Phishing through Website Duplication
Contrary to popular belief, phishing is not always done through the proliferation of spam email and unendorsed electronic communication. Many trustworthy websites are now finding that they are falling victim to phishing via a phenomenon called website duplication - which is often a very difficult thing to spot unless the victim is really paying attention.
Imagine that you were to visit your bank website - in order to make a bill payment. You would head off to the site, put your log in details in to the system, and then proceed to complete your tasks. But - how often do you actually check to make sure that you are on the right site, before you actually log in? Sure, it looks like the correct site - but is it?
Detecting Website Phishing
Unfortunately, too many people do not employ internet safety techniques when it comes to online banking and shopping. They simply (and perhaps innocently) follow the lead of the website - and will pretty much do anything that they are asked to do in the process.
To illustrate this, how many of you reading this article do the following things before logging in to your internet bank account:
- Check to make sure that the site certificate is valid.
- Ensure that the page is SSL secured.
- Check the address bar to ensure that your banks URL is exactly correct.
- Never visit your bank through a link in an email.
If you do these 4 things every time, you are probably safe from website duplication phishing. However, if you have been automatically assuming that the internet is a totally safe place - you might want to think again, and have a closer look at your web actions.
It's Easy To Duplicate A Website
When we tell people that they should be paying close attention to the website they are on, and ensuring at every step that they are still on the actual "trustworthy" site - they usually laugh and wonder if we are out of our minds.
After all, they reason, duplicating an entire website must be extremely difficult! Actually - it's not, and the fact of the matter is that even if it was, people would still do it to fool you in to handing over your login details. So - watch out for this type of scam, and always pay attention when you are surfing the internet.