ALKHOBAR, 29 May 2007 — Fishing used to be an activity for lazy summer days, but those of us in the IT industry hardly ever think of it that way anymore. Now phishing (pronounced “fishing”) is the sport of thieves and when someone starts talking about phishing expeditions, it’s certain that fraud is involved.
There are lots of new kinds of phishing such as Spear Phishing and Spy Phishing. There’s also Phish Hopping and Schools of Phish. Banks are getting attacked by Spiny Devil Phish and financial institutions need a special type of tech doctor to eliminate a Phish Rash. Don’t worry about deciphering the intricacies of all of these. The important point here is that there is a growing sophistication on the part of cyber criminals. Their attacks are increasing, evolving and getting tougher to defend against.
Phishing is not the only form of fraud on the Internet. Any time there is an attempt to hijack a reputable brand, corporate image or corporate trademark — this is fraud. It can be blatant such as a website selling fake Rolex watches as genuine or it can be more subtle, such as a company illegally associating itself with another reputable company. Brand abuse on the Internet is a large and growing problem that can no longer be ignored. Corporate brands are constantly threatened by opportunistic or malicious acts including trademark infringement, unauthorized linking relationships and even “copycat sites.” In the end, consumers and legitimate enterprises suffer, and criminals profit and become bolder.
How did crime on the Internet get so out of control? The fact is that the World Wide Web was never designed to serve all the purposes it does today. The Internet was originally a means for scientists to share information in the spirit of positive collaboration. There was no thought of criminal intent and abuse. It was a virtual world where concepts such as inclusion and sharing were encouraged. Any regulation was simply to enhance cooperation.
The age of Net naiveté is long gone. Nations and organizations are working to create real world regulations to deal with virtual crime but the efforts are fragmented and public law enforcement resources are stretched. Online fraud attacks, such as phishing, are used by criminals to steal customer identities or to pitch fake services or counterfeit products. These attacks erode consumer confidence in online sales or self-service web portals. While victims blame the criminals, they typically also hold the targeted organization responsible and expect those organizations to leverage the latest technology to protect them from these scams. That’s why many enterprises are turning to a new group of “super heroes” to help fight fraud in the virtual world.
The team at MarkMonitor can’t leap tall buildings in a single bound, but their online fraud detection network is the most comprehensive in the industry. On a daily basis, MarkMonitor (www.markmonitor.com) identifies approximately 16 million suspicious events from data received from the top Internet service providers (ISPs), representing over 80 percent of consumers online. MarkMonitor uses proprietary technology to automatically scan and analyze information from a wide range of sources. The company’s aim is to combine its sophisticated detection technology with around-the-clock fraud monitoring to enable expedient prediction, prevention, detection and shut down of online phishing attacks.
Now what does this have to do with Saudi Arabia and the Gulf region? Actually, it turns out that according to MarkMonitor, the GCC is predicted to be the next big target of global phishers.
“Phishing began in the United States against online auctions and payment plans and then spilled over to the biggest credit cards. A year later phishers became more entrenched into the hacking schemes of systems and their programming ability skyrocketed. They went from targeting the largest financial brands to midrange and smaller players. Then they moved over to Europe. In our research into how the scams were developed, we discovered that some of the best hackers in these frauds are based in Kuwait. That gave us the indication that the Middle East will be the next region to struggle with cyber fraud,” explained Ihab Shraim, chief security officer (CSO) and VP, Network and System Engineering, MarkMonitor.
A Phish Kit, which is used to help create online frauds can be purchased for as little as $10, so it’s not difficult for a criminal to get the illegal operation up and running. The conditions are also right for successful online crime in the region. Connectivity is growing. Net services are attracting thousands of new consumers weekly. Network staff are in short supply. Local banks are hugely profitable and international financial operations such as Pay Pal have come into the area. This has not gone unnoticed by cyber criminals.
“Last year we began seeing the first phishing attacks against local banks. Now, every bank in the region has warnings on their websites about online crime,” said Mirza Asrar Baig, CEO, IT Matrix and regional partner of MarkMonitor. “Banks are attempting to promote awareness of Net fraud, but that’s only one part of the effort to fight crime online. With the growing sophistication of global criminals, the local financial institutions understand that they have to be proactive and move aggressively against these criminals. Any hint of weakness is encouragement to the phishers.”
