<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.0.4" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>PhishTank Blog</title>
	<link>http://www.phishtank.com/blog</link>
	<description>A blog about and from PhishTank, a collaborative clearinghouse for data about phishing.</description>
	<pubDate>Mon, 05 May 2008 22:47:02 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.4</generator>
	<language>en</language>
			<item>
		<title>PhishTank April &#8216;08 stats. Learn to protect yourself, your company.</title>
		<link>http://www.phishtank.com/blog/2008/05/05/phishtank-april-08-stats-are-live/</link>
		<comments>http://www.phishtank.com/blog/2008/05/05/phishtank-april-08-stats-are-live/#comments</comments>
		<pubDate>Mon, 05 May 2008 22:47:02 +0000</pubDate>
		<dc:creator>Allison</dc:creator>
		
	<category>PhishTank</category>
		<guid isPermaLink="false">http://www.phishtank.com/blog/2008/05/05/phishtank-april-08-stats-are-live/</guid>
		<description><![CDATA[April stats and new Google AdWords phishing scam.]]></description>
			<content:encoded><![CDATA[<p>We just posted PhishTank <a href="http://www.phishtank.com/stats/2008/04/">statistics</a> for April 2008. No major surprises: The United States is, for the thirteenth straight month, hosting more phishes than any other country; A group of large banks, eBay, and PayPal round out the top most spoofed brands; And the PhishTank community of submitters and verifiers continues to have an impressively high accuracy rate.</p>
<p>The <a href="http://news.google.com/news?hl=en&#038;tab=wn&#038;ned=us&#038;q=phishing">headlines</a> tell us the phishers are not giving up. Seemingly every week we see reports of a new type of phishing scam. This week it&#8217;s Google AdWords phishing, where AdWords account holders are sent emails alerting them their account needs updating. The account holder logs into the spoofed AdWords interface and hands over their credit card information. </p>
<p>The AdWords phishing scam is interesting to me largely because, in lots of cases, it&#8217;s targeting businesses. People understand identity theft. But what happens when a business&#8217;s identity is stolen? There&#8217;s no easier or more efficient avenue to get reimbursed for a business than for an individual. Basically, whether you represent yourself or your company, you have to go to your credit card company and beg for forgiveness. (Whether or not it should be the banks &#8212; some of the most commonly spoofed brands &#8212; that are responsible for reimbursing money stolen through phishing is part of a separate debate.)</p>
<p>And the spoofed AdWords account interfaces, at least the <a href="http://www.phishtank.com/phish_detail.php?phish_id=441259">ones</a> I&#8217;ve seen, are <em>good</em>. I can easily understand how the marketing person tasked with managing AdWords for their company could be fooled. I know plenty of small and mid-size companies that rely on online advertising to drive traffic to their site, and see huge dents in revenue when something goes wrong and the traffic doesn&#8217;t come. That marketing person has plenty of incentive to make sure their account information isn&#8217;t wrong and nothing is preventing potential customers from seeing their ads.</p>
<p>Experts repeat the same warning about AdWords phishing that we&#8217;ve all heard about phishing in general for years: Educate yourself about phishing and look skeptically at URLs. Remember that as a general rule, you won&#8217;t be warned via e-mail that your account has been compromised, so if you are ever encouraged via e-mail to login to an account and update information, proceed with caution and look closely at the URL you&#8217;re encouraged to click. </p>
<p>Take for example, one of the AdWords phishes someone submitted to PhishTank. See the &#8220;d0l9i.cn&#8221; in the middle of the URL? If you open a new window and load http://adwords.google.com/select/login, you&#8217;ll see the real site&#8217;s URL doesn&#8217;t include that series of characters. That should be a red flag.</p>
<p><strong>[NOTE: This is a known, verified phishing site. We recommend you do NOT visit it.] </strong></p>
<div style="float:left;margin: 0 10px 10px 0;"><img src="http://www.phishtank.com/images/adwords_phish.gif" width="441" height="278" /></div>
<p>OpenDNS users and users of other services leveraging PhishTank data &#8212; McAfee, Opera, Yahoo! Mail, Kaspersky Labs, to name a few &#8212; have an extra line of defense when it comes to phishing &#8212; they benefit from PhishTank and the wisdom of the community. But it&#8217;s abolsutely a good idea to learn to look for inconsistencies in URLs and think twice before providing sensitive information online, whether it&#8217;s your own or your company&#8217;s.<br />
<div style="clear:both;"></div>
]]></content:encoded>
			<wfw:commentRSS>http://www.phishtank.com/blog/2008/05/05/phishtank-april-08-stats-are-live/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>What motivates you to help with PhishTank?</title>
		<link>http://www.phishtank.com/blog/2007/12/19/cmu-survey/</link>
		<comments>http://www.phishtank.com/blog/2007/12/19/cmu-survey/#comments</comments>
		<pubDate>Wed, 19 Dec 2007 20:27:53 +0000</pubDate>
		<dc:creator>John Roberts</dc:creator>
		
