Business Wire
Welcome
  • Log In
  • Sign Up
Search News:
Help
http://www.antiphishing.org
October 15, 2008 11:51 AM Eastern Time 

Teaching Consumers On-Line Safety Easiest When They Take the Bait

APWG and Carnegie Mellon Team Up to Deliver Safety Instruction in ‘Teachable Moment’ When Consumers Fall for Phishing Scams

ATLANTA--(BUSINESS WIRE)--The Anti-Phishing Working Group (APWG) and Carnegie Mellon University’s Supporting Trust Decisions Project have established a phishing page redirect initiative that protects global online consumers who have been tricked into clicking links in scam emails by delivering them to Web pages that instruct them on the dangers of phishing – and how to avoid them. The program was announced today at the APWG conference in Atlanta.

“This initiative gives takedown teams, ISPs, registrars, and registries the opportunity to take one more step in protecting consumers against identity theft and the other crimes perpetrated by Phishers”

The AWPG/Carnegie Mellon Phishing Education Landing Page program builds on the philosophy of using the “teachable moment” to warn users immediately after they’ve fallen for a phishing lure and then give them on-line safety instruction precisely at a time when they are receptive to it. Phishing sites are designed to resemble Web sites of legitimate businesses, such as banks and online retailers, to trick people into revealing credit card numbers, bank accounts or login names and passwords. Actionable messaging will help consumers to avoid falling victim to these scams a second time.

“We are excited about the opportunity to educate consumers as they are falling victim to a phishing site,” said Dr. Laura Mather, Managing Director of Operational Policy for the APWG and CEO of Silver Tail Systems. “We see this initiative as having real impact in helping people understand when they have received a phishing communication so that they can protect themselves going forward.”

This education-at-time-of-action is accomplished by leveraging the URLs of the phishing sites themselves after anti-phishing investigators have identified the sites and shut them down. Instead of leaving the URL file blank, returning a ‘PAGE NOT FOUND’ message to consumers following phishing links, they will be served a page of instruction on how to avoid phishing and reduce the risk of falling victim to electronic crime. (Redirect scripts placed at the sanitized phishing URL will automatically forward the advisory content.)

“Our research has shown that most Internet users don’t know very much about online scams and don’t realize that there are some simple things they can do to protect themselves,” said Dr. Lorrie Cranor, an associate professor of computer science and engineering & public policy at Carnegie Mellon and director of the Supporting Trust Decisions Project.

Ponnurangam Kumaraguru, a computer science Ph.D. student who is leading the effort to design and evaluate anti-phishing training materials at Carnegie Mellon added, “Nobody wants to spend their time taking on-line safety courses. But we’ve demonstrated that users are receptive to on-line safety instruction immediately after they fall for a phishing attack and they tend to remember this instruction."

The phishing education landing page developed by APWG and Carnegie Mellon teaches would-be victims not to give out personal information upon email request and to use a skeptical eye in judging online communications.

The implementation of the program depends on the participation of both takedown service providers and the ISPs and other companies whose servers have been co-opted to host phishing sites. The APWG is already successfully recruiting companies that perform phishing site takedowns, victimized brandholders and trade associations to encourage ISPs and other organizations that remove phish sites to use the APWG’s education landing page program.

The program is based on a similar program initiated by Bank of America in 2007. The APWG/Carnegie Mellon program builds on Bank of America’s ideas by creating a page that can be used for phishing site against any brand. Bank of America has already implemented the APWG/Carnegie Mellon program.

“Bank of America is committed to providing its customers with industry leading security tools and advice to protect them and enhance their overall customer experience. Educating our customers about the risks of identity theft and fraud is critical,” says David Shroyer, SVP for eCommerce Online Security at Bank of America.

"We know from experience that an educated customer is the best defense against fraud, and with this program we are educating our customers at the point of incidence, and letting customers know that we are working to protect them,” Mr. Shroyer said.

The APWG/Carnegie Mellon scheme will augment the usual procedure for communicating to the hosting organization about phishing sites. Instead of asking that the site be disabled and file content associated with the phishing URL removed, the takedown provider or victimized brandholder would request that the URL be preserved and a redirect script send the duped user to a webpage hosted by the APWG.

The education landing page will automatically determine whether the user is using a PC or laptop or handheld device and vend the device-appropriate page. Users of PDAs and Web-enabled cell phones will receive a page exclusively of text. People using PCs and laptops will receive an enhanced page of text, graphics and a number of links to online resources.

