Reuters: Technology News | Thu May 11, 2017 | 2:46pm EDT:
France’s central bank on Tuesday said there had been an increase in phishing attempts using its name and logo and email addresses purporting to be Bank of France ones.
The Bank of France in a statement called the general public “to be very vigilant”.
Phishing Explained:
Phishing is the attempt to obtain sensitive information such as usernames, passwords, and credit card details (and, indirectly, money), often for malicious reasons, by disguising as a trustworthy entity in an electronic communication.
The word is a neologism created as a homophone of fishing due to the similarity of using a bait in an attempt to catch a victim. According to the 3rd Microsoft Computing Safer Index Report released in February 2014, the annual worldwide impact of phishing could be as high as $5 billion.
Phishing is typically carried out by email spoofing or instant messaging, and it often directs users to enter personal information at a fake website, the look and feel of which are almost identical to the legitimate one. Communications purporting to be from social web sites, auction sites, banks, online payment processors or IT administrators are often used to lure victims. Phishing emails may contain links to websites that are infected with malware.
Phishing is an example of social engineering techniques used to deceive users, and exploits weaknesses in current web security. Attempts to deal with the growing number of reported phishing incidents include legislation, user training, public awareness, and technical security measures. Many websites have now created secondary tools for applications, like maps for games, but they should be clearly marked as to who wrote them, and users should not use the same passwords anywhere on the internet.
Examples: (From Wikipedia)
Above is an example of a phishing email, disguised as an official email from a (fictional) bank. The sender is attempting to trick the recipient into revealing confidential information by “confirming” it at the phisher’s website.
Note the misspelling of the words received and discrepancy as recieved and discrepency.
Also note that although the URL of the bank’s webpage appears to be legitimate, the hyperlink would actually be pointed at the phisher’s webpage.