X
2006

Microsoft Launches Anti-Phishing Legal Offensive

March 11, 2006 0

Microsoft is taking phishers to court in Europe, after launching a similar legal campaign in the United States

Microsoft has kicked off an initiative to file more than 100 legal cases against organizations running phishing scams from Europe, the Middle East and Asia. The company’s Global Phishing Enforcement Initiative is a worldwide effort to coordinate and expand anti-phishing work through prosecution, partnerships, and consumer protection software.

 

The first 53 cases will be filed within the next two weeks against individuals from Turkey, France, Spain, Morocco, the UK, Germany, Austria, Egypt and Sweden.

The suspects were tracked down as part of US investigations into phishing attacks, and Microsoft has assisted local authorities in identifying perpetrators. “All the attacks were targeted at Microsoft users or services such as Hotmail, MSN and Passport.”

Company officials announced the plans at the debut of what Microsoft calls its Global Phishing Enforcement Initiative (GPEI), a worldwide effort to coordinate and expand anti-phishing work through prosecution, partnerships, and consumer protection software, such as the beefed-up Internet Explorer 7 browser scheduled to release later this year.

By the end of June, Microsoft will have initiated at least 51 new anti-phishing cases in the company’s European, Middle Eastern, and African territories, bringing the total filed to over 100.

"It is critical that we start developing global enforcement programmes to address phishing and all cyber-crime issues," said Tim Cranton, a Microsoft senior attorney and director of the Internet Safety Enforcement Programme.

In phishing scams, fraudsters try to steal personal data such as passwords and credit card numbers. Typically, they send out e-mails luring people to Web sites spoofed to look like they belong to a trusted provider such as a bank. A record 7,197 phishing Web sites were spotted in December, according to the Anti-Phishing Working Group.

They most commonly target US bank customers and eBay users.

The operators of fraudulent Web sites that claim to be Microsoft sites, such as MSN or Hotmail, will be pursued by the company for copyright infringement, the software giant announced at a discussion panel event in Brussels.

"Phishing is a crime. It undermines consumers’ trust in the Internet and is an impediment to European policymakers’ and industries’ efforts to boost citizens’ use of innovative and valuable Internet services," Neil Holloway, president of Microsoft for Europe, the Middle East and Africa, said at the discussion.

The panel was hosted by the European Internet Services Providers Association and co-sponsored by Interpol.

Holloway said Microsoft was committed to battling phishing, and would continue to partner with law enforcement, educate consumers, and develop anti-phishing technologies. Microsoft executives said the Redmond, Wash.-based company expects to file 53 cases against phishing attackers by the end of March, rising to more than 100 by June.

But attacks are starting to become more sophisticated, and have been attempting to obtain log-in names and passwords for corporate networks. Data from email security vendor CipherTrust indicates that most phishing attacks originate from computers in the US (32.1 per cent) and Korea (15.4 per cent).

But it is often hard to determine the origin of the attacks because they are usually launched from hacked computers that are part of botnets controlled by the phishing gang.

Paul Judge, chief technology officer at CipherTrust, applauded Microsoft’s initiative.

Without the enforcement, people feel that there is no downside to participating in this type of activity. It is almost a free for all, and they can hide behind the anonymity of the technology, he told vnunet.com.

This latest campaign continues Microsoft’s (GPEI), a program dedicated to pooling private sector and government resources to prosecute cyber-criminals and to protect consumers. The company has helped take down more than 4,744 phishing sites worldwide, it said. It collaborated with police forces to shut down an operation in Bulgaria that played off MSN properties.

Bernard Otupal, a crime intelligence officer from Interpol’s Financial and High-Tech Crime Unit, emphasized the benefit of working with Microsoft to law enforcement officials. He said the partnership gave them direct access to the latest technology advances in phishing.

"Law enforcement cannot deal with the issue alone. It is time to make links between Internet service providers, hardware and software companies and law enforcement," Otupal said at the panel discussion.

"But to see that there is a group that will invest the time and resources to track them down and bring them to court will force several of them to reconsider the risk and reward of this type of activity.

Although Holloway did not divulge details on the upcoming lawsuits, the company’s statement said the filings would include formal complaints, court actions, and settlements against "serious criminals engaged in phishing."

Judge argued that legal action against spammers has helped to cut spam, and that the same will happen with phishing.

A recent survey by U.K.-based security company Sophos said that more than half of U.S. business PC users receive at least one or more phishing e-mails daily, while the Anti-Phishing Working Group, an American organization, has noted that phishing attacks reached an all-time high in late 2005.

Microsoft claimed that it had shut down nearly 5,000 phishing sites worldwide, and had filed 117 phishing-related lawsuits in the U.S. alone during 2005