Monday, 22 December 2014
Phishing: Message Options
No single method will protect - in the end, you have to be suspicious of any request for personal details or even opinions. How many of us have answered a phone call that was apparently a survey and ended up being asked for details that could open us up to further unwanted phone calls or given details about our address, postcode or buying habits?
If you use a Windows computer, you may also have Microsoft Office. This is a fantastic tool for organising your e-mail, but the latest version has made it harder to look closely at incoming messages before you actually open them. The trick is to look at the Message Options and see if the addresses in the mail headers actually look anything like the apparent sender.
In Outlook 2003 and later versions, it used to be possible to right-click on a message in the Inbox and look at the headers directly. The latest version, Outlook 2013 (also part of Office 365) doesn't allow this unless you first do a little customisation. Here's how to do it.
I haven't yet found a way to restore the right-click function but you can still use it if you customise the Quick Access Toolbar of Outlook 2013. That's the very top of the window, where the Outlook application icon, the Send/Receive All button and the Undo button can be found. It looks like this:
Right-click on the ribbon (that's the feature with the tab names and icons just below the Quick Access Toolbar). You'll be offered the option to customise the Quick Access Toolbar. Set the top drop-down box to Commands Not in the Ribbon. It looks like this:
Select Message Options and then click Add, and move it up one place using the buttons on the far right. When you click OK, the Quick Access Toolbar should look like this:
When you receive a message that looks suspicious - as examples, a bill you weren't expecting, a receipt for a charity donation, a request to confirm your details, a notification of a failed payment, in your Inbox, select but don't open the message. Then click on the fourth icon from the left at the top of the window (Message Options). If when you scroll down, you see evidence of spoofing of addresses, just delete the message - don't open it, and certainly not its attachments. Here's an example of a spoof e-mail with some of the tell-tale signs:
This was supposed to be from NatWest Bank. Why would it send an e-mail from a belgacom.be address, relayed through skynet.be? And then why would its From address be nto.com. Who?
Use this tip and your own intelligence to cut down your risk of being hacked by evil people.
Wednesday, 14 May 2014
Credit card security blown wide open on postal transactions

(Originally made this post on Ecademy.com, now Sunzu.com, on 11 Dec 2007)
I'm becoming increasingly worried by suppliers that ask for your debit or credit card security number in writing, along with the card number and expiry date, for postal transactions. This blows the security system wide open. Anyone that intercepts your instructions, either before or after your legitimate payment is made, has everything needed to rip off suppliers (and you).
Why are suppliers doing this? Simply, it's because their banks are demanding these details for Customer Not Present transactions that are entered through merchant machines such as the PDQ.
When you enter card details onto a secure supplier website or a proper payment service such as PayPal, the possible number of fraudsters is quite limited, and collusion or fraudulent action by the owner of the site is a strong suspicion if anything goes wrong. The chain is pretty clear. But just like a pair of CD-ROMs, if a piece of paper goes astray, it could be in anyone's hands, it can be photocopied and sent anywhere in the world, and huge amounts of damage can be done.
Signature as confirmation of identity should be enough for 'cold' transactions where no goods are shipped within 24 hours. When a PDQ machine is used, the bank now seems to require the security number. Specific cases in the last two weeks: NatWest demanded this from a charity for a donation that I wanted to make by card (I sent a cheque instead, along with my Gift Aid form) and a UK passport application where the payment must accompany the application form (I used the Check and Send service at a Post Office which allowed me to make the payment electronically).
This is really dangerous stuff. Barclaycard told me definitely not to send the card security number in writing along with other card details, but I wouldn't be surprised if their merchant people are following the same protocol as NatWest and the Home Office. Is this a general problem? I'd like to gather evidence and to hear of any other cases where this practice has been introduced. And then make some noise in the right places.
