ALKHOBAR, 27 December 2005 — Nearly every week these CompuNet pages feature articles on information security. Unfortunately, some people don’t take such articles seriously. In the past, Arab News has received e-mails stating that providing such information is “alarmist” and merely serves the interests of IT security vendors. Begging to differ with such views, information security must be a priority for everyone in our increasingly networked world. It is sometimes difficult to show specific information security threats with a well-defined Saudi flavor, but on Sunday such an example arrived by e-mail. Samba Financial Group, one of the Kingdom’s top banks, became the latest victim of a phishing attack.
According to the Anti-Phishing Working Group, phishing attacks use both social engineering and technical subterfuge to steal consumers’ personal identity data and financial account credentials. Social-engineering schemes use “spoofed” e-mails to lead consumers to counterfeit websites designed to trick recipients into divulging financial data such as credit card numbers, account user names, passwords and ID numbers. Hijacking well-known brand names of banks, e-retailers and credit card companies, phishers often convince recipients to respond.
Sunday’s phishing attack against Samba was a little unusual due to its sophistication. The attacker had good knowledge of the Kingdom’s banking system and had nicely copied the Samba website. Excellent Arabic was used in the spoofed e-mail that launched the attack. A translation of the spoofed e-mail reads:
“Dear Customer: The Security Department in the bank would like to inform you that measures have been taken to increase the level of security in your Internet Banking Transactions and that is to confront the increasing attempts to illegally hack into the banking computers. To reach the more secure customer service area you have to complete the registration process. Click here to go to the authorization page. We would like to make you aware that it is very important to deal with the new security measures in a very serious manner and to view them right now. Best wishes. Security Department.”
Needless to write, clicking on the link to reach the “more secure” customer service area would be a very big mistake. There was a large clue, however, in the e-mail that a fraud was under way as the e-mail purportedly came from the website “fult.com.” Samba users should have been immediately suspicious of a supposedly Samba e-mail originating at a non-Samba site. Samba customers who had read the company’s “Internet Security” policy, prominently displayed at the Samba Online site (www.samba.com.sa) would have been aware of the potential for fraud. The security information from Samba states:
“Hoax or Phishing e-mails generally appear to be sent from a well-known entity. These pose great risk to your account as the originator of such e-mails are after your confidential personal information such as Passwords or PIN, ATM or Credit Card Number, Samba Account Number or Credit Card Validation (CCV) number. By clicking the hoax link, you will be exposed to background installations of hoax software or viruses. Do not provide what is asked and do not open attachments or click to the links in unsolicited e-mails, especially those asking for your sensitive information.”
The security information continues, “Samba does not send you any e-mail to your e-mail address that asks you to provide, update or confirm sensitive information such as your Online Banking ID, password, Identification Number or Credit Card Number. We notify you by sending you e-mail to your sambaonline inbox that could be accessed once you successfully sign-on the site.”
Despite such notices, there is the chance that some Samba customers were taken in by the scam. The attacker did his best to make the e-mail appear authentic. For example, Samba offers several online products including Samba Direct, Samba Online, Samba Access and Samba Tadawul. In the phishing attack, potential victims were directed to a link called, “sambaonlineaccess.com.” A quick check of Whois at Network Solutions showed that the domain sambaonlineaccess.com was registered on Sunday to a Mr. John Polheber. Whether the details of the registration are correct is a matter for the authorities to investigate.
If an individual clicked on the link before the Internet Services Unit at the King Abdul Aziz City for Science and Technology (KACST) blocked access to the site, an authentic looking registration form was available to fill in. The form requested user name, password and ID/iqama number. In a terrible twist, the registration form had a notice: “Please do not open unknown advertisement popup(s) for the prevention of computer viruses and fraud. For more information, please visit Samba information security tips.”
Additionally, in case a customer forgot user name or password information, the fraudulent registration form linked back to the official Samba site to assist the individual in obtaining that information. The phishing attack might have been even more successful if the criminal action had been launched either on a Thursday or during the upcoming holidays, when people often turn to online banking with brick and mortar resources unavailable.
As of Monday afternoon, the website sambaonlineaccess.com was still live and while it could not be accessed within the Kingdom, it could be accessed from other countries. Internet users generally check e-mail daily and there was the possibility that uninformed Samba Online users currently outside Saudi Arabia could have received the phishing e-mail, clicked the link to sambaonlineaccess.com and been scammed.
The Anti-Phishing Working Group advises that the number and sophistication of phishing scams sent out to consumers is continuing to increase dramatically. The group has some tips to avoid being taken in by such scams:
• Phishers typically include upsetting or exciting (but false) statements in their e-mails to get people to react immediately.
• Phishers typically ask for information such as usernames, passwords and credit card numbers.
• Phisher e-mails are typically not personalized, while valid messages from a bank generally are.
• Don’t use the links in an e-mail to get to any web page. Instead, call the company on the telephone or log onto the website directly by typing in the web address in a browser.
• Avoid filling out forms in e-mail messages that ask for personal financial information.
Additionally, regularly log into online accounts, several times monthly if possible. Check bank, credit and debit card statements to ensure that all transactions are legitimate. If anything is suspicious, contact the bank and all card issuers. Ensure that a computer’s web browser is up to date and security patches are applied before accessing online accounts.
For the average Internet user, phishing attacks are becoming more and more difficult to detect. Many people are just starting to take advantage of online services, such as banking, and may not be aware of the potential for fraud. Phishing attacks continue because in every attack some people will be fooled into giving up their personal or financial information.
If anyone makes an error in judgment and believes he or she has wrongly given out personal or financial information, time is of the essence. If you have been tricked into participating in a phishing scam, assume that you will become a victim of credit card fraud, bank fraud or identity theft. Get help!
• Report the theft of information to the bank as quickly as possible.
• Cancel bank accounts and credit cards.
• Change user name and passwords on all online accounts.
• If a national ID number or iqama number has been compromised, take direction from the police on how to proceed.
The Anti-Phishing Working Group estimates that there has been a 38 percent average monthly growth rate in phishing attacks. A year ago, most phishing sites were hosted on free services of major ISPs in the United States. Today, a huge percentage have migrated to foreign ISPs or personal computers that have been infected by malicious code, unbeknownst to their owners. The latest genre of phishing sites not only attempt to trick users into divulging personal information, but also download eavesdropping threats like Trojan horses and keystroke loggers onto visitors’ PCs. These malicious programs give hackers control of infected machines, enabling them to use compromised systems to further propagate phishing scams. To avoid detection, criminals also move their phishing sites from one IP address to another — often on an hourly basis. Everyone should install and/or update anti-virus and personal firewall software and run a full scan on installation and then regularly after that. Confirm every connection to a website the firewall allows.
Awareness is the key to stopping online theft of personal and financial data. Don’t take the bait and get caught by phishing. Be informed. Get the facts on phishing from www.antiphishing.org.
(Comments to [email protected].)

