Tech companies not doing enough to protect users from phishing scams

31 Jul 2019

1

Technology companies could be doing much more to protect individuals and organisations from the threats posed by phishing, according to research by the University of Plymouth.

However, users also need to make themselves more aware of the dangers to ensure potential scammers do not obtain access to personal or sensitive information.
Academics from Plymouth's Centre for Security, Communications and Network (CSCAN) Research assessed the effectiveness of phishing filters employed by various email service providers.
They sent two sets of messages to victim accounts, using email content obtained from archives of reported phishing attacks, with the first as plain text with links removed and the second having links retained and pointing to their original destination.
They then examined which mailbox it reached within email accounts as well as whether they were explicitly labelled in any way to denote them as suspicious or malicious.
In the significant majority of cases (75 per cent without links and 64 per cent with links) the potential phishing messages made it into inboxes and were not in any way labelled to highlight them as spam or suspicious. Moreover, only 6 per cent of messages were explicitly labelled as malicious.
Professor Steven Furnell, leader of CSCAN, worked on the study with MSc student Kieran Millet and Associate Professor of Cyber Security Dr Maria Papadaki.
He says, "The poor performance of most providers implies they either do not employ filtering based on language content, or that it is inadequate to protect users. Given users' tendency to perform poorly at identifying malicious messages this is a worrying outcome. The results suggest an opportunity to improve phishing detection in general, but the technology as it stands cannot be relied upon to provide anything other than a small contribution in this context."
The number of phishing incidents has risen dramatically since they were first recorded in 2003. In fact, global software giant Kaspersky Lab reported that its anti-phishing system was triggered 482,465,211 times in 2018, almost double the number for 2017.
It is also a significant problem for businesses, with 80% telling the Cyber Security Breaches Survey 2019 that they have encountered 'Fraudulent emails or being directed to fraudulent websites' - placing this category well ahead of malware and ransomware.
Phishing is designed to trick victims into divulging sensitive information, such as identity and financial-related data, and the threat can actually take several forms:
  • Bulk-phishing - where the approach is not specially targeted or tailored toward the recipient;
  • Spear-phishing - where the message is targeted at specific individuals or companies and tailored accordingly;
  • Clone-phishing - where the scammers take a legitimate email containing an attachment or link, and replace it with a malicious version;
  • Whaling - in these cases the phishing is specifically targeted towards high value or senior individuals.
Professor Furnell, who has previously led various projects relating to user-facing security, added: "Phishing has now been a problem for over a decade and a half. Unfortunately, just like malware, it's proven to be the cyber security equivalent of an unwanted genie that we can't put back in the bottle. Despite many efforts to educate users and provide safeguards, people are still falling victim. Our study shows the technology can identify things that we would ideally want users to be able to spot for themselves - but while there is a net, it clearly has big holes."

Latest articles

Ford cancels $6.5 billion battery deal with LGES amid massive EV strategy reset

Ford cancels $6.5 billion battery deal with LGES amid massive EV strategy reset

Tesla opens its first charging station in Gurugram, expands India EV footprint

Tesla opens its first charging station in Gurugram, expands India EV footprint

Vedanta Aluminium expands Lanjigarh refinery to 5 MTPA, boosts India’s global rank

Vedanta Aluminium expands Lanjigarh refinery to 5 MTPA, boosts India’s global rank

Larsen & Toubro wins large orders for Omkareshwar museum and FIFA stadium

Larsen & Toubro wins large orders for Omkareshwar museum and FIFA stadium

ACME Solar commissions 52 MW of Gujarat wind project; shares rise

ACME Solar commissions 52 MW of Gujarat wind project; shares rise

Ola Electric founder clears ₹260 crore debt via stake sale; stock hits record low

Ola Electric founder clears ₹260 crore debt via stake sale; stock hits record low

ITC gets CCI nod for Rs3,498-cr acquisition of Aditya Birla Group’s paper and pulp manufacturing business

ITC gets CCI nod for Rs3,498-cr acquisition of Aditya Birla Group’s paper and pulp manufacturing business

IndiGo overtakes Air India Group in international traffic after six-year gap

IndiGo overtakes Air India Group in international traffic after six-year gap

MUFG to bet big on India with $4 billion stake in Shriram Finance

MUFG to bet big on India with $4 billion stake in Shriram Finance

Business History Videos

History of hovercraft Part 3 | Industry study | Business History

History of hovercraft Part 3...

Today I shall talk a bit more about the military plans for ...

By Kiron Kasbekar | Presenter: Kiron Kasbekar

History of hovercraft Part 2 | Industry study | Business History

History of hovercraft Part 2...

In this episode of our history of hovercraft, we shall exam...

By Kiron Kasbekar | Presenter: Kiron Kasbekar

History of Hovercraft Part 1 | Industry study | Business History

History of Hovercraft Part 1...

If you’ve been a James Bond movie fan, you may recall seein...

By Kiron Kasbekar | Presenter: Kiron Kasbekar

History of Trams in India | Industry study | Business History

History of Trams in India | ...

The video I am presenting to you is based on a script writt...

By Aniket Gupta | Presenter: Sheetal Gaikwad

view more
View details about the software product Informachine News Trackers