	<category>PhishTank</category>
	<category>Members</category>
	<category>Community</category>
		<guid isPermaLink="false">http://www.phishtank.com/blog/2007/12/19/cmu-survey/</guid>
		<description><![CDATA[Help some Carnegie Mellon University researchers by completing a brief survey of anti-phishing volunteers.]]></description>
			<content:encoded><![CDATA[<p>Whatever your motivation, we salute you.</p>
<p>Some Carnegie Mellon University researchers would like to know more, as part of ongoing work at their <a href="http://www.cylab.cmu.edu/">CyLab</a> on phishing in general.</p>
<blockquote><p>We&#8217;re conducting a survey of anti-phishing volunteers, as part of ongoing<br />
research in Human Computer Interaction regarding phishing. The survey will ask<br />
you questions regarding how volunteers spend their time, motivations, and what<br />
tools are important for the task. The survey should take 5-10 minutes to<br />
complete.</p>
<p>Those who are willing may volunteer at the end of a survey to be interviewed.<br />
Interviews will be held over the telephone, and we will offer a $10 gift certificate<br />
as a token of our appreciation for those who participate in the interview. We<br />
expect interviews will take from 30 minutes to an hour.</p>
<p>All personal information collected in the course of this research will be<br />
anonymized before publication.</p></blockquote>
<p><b><a href="http://www.surveymonkey.com/s.aspx?sm=35TJTRQ4Niem30Zehbh_2fQg_3d_3d">http://www.surveymonkey.com/s.aspx?sm=35TJTRQ4Niem30Zehbh_2fQg_3d_3d</a></b></p>
<p>Take a few minutes and let them know your thoughts. It&#8217;s useful when the good guys help each other.</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.phishtank.com/blog/2007/12/19/cmu-survey/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>PhishTank Annual Report: U.S. telecoms hosting phishes; OpenDNS offering a solution</title>
		<link>http://www.phishtank.com/blog/2007/10/09/phishtank-annual-report/</link>
		<comments>http://www.phishtank.com/blog/2007/10/09/phishtank-annual-report/#comments</comments>
		<pubDate>Tue, 09 Oct 2007 17:50:21 +0000</pubDate>
		<dc:creator>Allison</dc:creator>
		
