Forensic characteristics of phishing petty theft or organized crime?

Stephen McCombie*, Paul Watters, Alex Ng, Brett Watson

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference proceeding contributionpeer-review

18 Citations (Scopus)

Abstract

Phishing, as a means of pilfering private consumer information by deception, has become a major security concern for financial institutions and their customers. Gartner estimated losses in 2006 to phishing in the US were approximately USDS2.8 Billion. Little has been published on the forensic characteristics exhibited in phishing e-mail. We hypothesize that shared features of phishing e-mails can be used as the basis for grouping perpetrators using at least a common modus operandi, and at most, a level of criminal organization - i.e., we suggest that phishing activities are carried out by a small number of highly specialized phishing gangs, rather than a large number of random and unrelated individuals using similar techniques. Analysis of repeated phishing e-mails samples at a major Australian financial institution - using a criminal intelligence methodology - revealed that 6 groups, from a sample of 500,000 spam e-mails, could be uniquely classified by constructing simple decision rules based on observed feature sets, and that 3 groups were responsible for 86% of all incidents. These results suggest that - at least for the institution concerned - there appears to be a level of criminal organization in phishing attacks.

Original languageEnglish
Title of host publicationWEBIST 2008 - 4th International Conference on Web Information Systems and Technologies, Proceedings
EditorsJosé Cordeiro, Joaquim Filipe, Slimane Hammoudi
Place of PublicationHeidelberg
PublisherSpringer, Springer Nature
Pages149-157
Number of pages9
Volume1
ISBN (Electronic)9783642013447
ISBN (Print)9789898111265
Publication statusPublished - 2008
EventWEBIST 2008 - 4th International Conference on Web Information Systems and Technologies - Funchal, Madeira, Portugal
Duration: 4 May 20087 May 2008

Other

OtherWEBIST 2008 - 4th International Conference on Web Information Systems and Technologies
Country/TerritoryPortugal
CityFunchal, Madeira
Period4/05/087/05/08

Fingerprint

Dive into the research topics of 'Forensic characteristics of phishing petty theft or organized crime?'. Together they form a unique fingerprint.

Cite this