Armour Comms launches industry leading secure Grou... » London: In direct response to customer demand, Armour Communications has announced the availability ... TDSi Supports Education Programme at IFSEC Inter... » Poole: Integrated security manufacturer TDSi will be sponsoring the Tavcom Training Theatre at IFSEC... 'POWER PLAYERS' INITIATIVE OPENS TO ENTRIES » Leading younger people from across the engineering services sector have a new opportunity to be reco... Multitone launches comprehensive EkoCare Communi... » Multitone Electronics plc has announced the launch of its new EkoCare range for healthcare facilitie... Momentum builds as Critical Communications World d... » Critical Communications World (May 16-18, Hong Kong) is the leading and most influential congress an... New initiative shows increasing importance of CSR » A major new survey on corporate social responsibility (CSR) is now open to electrotechnical busine... OF FOOLS OF THE MIDDLE BELT, ONE NORTH AND PASTORA... » SERIES: BUHARISM AND THE FIERCE URGENCY OF NOW A treatise on pastoral jihadism, islamism, arabism a... Commvault partners with Pure Storage » Cisco Live, Melbourne, AU and Tinton Falls, NJ: Commvault has announced the integration of its Commv... OF FOOLS OF THE MIDDLE BELT, ONE NORTH AND PASTOR... » A treatise on pastoral jihadism, islamism, arabism and cultural imperialism in Nigeria (Ephesians ... Where was Aisha Buhari when idiot Kumapayi flagr... » "Clip-clip..clip-clip...Did you not hear when BABA DAURA say women's place is in the kitchen?" ...



In a new blog post from PhishMe a recent IRS phishing scam is discussed. PhishMe has identified that the scam is a data-entry phishing attack, a classic tactic for stealing passwords and other credentials.


It’s about the time of year when people should be receiving tax refunds from the IRS, which gives attackers a great opportunity to craft phishing emails. PhishMe users recently reported a round of phishing emails purporting to be from the IRS about tax refunds.

Key takeouts from the post include:

Thanks to a coding error on the attackers’ part, we can specify how much we want back for our refund, as they defined this field as a text box. If the user wasn’t already tipped off that this is fake by the misspellings in the URL and data entry page, the ability to enter any figure into the refund field should be another indicator that this isn’t actually from the IRS.

We often see phishing attacks repeat themselves, and when investigating the content of the phishing website, we found the same exact text and format in an IRS phishing webpage in an archive that was dated March 14th, 2006.

Google Chrome blocked some of the domains as being phishing websites. To an extent, this can really help vulnerable users from getting compromised, but it should be viewed as a layer of protection in addition to a properly trained user base.

In a nutshell, even though monitoring/detection and prevention technologies have existed for a long time, the data entry attack has not died yet. Since the main vulnerability that the attackers exploit here is the human weakness, the best way to manage this threat is to augment a security technology strategy with proper employee training, education and user experience.