	<category>PhishTank</category>
	<category>Statistics</category>
	<category>Community</category>
	<category>PhishTank in the news</category>
	<category>Data</category>
	<category>Hosts</category>
		<guid isPermaLink="false">http://www.phishtank.com/blog/2007/10/09/phishtank-annual-report/</guid>
		<description><![CDATA[First PhishTank annual report published]]></description>
			<content:encoded><![CDATA[<p>With a full twelve months under our belt, today OpenDNS published the first-ever PhishTank <a href="http://www.phishtank.com/images/PhishTank_Annual_Report_10-9-07.pdf">annual report</a>. </p>
<p>The report looks at the more than 300,000 phishes you&#8217;ve submitted and helped verify over the course of one year. While some of the report&#8217;s findings come as no surprise (e.g., PayPal and eBay round out the top of the list of most spoofed brands), some are alarming. Perhaps the most important finding, and the one that drove us to come up with a fix, is that U.S. telecoms are hosting more phishes than telecoms in any other country. </p>
<p>I think lots of American organizations are led to believe that phishing is something they can do nothing about, aside from simply educating themselves and their people on how to identify phoney emails. Not the case. Starting today we invite all telecoms and other organizations to search PhishTank by their ASN (Autonomous System Number) or brand name. We&#8217;ll even deliver information about phishes hosted on their network via a RSS feed. As a hosting provider, once you know about phishes on your network it&#8217;s easy to stop them.</p>
<p>Here&#8217;s a list of the U.S. telecoms hosting the most phishes, according to PhishTank:</p>
<p>1. SBC - 53,666<br />
2. Comcast - 28,016<br />
3. Roadrunner - 25,925<br />
4. Charter - 12,544<br />
5. Internet Services - 10,332<br />
6. Inktomi Corporation - 9,293<br />
7. XO Communications - 8,511<br />
8. Bresnan Communications - 8,408<br />
9. Advanced Internet Technologies - 8,274<br />
10. Park Region Mutual Telephone Co. - 7,566 </p>
<p>Other interesting report findings include:</p>
<p>18 percent of all verified phishing Web sites were hosted on just three IP addresses. </p>
<p>Web sites ending in &#8220;.cn&#8221; - the Top Level Domain (TLD) assigned to China - account for four of the top five Web sites with the most valid phishes. </p>
<p>One unique phishing scam is launched every two minutes.</p>
<p>You can read the full press releases about the annual report findings <a href="http://www.opendns.com/about/announcements/52/">here</a> and the new ASN and brand search <a href="http://www.opendns.com/about/announcements/51/">here</a>.</p>
<p>Thanks to everyone who contributed to what Brian Krebs of the <a href="http://blog.washingtonpost.com/securityfix/2007/10/a_years_worth_of_phish_phacts.html?nav=rss_blog">Washington Post</a> today called &#8220;one of the most comprehensive data sets ever published on [phishing], offering fascinating insights on the scope and increasing sophistication of phishing attacks.&#8221; <img src='http://www.phishtank.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRSS>http://www.phishtank.com/blog/2007/10/09/phishtank-annual-report/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Phishing for clicks, at my expense</title>
		<link>http://www.phishtank.com/blog/2007/09/07/phishing-for-ad-clicks/</link>
		<comments>http://www.phishtank.com/blog/2007/09/07/phishing-for-ad-clicks/#comments</comments>
		<pubDate>Fri, 07 Sep 2007 19:50:39 +0000</pubDate>
		<dc:creator>John Roberts</dc:creator>
		
