403 Web Security Blog

Insight from the leader in secure application development

Archive for the ‘Phishing Scams’ Category

The Zappo’s Breach – When Bad Things Happen to Good Companies

shoeWho doesn’t love Zappos? They are one of the friendliest Internet stores in the US. Zappos started in 1999 by Nick Swinmurn, a truly great guy, who grew the company to $1 billion in sales by 2008. It has been a few years, but I still remember those giant boxes of Zappos shoes my wife and daughter would order – lots of styles in several sizes each. The shoe … Read More »

The Easy Millionaire Road

UntitledIt is with mixed emotions that I tell you I will soon be leaving 403 Web Security. While the date of my departure has not been established, I am confident that the pressures of managing my soon-to-be millions of dollars will not allow me to continue as the Managing Director of 403 Web Security. As I regard you as my trusted friends, I will share the source of some … Read More »

Changing Grades – One Student’s Dream

A+As the current Fall semester comes to a close, a young geek’s dreams turn towards… No, not girls, why bother to even think about the impossible? The great geek dream is the hacking of the registrar’s database to fix a few grades. How many movies and TV shows have we all seen where the geek makes a few grade changes; maybe helping out that cute girl in his class … Read More »

After the Breach – What Happens to the Little Guy?

data breach victimEarlier this year Citibank, Epsilon and Sony made the headlines as the victims of massive data breaches. These data breaches compromised sensitive information, created lawsuits and tarnished company reputations. Needless to say, data breaches like these are a nightmare for any company, but what about the other victims… “…what about me, the little guy, you know the one who had his identity stolen? I’m the one who is now … Read More »

The Simplicity of a Phishing Scam

email phishing scamWhile I’ve written many blog entries on Phishing (perhaps enough already) – I ran across an email phishing scam so simple and elegant I just couldn’t help but share. In a rare confessional mood, I will admit my admiration for this particular scam stems from the fact that, when I first read the baiting email (below), I silently swore at my own stupidity for sending out the huge vacation … Read More »

Office Stranger Danger – Preventing Opportunities for Social Engineering

hacker296_thumb230As I discussed in my last post, social engineering is the act of enticing people to bypass computer security by performing actions or divulging confidential information. Unfortunately the largest threat to the security of our businesses typically comes from within – naïve employees who inadvertently give up important security information to sly con artists. While educating your employees about phishing and other potential social engineering scams is an important … Read More »

Office Stranger Danger – Avoiding Social Engineering at Work

stranger-dangerTwo great stories in Social Engineering history: 1.  In November 2010, Andy Surface sent an email to Conde Nast (the company the publishes Vogue and the New Yorker) requesting $8 million dollars — from a fake company whose name sounded like the media giant’s printing company. Conde Nast paid the invoice. 2.  In a recent information security survey, 90% of office workers gave researchers what they claimed was their … Read More »

The Currency of Cyber Crime – Protecting Your Personal Data

Cyber CrimeYou might spend a good deal of time online, but what you probably don’t realize is that cyber crime is a multi-billion dollar industry and your personal data is the currency. We all see films and TV shows where millions of dollars are stolen from banks by young, attractive bad boys (who just happen to be computer experts). While this may occasionally happen, real cyber crime at the consumer … Read More »

The PlayStation Network Breach

Sony Playstation hackAn anonymous group of hackers caused the Sony PlayStation Network to go down over a month ago. Though this PSN outage has been a pain for gamers, it also caused far more serious problems including putting users’ personal data at risk. Learn more about how the PlayStation Network Breach might have occurred, what it means for you and how gamers can protect themselves from identity theft.     Question: … Read More »

Spear Phishing for Fun and Profit

phishing scamRemember the old scam where a distraught woman wanders a train (usually carrying a baby) telling her fellow passengers she has lost her wallet and just needs $10 to get home? Having grown up in New Jersey, I’ve had the chance to watch this scam in action. A poorly dressed woman, baby in hand, moved from train car to train car, collecting money in each car. She was very … Read More »