Eben Louw, forensics manager, KPMG, comments that the statistics in May 2010 highlighted an increase in identity and information theft made possible by phishing, spoofing and spyware. As of May 2010 Messagelabs Intelligence has reported that an astonishing 1 in every 237 emails received is a phishing attack. In keeping with the times the current trend is to disguise these attacks as Soccer World Cup promotions.
“Cyber-Crime is an attack that originates from or is facilitated by a computer or network system on another computer or network system. It’s a “clean” and “sophisticated” method of committing a serious crime.”
He explains that more people are sharing sensitive information on social websites like Facebook that currently boasts more than 400 million users and Linkedin with more than 70 million. Sensitive information can be used by Cyber-criminals to commit identity fraud and eventually steal money from a user.
Louw quotes the example of a family that wishes to invest their savings into a profitable scheme for when their children are old enough to attend university. They received an email as part of the World Cup promotions from an Investment Company offering them great deals. They may visit the internet based Investment Company and complete the compulsory application form that asks for their banking details, contact numbers and physical address. Innocently they complete and post the form on-line with no reason for concern as the Investment Company ensures their information will remain secure and confidential.
But he argues that the entire on-line investment scheme could be a scam. Furthermore, questions should be asked about whether the investment scheme’s online application form is secure and not vulnerable to compromise or interception.
“A serious threat to companies is the involvement of criminal syndicates that breach security systems by using authorized staff to commit fraud. Both private and public sector businesses are constantly affected by this modus operandi.”
Louw warns that cyber-crime is not just a buzz word but truly an attack by serious criminals! “Our only defense is secure systems, continuous monitoring applications, trusted staff, appropriate awareness and educational programs”.
Author: Eben Louw (Manager – KPMG Forensic)