	<category>PhishTank</category>
	<category>Verifying phishes</category>
	<category>Yahoo</category>
		<guid isPermaLink="false">http://www.phishtank.com/blog/2007/09/07/phishing-for-ad-clicks/</guid>
		<description><![CDATA[Phishers keep following the money, even via more indirect routes, like sponsored search advertising.]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.phishtank.com/images/status_isaphish.gif" align="right" valign="top" height="51" width="51" />Banks, credit unions, PayPal, eBay, Amazon, the IRS&#8230; all of these organizations suffer from phishing attacks on a regular basis. (Sad, but true.)</p>
<p>Yesterday morning, I personally received an example of a new (to me) category of phish: someone trying to get me to provide Yahoo credentials. Not my personal Yahoo credentials, but my &#8220;Sponsored Search&#8221; account, where I&#8217;d control my advertising spend with Yahoo Search Marketing&#8230;if I had an account!</p>
<p>I suppose the purpose was to steal my credentials and then have &#8220;me&#8221; schedule <strong>and pay for</strong> pay-per-click advertising on behalf of the criminal. Phishers keep following the money, even via more indirect routes.</p>
<ul class="bulleted">
<li>The phish: http://yahincmarketing.com/Login.html (purposefully not linked)</li>
<li>PhishTank submission: <a href="http://www.phishtank.com/phish_detail.php?phish_id=316499">http://www.phishtank.com/phish_detail.php?phish_id=316499</a></li>
<li>Real URL: <a href="https://login.marketingsolutions.yahoo.com/">https://login.marketingsolutions.yahoo.com/</a> (redirects to another Yahoo.com URL, but totally legitimate!)</li>
</ul>
<p>The phisher even copied the Javascript popup from the legitimate site encouraging me to bookmark this new location!</p>
<p>Note: Besides the community&#8217;s vote (thank you!), I&#8217;ve notified someone at Yahoo Search Marketing, so I would expect and hope this site will be taken offline rapidly. It&#8217;s already blocked for <a href="http://www.opendns.com/">OpenDNS</a> customers, of course.</p>
<p><strong>whois info:</strong></p>
<pre>
Domain name: yahincmarketing.com

Registrant:
   Jim Johnson  (SROW-615849)
   mdumi82u@aol.com
   5 rue de Thorigny
   PAris   PARIS
   75003   FR
   +33 42719715
</pre>
]]></content:encoded>
			<wfw:commentRSS>http://www.phishtank.com/blog/2007/09/07/phishing-for-ad-clicks/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>PhishTank in the News: June 12, 2007</title>
		<link>http://www.phishtank.com/blog/2007/06/12/phishtank-in-the-news-june-12-2007/</link>
		<comments>http://www.phishtank.com/blog/2007/06/12/phishtank-in-the-news-june-12-2007/#comments</comments>
		<pubDate>Tue, 12 Jun 2007 17:40:56 +0000</pubDate>
		<dc:creator>Allison</dc:creator>
		
	<category>PhishTank</category>
	<category>Community</category>
	<category>PhishTank in the news</category>
		<guid isPermaLink="false">http://www.phishtank.com/blog/2007/06/12/phishtank-in-the-news-june-12-2007/</guid>
		<description><![CDATA[Two great articles mentioning PhishTank.]]></description>
			<content:encoded><![CDATA[<p>The press spotlight is shining squarely on PhishTank. <img src='http://www.phishtank.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
<a href="http://www.computing.co.uk/computing/news/2191522/phishers-escaping-net"><br />
Computing</a>, a high-profile tech magazine in the UK, covered the recent findings of Cambridge University researchers, who used PhishTank data to analyze Rock Phish. PhishTank is referred to as &#8220;the largest online clearing house of phishing data.&#8221; </p>
<p>Back State-side, Brian Krebs of the <a href="http://blog.washingtonpost.com/securityfix/2007/05/phishing_attacks_soar_nets_wid_1.html">Washington Post</a> does his own piece on Rock Phish and uses a nifty screenshot from PhishTank to demonstrate Rock Phish submissions. </p>
<p>Congrats to the entire community on all the great attention. </p>
]]></content:encoded>
			<wfw:commentRSS>http://www.phishtank.com/blog/2007/06/12/phishtank-in-the-news-june-12-2007/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>The community grows in May, gets even faster</title>
		<link>http://www.phishtank.com/blog/2007/06/01/the-community-grows-in-may-gets-even-faster/</link>
		<comments>http://www.phishtank.com/blog/2007/06/01/the-community-grows-in-may-gets-even-faster/#comments</comments>
		<pubDate>Fri, 01 Jun 2007 20:47:31 +0000</pubDate>
		<dc:creator>Allison</dc:creator>
		
