Andrew Ellson
Enter our Snapshots of Summer photography competition

Civil servants exposed almost half of the British population to the threat of identity theft this week when they lost the names, addresses, dates of birth and account details of 25 million people. The debacle, which cost Paul Gray, the chairman of HM Revenue & Customs, his job, highlighted how little control we have over our personal data. But while the Government’s cavalier approach to information security has put millions at risk of fraud, security experts say that the greatest threat to our personal data and account details is online. Internet fraud is now so common that the House of Lords Science and Technology Committee recently branded the internet a lawless “Wild West”, while the US Treasury believes cyber crime is worth more than the illegal drugs trade.
GetSafeOnline.org, a joint initiative between the Government and the Serious Organised Crime Agency (SOCA), estimates that the average loss to cyber crime is £541. More worrying still, it says that one person in five knows nothing about internet security. Women are twice as likely as men not to know how to surf the web safely.
Methods of cyber crime fall broadly into two categories. In the first, fraudsters try to trick people into revealing account details and other personal data to steal money or create false identities. In the second, hackers break into a PC’s system to find these details or to sabotage the PC, making it slow or unusable. Con-men even hijack home computers to send spam to other people.
A common form of fraud is known as “phishing” because it involves con-men trawling the web to elicit account details. This is usually done through fake e-mails that look to be from legitimate companies such as eBay or Amazon. One recent example appeared to come from Revenue & Customs and suggested that recipients were due a tax refund of £172. The e-mail directed unsuspecting internet users to a fake website that appeared identical to the legitimate website and asked them to enter debit or credit card details so that the repayment could be credited to their account. People who followed the instructions will have had their account emptied or card plundered.
Experts believe that almost half of phishing thefts last year were committed by groups operating through the Russian Business Network, a web hosting company based in St Petersburg and run by a figure known as “Flyman”. Dubbed “the mother of cyber crime”, RBN has also been linked to child pornography, corporate blackmail, spam attacks and online identity theft. A report by Veri-Sign, one of the world’s largest internet security firms, suggested that Rock Group, a criminal gang specialising in phishing, used RBN’s network to steal about £75 million from bank accounts last year. RBN is also said to have developed fake software such as antivirus programs to dupe internet users into giving it access to their computers in the mistaken belief that they were protecting themselves.
Fraudsters also exploit our willingness to share personal details on social networking sites. One in four of the ten million Britons registered to Facebook, MySpace or Bebo has posted information such as their phone number, address or e-mail on their online profile, making them vulnerable to identity fraud. Tony Neate, the head of GetSafeOnline.org, says: “These details may provide rich pickings. Your date of birth and address is enough for someone to set up a credit card in your name.”
There are simple steps we can all take to protect ourselves and our computer from the myriad threats online. The first is awareness. “Reputable companies don’t ask customers for passwords or account details in an e-mail,” says Graham Cluley, a senior technology consultant at Sophos, an internet security company. “Even if you think an e-mail may be legitimate, don’t respond; ring the company or visit their website. Never click on links within dubious-looking e-mails; go to your web browser and type in the address.”
There are often telltale signs that an e-mail or website is a forgery. Fraudsters may have perfected web technology but they rarely master written English. Phishing e-mails and fake websites often contain spelling mistakes or poor grammar. The URL or internet address at the top of a web browser can be another giveaway. The addresses on most phishing websites differ from the genuine version. For example, the site purporting to be HMRC started with the web address gastager-weltreisen. de, suggesting that it is hosted in Germany, rather than the hmrc.gov.uk of the legitimate site.
There are simple ways to minimise the risk of hackers stealing your account details, passwords and personal details. Cluley says: “Be cautious about opening attachments and downloading files from e-mails or the internet, no matter who they are from; you may be infecting your computer with malicious spyware or viruses.” Spyware is software that infiltrates your PC to monitor your activity, scan personal information or give hackers control of your system.
