create your own

Identity Theft Fears and Social Networking

63
rate or flag this page

By gpbrewer


Virus


Hi, this is Greg from Arlington, VA. I wanted to share some information with you folks that use social networking regarding the threat of Identity Theft and your on-line banking account.

It appears that over 500,000 online bank accounts and credit and debit cards have been compromised by a virus described as "one of the most advanced pieces of crimeware ever created". The Sinowal Trojan as it is called, has been tracked by the British security division of EMC, RSA FraudAction Research Lab, which helps to secure networks in Fortune 500 companies.

RSA FraudAction Research Lab has discovered log-in information for about 300,000 online bank accounts and 250,000 credit and debit card accounts that have been gathered by a cybercrime gang over the past three years using the Sinowal Trojan.

The Big Problem

RSA described Sinowal as "one of the most serious threats to anyone with an internet connection," because it works behind the scenes using a common infection method known as "drive-by downloads".

According to Microsoft, Drive-by downloading is a catch-all name for software downloaded on your computer without your knowledge or intervention. Drive-by downloading is different than phishing, which misleads users by using authentic-appearing sites that deceive users into entering sensitive information, and different than pop-ups, which fool users into agreeing to download software. Drive-by downloads sneak onto computers without the user’s knowledge or permission.

RSA said the trojan virus has infected computers all over the planet. Sinowal has been constantly updated with new variants.

See Full Report Here

In April 2007, researchers at Google discovered hundreds of thousands of web pages that initiated drive-by downloads. It estimated that one in ten of the 4.5 million pages it analysed were suspect. Sophos researchers reported in 2008 it was finding more than 6,000 newly infected web pages every day, or about one every 14 seconds.

Organized Cybercrime Gangs

RSA said the worrying aspect about Sinowal is that it has been operating for so long. One of the key points of interest about this particular trojan is that it has existed for two and a half years quietly collecting information. Any IT professional will tell you it costs a lot to maintain and to store the information it is gathering.

The group has been able to use the web to cloak its identity.

Remedies

Under normal circumstances, using caution and common sense goes a long way. Most of us are familiar with the term "think before you link." In other words, be wary of clicking on anything in a high traffic site like social networks. Also, it pays to observe the url displayed in the link and put it in the address line to connect.

But with this trojan, just surfing the site may allow your computer to become infected. So, in addition to common sense measures,

  • Install the latest version of your browser, e.g., Internet Explorer 7, Firefox 3, etc.
  • Keep anti-virus programs up to date and regularly scan your machine for malicious software, at least weekly - daily is better.
  • Carefully monitor online bank accounts for suspicious activity. RSA urges users to be wary if different forms of authentication such as a social security number or other details are asked for by their "bank."
  • Consider an Identity Monitoring and Restoration product to represent you if you become a victim.

RSA said it is co-operating with banks and financial institutions the world over to tell them about Sinowal. It also has passed information about the virus to law enforcement agencies.

If you would like additional information on Identity Theft Protection, please visit our web site.



Print   —   Rate it:  up  down  flag this hub

Comments

RSS for comments on this Hub

Rallie Rallis  says:
14 months ago

Thanks for info on the latest security problem we face. Can this Trojan Horse be enbedded on a download without a well know Internet Marketer knowing it's there?

gpbrewer profile image

gpbrewer  says:
13 months ago

Rallie: It appears that the trojan could infect your computer even if there was no download, just by surfing a site. Apparently, it takes advantage of browsers with security weaknesses in them. So if you have the most current addition of Internet Explorer or Firefox or AOL, and your regularly update your anti-virus software, you should be OK. Personally, I will also closely monitor my bank account for any unusual activity. A lot of work but we all must be vigilant. These are well organized, cyber criminals.

Greg

Becky Joubert profile image

Becky Joubert  says:
13 months ago

I'm a little "Pollyanna" so I don't like to think that negative things like this could happen to me, but I've picked up enough trojans while surfing to know that it catches you by surprise. It helps to be imformed.

Thanks for the info,

Becky Joubert

gpbrewer profile image

gpbrewer  says:
13 months ago

Thanks Becky! And, by the way, Adobe identified a security vulnerability this week and send out a updated Adobe pdf reader. Make sure you are using version 8.1.3

Joyce Jacobsen  says:
13 months ago

Thank you for keeping us informed with such great information. It's a little scary sometimes just being on the internet. Thanks again.

<a href="http://joycejacobsen.com/blog">Joyce Jacobsen</a>

Submit a Comment

Members and Guests

Sign in or sign up and post using a hubpages account.


optional


  • No HTML is allowed in comments, but URLs will be hyperlinked
  • Comments are not for promoting your hubs or other sites

Google Drive By Download Video

working