	<category>PhishTank</category>
	<category>Statistics</category>
	<category>Community</category>
		<guid isPermaLink="false">http://www.phishtank.com/blog/2007/06/01/the-community-grows-in-may-gets-even-faster/</guid>
		<description><![CDATA[May stats are up]]></description>
			<content:encoded><![CDATA[<p>May stats are live. Check &#8216;em out <a href="http://www.phishtank.com/stats/2007/05/">here</a>. </p>
<p>A few things popped out at me. First off, median time to submission dropped by 11 hours down to just 19. And the total number of invalid phishes is only 739 out of more than 53,000. Not only is the community getting faster, it&#8217;s also getting more diligent about submitting. </p>
<p>It just keeps getting better and better. Thanks, guys. Keep it up!
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.phishtank.com/blog/2007/06/01/the-community-grows-in-may-gets-even-faster/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Phishing data should be shared</title>
		<link>http://www.phishtank.com/blog/2007/05/21/phishing-data-should-be-shared/</link>
		<comments>http://www.phishtank.com/blog/2007/05/21/phishing-data-should-be-shared/#comments</comments>
		<pubDate>Mon, 21 May 2007 21:16:37 +0000</pubDate>
		<dc:creator>Allison</dc:creator>
		
	<category>PhishTank</category>
	<category>Community</category>
		<guid isPermaLink="false">http://www.phishtank.com/blog/2007/05/21/phishing-data-should-be-shared/</guid>
		<description><![CDATA[PhishTank and Anti-Phishing Working Group are working together.]]></description>
			<content:encoded><![CDATA[<p>And starting today, it is, between <a href="http://www.opendns.com/about/press_release.php?id=19">Anti-Phishing Working Group and OpenDNS</a>.</p>
<p>This is a big day for us, folks, and for all of you who have worked to make PhishTank the most authoritative source of phishing data on the Web. </p>
<p><a href="http://www.antiphishing.org/">Anti-Phishing Working Group</a> is big, and has a member list boasting companies like eBay, Microsoft, Yahoo!, Verisign and Cisco. They&#8217;ve been at phish-fighting since 2003 and have made great progress in raising awareness about the seriousness of Internet crime.</p>
<p>We&#8217;re young, but growing at lightning speed. The human approach OpenDNS and PhishTank bring to the table is an incredibly important element to combatting the problem. </p>
<p>Anti-Phishing Working Group and OpenDNS make a great team and we&#8217;re excited about what we can accomplish together.</p>
<p>[Cross-posted to PhishTank and OpenDNS blogs.]
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.phishtank.com/blog/2007/05/21/phishing-data-should-be-shared/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>PhishTank cited in International Herald Tribune</title>
		<link>http://www.phishtank.com/blog/2007/05/12/international-herald-tribune/</link>
		<comments>http://www.phishtank.com/blog/2007/05/12/international-herald-tribune/#comments</comments>
		<pubDate>Sat, 12 May 2007 13:11:10 +0000</pubDate>
		<dc:creator>John Roberts</dc:creator>
		
	<category>PhishTank</category>
	<category>Statistics</category>
	<category>PhishTank in the news</category>
		<guid isPermaLink="false">http://www.phishtank.com/blog/2007/05/12/international-herald-tribune/</guid>
		<description><![CDATA[April statistics garner a mention in the English-language publication's review of online credit fraud.]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.iht.com/articles/2007/05/11/news/mcredit.php">Credit card fraud keeps growing on the Net</a> is the headline in the May 11, 2007 version of the <a href="http://www.iht.com/">International Herald Tribune</a>. PhishTank&#8217;s <a href="http://www.phishtank.com/stats/2007/04/">April 2007 statistics</a> earned a mention.</p>
<blockquote><p>Statistics from Phishtank, an antiphishing network, found that last month alone some 77,709 phishes were sent out, with 19 percent originating in the United States, 15 percent in France, 14 percent in Turkey and 10 percent from South Korea.</p>
<p>&#8220;This is a global problem,&#8221; said David Ulevitch, the founder of Phishtank, whose data is now being used by Yahoo to help make the Internet safer.</p></blockquote>
<p>Note: the <a href="http://www.iht.com/bin/print.php?id=5664687">printer-friendly version</a> has everything on one page. The PhishTank reference is page 2 of the article, otherwise.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.phishtank.com/blog/2007/05/12/international-herald-tribune/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>PhishTank numbers skyrocket in April</title>
		<link>http://www.phishtank.com/blog/2007/05/01/phishtank-numbers-skyrocket-in-april/</link>
		<comments>http://www.phishtank.com/blog/2007/05/01/phishtank-numbers-skyrocket-in-april/#comments</comments>
		<pubDate>Tue, 01 May 2007 23:28:48 +0000</pubDate>
		<dc:creator>Allison</dc:creator>
		
