Impressive Phishing Attack
Read about it here, or in even more detail.
I find this phishing attack impressive for several reasons. One, it’s a very sophisticated attack and demonstrates how clever identity thieves are becoming. Two, it narrowly targets a particular credit union, and sneakily uses the fact that credit cards issued by an institution share the same initial digits. Three, it exploits an authentication problem with SSL certificates. And four, it is yet another proof point that “user education” isn’t how we’re going to solve this kind of risk.
Richard Braakman • February 22, 2006 8:52 AM
I’m amused by the Geotrust comments that imply that only organizations that look like financial institutions are checked. This raises the question… if only financial institutions need such scrutiny, then why does anyone else use a signed SSL certificate?