The APWG/Carnegie Mellon scheme will augment the usual procedure for communicating to the hosting organization about phishing sites. Instead of asking that the site be disabled and file content associated with the phishing URL removed, the takedown provider or victimized brandholder would request that the URL be preserved and a redirect script send the duped user to a webpage hosted by the APWG.

The APWG page will automatically determine whether the user is using a PC or laptop or handheld device and vend the device-appropriate page. Users of PDAs and Web-enabled cell phones will receive a page exclusively of text. People using PCs and laptops will receive an enhanced page of text, graphics and a number of links to online resources.

“This initiative gives takedown teams, ISPs, registrars, and registries the opportunity to take one more step in protecting consumers against identity theft and the other crimes perpetrated by Phishers,” said Dr. Mather.

As a next step, the APWG will organize the translation of the pages into various languages to serve the larger international community of consumers, brandholders and ISPs who are confronting the threats of electronic crime and engaging questions of efficacious consumer education.

Links:

Redirect education page: http://education.apwg.org/r/en/

Text only redirect education page: http://education.apwg.org/r/index.html

About the redirect education page initiative: http://education.apwg.org/r/about.html

About the APWG: The APWG is an industry, founded as the Anti-Phishing Working Group in 2003, is an industry, law enforcement and government coalition focused on eliminating the identity theft and fraud that result from the growing problem of phishing, email spoofing, and crimeware. Membership is open to qualified financial institutions, online retailers, ISPs, the law enforcement community and solutions providers. There are more than 1,800 companies and government agencies worldwide participating in the APWG and more than 3,200 members. The APWG's Web site (www.antiphishing.org) offers the public and industry information about phishing and email fraud, including identification and promotion of pragmatic technical solutions that provide immediate protection. APWG's corporate sponsors include: 8e6 Technologies, AT&T (T), Able NV, Afilias Ltd., AhnLab, BillMeLater, BBN Technologies, BlueStreak, BrandMail, BrandProtect, Bsecure Technologies, Cisco (CSCO), Clear Search, Cloudmark, Cydelity, Cyveillance, DigiCert, DigitalEnvoy, DigitalResolve, Digital River, Earthlink (ELNK), eBay/PayPal (EBAY), Entrust (ENTU), Experian, eEye, Fortinet, FraudWatch International, FrontPorch, F-Secure, Goodmail Systems, Grisoft, GeoTrust, GlobalSign, GoDaddy, Goodmail Systems, GuardID Systems, HomeAway, IronPort, HitachiJoHo, ING Bank, Iconix, Internet Identity, Internet Security Systems, IOvation, IS3, IT Matrix, Kaspersky Labs, Lenos Software, LightSpeed Systems, MailFrontier, MailShell, MarkMonitor, McAfee (MFE), MasterCard, MessageLevel, Microsoft (MSFT), MicroWorld, Mirapoint, MySpace (NWS), MyPW, MX Logic, NameProtect, National Australia Bank (ASX: NAB) Netcraft, NetStar, Network Solutions, Panda Software, Phoenix Technologies Inc. (PTEC), Phorm, SalesForce, Radialpoint, RSA Security (EMC), SecureBrain, Secure Computing (SCUR), S21sec, Sigaba, SoftForum, SOPHOS, SquareTrade, SurfControl, Symantec (SYMC), TDS Telecom, Telefonica (TEF), Trend Micro (TMIC), Tricerion, TriCipher, TrustedID, Tumbleweed Communications (TMWD), SurfControl (SRF.L), Vasco (VDSI), VeriSign (VRSN), Visa, Websense Inc. (WBSN) and Yahoo! (YHOO)

About the Carnegie Mellon Supporting Trust Decisions Project. The Supporting Trust Decisions Project (http://cups.cs.cmu.edu/trust) is a research project affiliated with Carnegie Mellon University’s CyLab and the CMU Usable Privacy and Security Laboratory. The project has developed a number of approaches to end-user security education as well as automated tools for detecting phishing attacks. These user education tools and phishing filters are being commercialized by Wombat Security Technologies, Inc. This project is sponsored by the US National Science Foundation, Fundação para a Ciência e Tecnologia Portugal under a grant from the Information and Communications Technology Institute at Carnegie Mellon, and by the Army Research Office.

