report:
"Vista will also have added antiphishing capabilities. For instance,
suspicious Web sites -- such as those whose addresses begin with a
string of numbers -- will trigger a "suspicious Web site" message.
While other sites that have been reported by Vista users as definite
phishing sites will trigger a red warning and attempt to prevent users
from visiting that site. Users can also allow Vista to automatically
send information about trojans and spyware infecting their system in a
way that does not violate user privacy."
This is welcome news for users. Microsoft has also released its
Internet Explorer 7 beta version with anti-phishing security buit in to
the browser itself. This once again goes to show that global
corporations are getting serious in their commitment towards fighting
Internet fraud which threatens the very fabric of Ecommerce.
A lot of members have asked me as to why we are not members of the
Anti-phishing Working Group. Well, we would love to become members of
the APWG but it is simply not affordable at $7500 to join as a
Sponsoring Vendor or at $5000 as a Corporate member. (Joining as an
Individual member would not be beneficial as it would not give us
access to the phishing scams database or daily phishing updates).
As you are aware, Gralicwrap is a free anti-phishing software tool and
we have no Income source, Corporate Sponsorship nor the resources to
pay that kind of money for APWG membership. In fact I have personally
invested a substantial amount of capital to start Gralicwrap and
continue to invest money to run the Gralicwrap Anti-phishing service
gratis. I have written to the APWG chairman requesting him to waive
their fees for non-profit websites / organisations like ours but that
has elicited no response so far. (It is my firm opinion that essential
services like these should hence be controlled by the Government and be
not-for-profit and freely accessible to the people). But thats just my
two cents...
Well, I would like to end this long-winding post here. Thank you fpor
reading it. I also take this opportunity to thank all the Gralicwrap
contributors who continue to submit phishing scams to our database on a
daily basis. Without you, this service would not be a success.
Thank you,
Ameet Arurkar
Managing Director
Intelisys India Ltd
Gralicwrap.com
www.gralicwrap.com