	<category>PhishTank</category>
	<category>Statistics</category>
		<guid isPermaLink="false">http://www.phishtank.com/blog/2007/05/01/phishtank-numbers-skyrocket-in-april/</guid>
		<description><![CDATA[PhishTank April stats are now available]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s the first of the month again and you know what that means&#8230;. </p>
<p><a href="http://www.phishtank.com/stats/2007/04/">PhishTank April statistics</a> were posted on the Web site today and the differences between April and previous months are hard <em>not</em> to notice. PhishTank caught 77,709 unique phishes last month and tallied a grand total of 243,500 votes. That&#8217;s impressive! </p>
<p>You might notice, too, that new members &#8220;antiphishing&#8221; and &#8220;PhishReporter&#8221; came in No. 1 and No. 2, respectively, in the Top Submitters list. Both members represent organizations that did more than their share of submitting in April. The longer median time to verify can be attributed simply to a much greater pool of phishes to verify. </p>
<p>If you&#8217;re interested, check out the press release <a href="http://www.opendns.com/about/press_release.php?id=14">here</a>.  Keep it up, phish fighters!
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.phishtank.com/blog/2007/05/01/phishtank-numbers-skyrocket-in-april/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Virginia Tech tragedy, phishing, and helping out</title>
		<link>http://www.phishtank.com/blog/2007/04/22/virginia-tech/</link>
		<comments>http://www.phishtank.com/blog/2007/04/22/virginia-tech/#comments</comments>
		<pubDate>Sun, 22 Apr 2007 21:17:19 +0000</pubDate>
		<dc:creator>John Roberts</dc:creator>
		
	<category>PhishTank</category>
	<category>Community</category>
	<category>Developers</category>
	<category>Lists</category>
		<guid isPermaLink="false">http://www.phishtank.com/blog/2007/04/22/virginia-tech/</guid>
		<description><![CDATA[The bad guys take advantage of even the cruelest "opportunities" sometimes.]]></description>
			<content:encoded><![CDATA[<p>As posted to the <a href="http://phishtank.com/lists/users/">user mailing list</a>, the Virginia Tech tragedy has prompted some unscrupulous folks to set up <a href="http://phishtank.com/lists/users/msg01453.html">fake donation sites</a>. Several of these possible scams and phishes have been submitted to the Tank by <a href="http://www.phishtank.com/user.php?username=edgester">edgester</a>, who also helps on the technology side of PhishTank.</p>
<p>Judge them carefully. Scams are not necessarily phish, so apply your judgment appropriately.</p>
<p><b><a href="http://vtfamilies.org/">VTFamilies.org</a> is a site doing the right thing</b>. I&#8217;ve checked it out personally, after an appeal by one of the site administrators. If you want to help, or simply remember, you should visit.</p>
<p><i>I wouldn&#8217;t normally call attention to tragedies: there are simply too many. But the (possible) intersection of phishing and this story called for an exception.</i>
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.phishtank.com/blog/2007/04/22/virginia-tech/feed/</wfw:commentRSS>
		</item>
	</channel>
</rss>