The majority of banks in the Kingdom have already signed up with MarkMonitor and IT Matrix to guard their brands and reputations. What this means is that MarkMonitor has begun using its network resources to analyze online events involving the banks’ brands. Some of this analysis is an attempt to halt phishing attacks even before they start. For example, if a web domain name is registered, which is similar to the name of a local bank protected by MarkMonitor, the company then tags that URL and puts it under surveillance. If suddenly that new domain goes live with a website, MarkMonitor will move quickly to investigate the website for fraudulent activity and if that is found, shut it down.
“We have established contractual deals with most of the large ISPs across the world to shutdown illegitimate sites that misrepresent our customers,” said Shraim. “We shut down sites in 84 countries. Even websites in Russia and China are not out of reach. This is what we do for a living and our efforts have been very, very successful over the past three years. So far we have more than 10,000 shutdowns underneath our belt.”
Shraim emphasized that moves to shutdown a website are only taken when there is conclusive proof of fraudulent activity. That proof is produced for the ISP when shutdown is requested. That proof is also preserved so companies may prosecute violators if they choose. All MarkMonitor’s operations are overseen by a team of lawyers to ensure that they comply with all local and international regulations in their activities against alleged criminals.
“No on can claim that they can do something in minutes but our average has been very promising. In the United States we can shutdown sites operating fraudulently within four hours. In other countries it can take eight to 12 hours,” The MarkMonitor CSO advised. “There is a premise though when we put these numbers that the ISP must be open. You are dealing with criminals who work globally and they look for windows of opportunity such as weekends and special holiday seasons when ISPs and web hosts might not have normal staffing. Fortunately, we have developed a method to deal with such situations.”
MarkMonitor has created a patented-pending technical solution called dilution, which effectively injects inaccurate data into the website that is part of the fraudulent operation. The objective is not to bombard the site with data. The goal is to simulate the transaction of a consumer being phished. MarkMonitor’s solution provides properly formatted data such as credit card numbers, user IDs, passwords — whichever forms of information the phish itself has requested. For example if the phish is requesting six pieces of data, MarkMonitor’s data generators kick out six pieces of properly formatted data. Dilution allows MarkMonitor to “play” the phisher, giving the company time bring legal action to defeat the criminal.
There is another way to keep consumers away from the fraudulent websites. On Shraim’s recent visit to the region, he met not only with the local financial institutions, but also with some top level administrators of the region’s networks. It is hoped that these entities will soon be using information provided by MarkMonitor to quickly block access to fraudulent sites, so that consumers are immediately protected, even as actions are being taken to shut the sites down.
“Criminals are looking for the soft target,” explained Baig. “There is no 100 percent security but in most cases all that’s required to keep criminals from trying to break into your home is that your house is better protected than the neighboring ones. MarkMonitor offers enterprises the ability to aggressively protect their brands and their reputations and that deters criminals. If a criminal does choose to attack, then MarkMonitor has the ability to not only shutdown that fraudulent operation but also to produce evidence to enable a prosecution. Over half of the Fortune 100 turn to MarkMonitor for online brand protection and Internet fraud prevention and now Saudi banks have decided that this is the best protection for their good names as well.”
MarkMonitor Releases Brandjacking Index
MarkMonitor has released the company’s first Brandjacking Index, a quarterly report that measures the effect of online threats to brands. The Brandjacking Index investigates trends, including analysis of how the most popular brands are abused online and the industries in which abuse is causing the most damage.
The Brandjacking Index tracks the Top 25 brands from the 2006 Top 100 Interbrand study plus additional Interbrand ranked companies for business segment analysis. The cornerstone of the Brandjacking Index is the volume of public data analyzed by MarkMonitor using the company’s proprietary algorithms. MarkMonitor searches approximately 134 million public records daily for brand abuse in domain data and US and international Patent and Trademark Office data.
The phishing data MarkMonitor analyzed for the Index is based on feeds and fraud broadcasting from leading international Internet service providers (ISPs), e-mail providers and other alliance partners. The company has scanned billions of web pages since November 2004 and processes 16 million phishing e-mails daily.
“Fraud, counterfeiting and other abuses against brands are increasing in intensity and numbers as brands and businesses move online,” said Rose Ryan, Research Analyst, IDC. “Protecting brand reputations, customer relationships and revenues from online abuses is becoming as important to enterprises as securing their networks, data and systems from Internet-borne threats.”
Register for the report at www.markmonitor.com/brandjacking.

