Webroot reports on fake Verified by Visa phishing scam

20 November 2009

IT security vendor Webroot says that a phishing scam purporting to come from Visa, the international card issuer, is scamming internet users as they start their online shopping for Christmas.

According to a blog posting by Webroot, the phishing scam commences with a phishing email advising the recipient that he or she can now sign up for Verified by Visa, an online authentication system designed to enhance security for online shoppers.

Whilst the Verified by Visa security scheme is legitimate, Webroot noted that the phishing email links to a bogus page that logs your credentials for - presumably - later use by the fraudsters.



"The thing is, you don't have to go to a special web page to sign up for Verified by Visa. You are supposed to be offered the chance to sign up while you're completing your purchase on the participating merchant's web site, as you're entering your billing details", said the blog posting.



"The Visa website spells this out in a simple graphic (though there have been some interesting problems with the way the system works)", it added.



According to Webroot, in the Verified by Visa phishing scam, users are sent to a web page that asks you for the information you gave the card-issuing bank at the time you first signed up for the card.



"That's red flag #1, but it's worth repeating: In a real sign-up form for Verified by Visa, you won't be asked to provide your mother's maiden name, social security number, birthdate, or any other sensitive details that you wouldn't otherwise enter into a web-based order form while shopping online", the blog notes.



The other red flags include the lack of a secure (httbs) connection and the registration of the domain name used by a Google email account.



Faux “Verified By Visa” Phishing Scam Targets Holiday Shoppers

By Andrew Brandt







When you sign up for a credit card — even with one of those pre-approved applications — you still have to provide the bank with your name, address, mother’s maiden name, social security number, and a host of other personally identifiable information. Once the bank issues the card, it shouldn’t ever need to ask you for all of that information again. But a phishing scam making the rounds this week — one that appears to be targeted at holiday shoppers who buy gifts online — aims to fool victims into doing just that.



The scam begins with an email, informing the recipient that they can sign up for Verified by Visa, a real program offered by the eponymous credit card company. The email links to a bogus page (part of which is shown at left) designed to lure an unsuspecting online shopper into the trap. (And this is only one of several scams you should watch for, leading up to Black Friday, Cyber Monday, or whenever it is you decide to go online for deals on that fruit basket for Grandma. Webroot released findings today on additional data-stealing malware, and the larger pool of online shoppers this year which it appears to be targeting.)



Once you register with the (real) Verified by Visa service, participating merchants permit you to enter a password in addition to your card information. In addition to providing the purchaser with an additional layer of safety, the password also gives the merchant some assurance that larger-than-normal transactions (like the ones you make during holiday shopping season) will be approved quickly, without triggering fraud alerts.



The thing is, you don’t have to go to a special Web page to sign up for Verified by Visa. You are supposed to be offered the chance to sign up while you’re completing your purchase on the participating merchant’s Web site, as you’re entering your billing details. The Visa Web site spells this out in a simple graphic (though there have been some interesting problems with the way the system works).





In the phishing scam, you’re sent to a Web page that asks you for, essentially, all the information you gave the card-issuing bank at the time you first signed up for the credit card. That’s Red Flag #1, but it’s worth repeating: In a real sign-up form for Verified by Visa, you won’t be asked to provide your mother’s maiden name, social security number, birthdate, or any other sensitive details that you wouldn’t otherwise enter into a Web-based order form while shopping online.





The page created by the phishing gang responsible for this scam is clearly more professional, slick and clean than most phishing pages. The form’s businesslike appearance serves to reassure the victim that the page really belongs to Visa.



The form data is supposed to be sent over a secure HTTP connection (with an HTTPS prefix before the website’s URL in the browser’s Address Bar), but this one clearly is using a standard HTTP connection, which is Red Flag #2. Sniffing the network lets us see exactly what the page sends to the scammers, like the fake data I entered into the form (shown above right).









Red Flag #3 is not as obvious if you don’t dig into the Website’s records, but really: Do you suppose a company as large as Visa International would register a domain name using a Gmail account, a Canadian mailing address, and (Thanksgiving-related puns aside) a telephone number that uses the international dialing code for Turkey?







Verified by Visa is, potentially, capable of helping reduce fraud and may also prevent criminals from using stolen credit card numbers. Just make sure you’re signing up for the right program, not handing your wallet over to crooks.

Posted by John B. Frank Friday, November 20, 2009

0 comments

Payments Industry News Blog

Search the PIN Debit Blog by Subject

Kapersky Calls for Mass Adoption of Card Readers

Kapersky Calls for Mass Adoption of Card Readers