Contacts

APWG:
Dr. Laura Mather, +1 650-450-4832
laura.mather@antiphishing.org
or
Carnegie Mellon University:
Byron Spice, +1 412-268-9068
bspice@cs.cmu.edu

Recent Stories from APWG

  • View Press Release
    APWG Cybercrime Report: Data-Stealing Malware Growth Spikes in H1 2011
    December 25, 2011
    CAMBRIDGE, Mass.--(BUSINESS WIRE)--Data stealing crimeware proliferation soaring. more »
  • View Press Release
    APWG Report: Cybercrime Attacks on Chinese Businesses Surged in First Half of 2011
    November 07, 2011
    SAN DIEGO--(BUSINESS WIRE)--A new phishing survey released by the Anti-Phishing Working Group (APWG) reveals that phishing attacks perpetrated against Chinese e-commerce and banking sites are soaring more »
  • View Press Release
    APWG Conference Spotlights Cybercrime Gangs’ Mastery of Disguise, Camouflage and Deceptive Techniques
    November 01, 2011
    Graphic
    CAMBRIDGE, Mass. & LOS ALTOS, Calif.--(BUSINESS WIRE)--The APWG’s Fall conference week agenda reveals a disturbing trend in the organization of cybercrime gangs’ enterprises: a growing mastery of d... more »
More Stories
RSS feed for APWG
http://www.antiphishing.org

Company Information Center

APWG RSS feed for APWG

Share

  • Facebook
  • Twitter
  • LinkedIn
  • Delicious
  • Reddit
  • StumbleUpon
  • Digg
  • MySpace
  • Newsvine
  • Google Bookmark
  • Yahoo! Bookmark
  • EmailEmail
Tweet
  • EmailEmail
All News
Business Wire
  • Home
    • Home
    • Membership Benefits
    • Submit a Press Release
  • News
    • All News
    • News with Multimedia
    • News by Industry
    • News by Subject
    • News by Language
    • RSS Feeds
    • Business Wire Mobile
    • Features
    • Company NewsCenters
    • Smart Marketing Pages
    • Company Profiles
    • Annual Reports
  • Events
    • Trade Shows & Events
    • Earnings & Conference Calls
    • Business Wire Events
  • PR Services
    • Press Release Distribution
    • Distribution Lists
    • Industry Targeting
    • LatinoWire & Ethnic Media
    • Public Policy Wire
    • Trade Show Services
    • Photos & Multimedia Marketing
    • GloMoSoMe
    • Press Release Measurement
    • Mobile Alerts
    • Clips & Research
    • Fax & Email Services
    • Online Newsrooms
    • News Feeds
  • IR Services
    • Material News Disclosure
    • XBRL
    • EDGAR (US)
    • IPO Services
    • SEDAR (Canada)
    • European Disclosure
    • Corporate Social Responsibility (CSR)
    • Investor Targeting
    • Fax & Email Services
    • Online Investor Centers
    • IR Resource Center
  • SEO Services
    • Press Release Optimization
    • EON: Enhanced Online News
    • Webinars & Resources
  • Journalist Tools
    • PressPass: Your News
    • Conduct Surveys
    • Business Wire News Feeds
    • Business Wire News On Your Website
    • Journalism Associations
  • Support & Education
    • FAQ
    • How to Write a Press Release
    • How To Optimize a Press Release for Search
    • How to Distribute a Press Release
    • Find Your News Online
    • Sample Press Release
    • Features News Tips
    • International Media Tips
    • SEC Regulations
    • Exchange Guidelines
    • White Papers
    • Webinars & Podcasts
    • Get WiredIn!
  • About Us
    • Business Wire Newsroom
    • Contact Us
    • History
    • Jobs
  • About Us
  • Contact Us
  • Site Map
  • Privacy Statement
  • Terms of Use
  • ©2012 Business Wire

More Business Wire sites

  • Canada
  • UK/Ireland
  • Deutschland
  • France
  • Italy
  • Japan
  • EON: Enhanced Online News
  • Tradeshownews.com
  • PYMNTS.com

About Us

  • Business Wire Newsroom
  • Contact Us
  • Business Wired blog

News on BusinessWire.com

  • All News
  • RSS Feeds
  • Business Wire Mobile Apps

Follow Us on Twitter

  • @BusinessWire
  • @BWSportsWire
  • @BWPolitics
  • @BWCSRNews
  • @EONpr
  • @TradeshowNews
  • @BW_Canada
  • @BWIntlMedia
  • @BWInfoDiva
  • @BusinessWireFR

Like Us on Facebook

  • Business Wire
  • Tradeshow News