Ensure that your computer has a regularly updated firewall and virus protection software. Microsoft offers Windows Vista users a free firewall, which should be adequate for most users. Free updates are available at www.windowsupdate.com. Companies such as Norton, McAfee and Symantec also sell automatically updated firewalls and virus protection software but there are also free alternatives such as Grisoft’s AVG, available for download at www.free. grisoft.com. For other options visit www.GetSafeOnline.org.
Internet shoppers can also check whether a website uses encryption technology to protect personal details before making a purchase. If the website is on a secure server it should start with “https://” (“s” for security) rather than the usual “http://”. Also look for a padlock symbol on your browser’s status bar. MasterCard’s SecureCode or Verified by Visa program offer another layer of protection. These secure payment systems require subscribers to enter a password when they make purchases with their cards at participating websites. Sadly, however, no amount of protection software or fancy electronic gizmos will protect you from the many “real world” scams that are increasingly conducted over the internet. Says Cluley: “Always have your wits about you when you go online.”
Win a luxury weekend to Newcastle and its neighbour Gateshead, find out more here
Risk, resilience and embracing new technology
Industry sectors news at a glance. Interactive heatmap, video and podcast
Discover the power of collective thinking. Submit a solution and be in with a chance to win a Media Hub Home Entertainment System
The inside track on current trends in the charity, not for profit and social enterprise sectors
Everything the Business Traveller needs to know to make a better trip
Make the most of the summer and enter our fabulous photographic competition, you could win a £5000 holiday
Corsica is an island of beauty and contrast, an ideal holiday destination
Enjoy further reading from Travel to Fashion, Business to Sport, discover more
Shortcuts to help you find sections and articles
The clever way to lease a new car is with Car leasing made simple™
2009
per month on 36-month
Personal Contract Hire (PCH)
2008
42850
Car Insurance
£24,250 - £30,346
MI5
London
£60,000
The Environment Agency
Bristol
Up to £90K
Boots
Midlands
OTE £85k
Credit Protection Association
Nationwide Opportunities
Completely London
Luxury Condo's in Manhattan with NYC views
The best new homes in Wimbledon?
Nationwide
Fabulous Cruise And Cruise & Stay Offers Including Virgin Atlantic Flights Prices Start From Only £699pp!
Last Minute Cruise And Cruise & Stay Offers. Med From £499pp, Caribbean From £699pp!
5 star quality at a 3 star price.
8 fabulous Canadian cities ...you won’t find cheaper
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times, or place your advertisement.
Times Online Services: Dating | Jobs | Property Search | Used Cars | Holidays | Births, Marriages, Deaths | Subscriptions | E-paper
News International associated websites: Globrix Property Search | Property Finder | Milkround
Copyright 2009 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.
I dont know if this helps much now-a-days but it should: -
1) Dont surf the net logged on as "administrator" type user; this would potentially allow malicious software to install software aimed at stealing or manipulating your sensitive data (passwords, usernames, credit card, etc.); surf the web using a "limited user" account without the ability to install software
2) When typing in sensitive data dont type it in normally, type characters out of sequence, e.g. if your password is "123" typing the "2", "3" & "1" would be logged by a key-logger (malicious software designed to record your keystrokes and thus reveal your sensitive data, while you use genuine websites) as "231"; just doing this with only 1 or 2 characters can make a difference.
This used to be of help in the early days.
Jack Sprat, Bristol, UK
Why no guidance about the many anti-phishing services available from Google, Yahoo or Mozilla? Why no guidance about new generation secure firewall routers like the Z100G from Checkpoint/ZoneAlarm? This advice is so last decade it is no wonder that British consumers are being ripped off.
If the UK does'nt get real about computer security it will be back to the quill pen pretty soon.
Nick, Charlotte, NC, USA
On Internet Explorer 7 the padlock symbol has been moved from the bottom status bar up to a position on the right of the address bar . It's function remains the same.
Robin Hector, worcester, United Kingdom