Comments received on Sunzu.com:
John, I agree with you and I will not write down a security number. I also agree with S - suppliers keeping written records of credit card numbers also provides a security loophole for dishonest employees and theft from suppliers premises. What's the point of shredding all your documents at home if suppliers have such details in their filing cabinets ! My advice (which I will now take myself in future) is not to write down my credit / debit card numbers on any paper form. Regards, G (UK)
John, I totally agree, you should never give out all these details in writing. The point of the security code, well is.... security. The best practice on this is never to have the card details in writing..... as soon as there is a record, there is a risk towards the data protection rules. As e-retailers, we make 3 important points: 1- all online purchases are managed through secure services so we never have access to the customer's card details 2- for transactions over the phone, we always carry out the transaction live and do not take notes of the card numbers. Once the transaction is finished we (and any other mischievous party) have no way of retrieving the card details. this is quite an effective way of preventing credit card fraud. 3- we never ask for card details in writing I now demand the same type of security from my suppliers, so no employee could take note of the card number in passing. Many organisations do not realise their responsibilities in that area... how many are ensured against employee dishonesty??? S (France)
Agreed
It always makes me think about it on line, I am not sure that is good practice even with the security that wraps around it. K (UK)
I agree with you John, I think there is very little personal safety as regards our financial details. I hate to think how many companies have our details of cards, dob, NI numbers etc. You are right - so much damage can be done in a short space of time. When the CD's went missing I think it gave everyone a shake up. And yet will any of these things stop? I think not. I recently watched a movie. It was called 'The Lives of Others' . It was in German with subtitles. It was set in East Germany just before the wall came down. It really exposed just how thorough the Stasi were in gathering information on everyone. It was a society where people had no freedom, no secrets, no comeback.Nowhere to go to talk about injustice. Anyone who spoke out or argued against the State were imprisoned or worse. Is this what is happening over here. One has to ask - 'What exactly is going on'? L (UK)
Friday, 28 October 2011
Solution for the Global Tech scam?
They ignore Telephone Preference Service registrations. They claim to be operating from Baker Street in London but the phone calls sound as though they're coming from a very long way away. A legitimate company working in the UK would not be making unsolicited sales calls to a TPS registered line. The scammers don't take any notice of polite requests to desist from making these nuisance calls.
They offer to help by taking control of your computer, in return for a credit card charge.
Since we can't send a jolt of current back up the line to them, another solution is needed. It seems to me that the credit card companies are the critical link and by accepting payments for the scammers, they are facilitating the scam. If people who've been caught out then report the scam to their credit card company, we may see some progress (and fewer annoying calls).
There's more useful information about other peoples' experiences on the Conflict International site (the blog is closed for comments).
You can register your phones with the Telephone Preference Service free of charge at http://www.tpsonline.org.uk/ - don't be misled by others who offer you a paid service that purports to do the same thing.
Wednesday, 30 March 2011
No to 'Outbound telesales'
This can be dangerous. Even when the caller identifies the name of the company she or he represents, there's no way to know whether or not this is for real. Someone called me today, she said, on behalf of a company whose services I've used for years. But she got the number of years wrong, and that says to me that she was doing the telephone equivalent of phishing.
I don't want to give any details to an unknown caller to enable them to offer me 'advice'. Nor do I do want to invite a high-pressure salesman into my home just because they happen to have 'someone in the area' next week; what area, planet Earth?
Telephone companies are bothersome at best when they phone to try and sell something. When they ask you at the end of a 20 minute call, "by the way, the contract is for 18 months, is that all right?", that doesn't feel like trustworthy practice. When you say, "I'd like to see the offer in writing", and they say it's only available today over the phone, is that a strong reason buy anyway? And if they send the key details, and they're in grey 4-point on the back of the brochure, is someone trying to hide something?
Frankly, I can find the products I want using Google, a newspaper, or even a flyer through the post. And then visit the website or make the call to Inbound Telesales, knowing who I'm calling, to do the deal. That's exactly what I did regarding buildings and contents insurance recently. Outbound Telesales is only for things you don't really want. Be brave - don't tick the box allowing them to contact you.
Thursday, 16 April 2009
Goodbye Norton 360
I've used Norton Antivirus and related products exclusively for the PCs that I control for the last 10 years. Laptops arrived with Norton products pre-installed, and these did the job adequately.
Norton 360 was included with the Toshiba Tecra (Vista) laptop that I bought about 15 months ago. Though I didn't like it very much, I renewed the subscription before the 90 days' trial was complete. Now that 12 months' renewal has expired and guess what! All protection seems to have stopped - the product doesn't carry on checking for viruses, firewall, intrusion protection, e-mail scanning, virus and spyware scan. The whole lot seems to have been switched off (if I understand the messages correctly) now that the date has been reached. Other Norton products carry on protecting with the versions of the virus signatures up to the date of the renewal. This doesn't; it's abdicated completely.
Goodbye Norton 360. I won't accept such a business policy. It's AVG for me.
Friday, 22 June 2007
Unsolicited calls
Two unsolicited calls today on my home phone, which is registered with the Telephone Preference Service (TPS). One caller identifies himself as working for 'various financial companies', the other for 'different financial companies'. They pronounce the 'various' and the 'different' very indistinctly to try and cover up the fact that they haven't introduced themselves properly. They want to make an offer regarding mortgage interest rates. Both are using a very low quality connection and refuse to state who they represent. They won't say who asked or told them to call me.
A UK regulated financial services company should not be making unsolicited outbound calls. It knows that this carries penalties, and increasingly will ask customers to sign up to receive a regular call from an adviser or an account manager. Product design may include a provision for calls from time to time. So a company may sometimes make a mistake, but it will try hard to avoid repeating it. If you don't want to be bothered, just tell them clearly that you don't want to hear from them again.
An unregulated company based abroad has few constraints apart from penalties that may arise if any misuse of the telephone system is proven. The best thing to do is to tell these people to get lost - and don't call again.
TPS advice is as follows
Companies based abroad who call into the UK and who are making calls on behalf of a UK based company, must comply with UK regulations and screen their call lists against TPS before making an unsolicited sales and marketing call to a UK telephone number. We do make the file available to overseas based companies under licence for the purpose of suppression so they know whom not to telephone but many overseas companies who telephone the UK on their own account from overseas do so to avoid legal and self regulatory restrictions. We would advise caution in responding to unsolicited sales and marketing telephone calls from overseas especially if they are asking you to send them money or using a premium rate phone line (numbers beginning with 09). If you are receiving unsolicited sales and marketing calls from overseas you should contact the overseas company who is making the call.
Just ask - which company's products are you selling? If there's no straight answer, it's either a scam or a very stupid sales approach. In either case, you really want nothing to do with them.
Monday, 2 April 2007
Report phishing attempts
| BankSafe Online (operated by APACS*): | reports@banksafeonline.org.uk |
| Anti-Phishing Working Group (APWG): | reportphishing@antiphishing.org |
| A&L | frauddepartment@alliance-leicester.co.uk |
| Barclays: | internetsecurity@barclays.co.uk |
| Halifax Bank/HBOS: | onlineemailinvestigations@hbosplc.com with the subject 'Report' |
| HSBC: | Gives links to APWG and BSO |
| Lloyds TSB: | EmailScams@lloydstsb.co.uk |
| Nationwide Building Society: | phishing@nationwide.co.uk |
| NatWest: | nwolb@natwest.com |
| Royal Bank of Scotland: | digitalbanking@rbs.co.uk |
| Abbey National: | E-Banking helpdesk on 0845 600 4388, open 7am-11pm, seven days a week |
| Clydesdale Bank: | links to APWG |
| Yorkshire Bank: | links to APWG |
| Northern Bank: | links to APWG |
Forwarding your suspect email
Select the suspect email (don't double click to open it), right click and select the Forward action, and send it to the appropriate email addressAttaching the suspect email to a new email
Create a new email in your PC or Mac based email software, and drag and drop the suspect email from your inbox into the body section of the new email. Please note that this method will not work for web based email services e.g. Hotmail, Yahoo! Mail etc.*APACS is the UK trade association for payments and for those institutions that deliver payment services to customers.




