Articles
Back

The Dangers of Internet Phishing: How to Protect Yourself from Fraud and Identity Theft

Phishing is one of the most widespread and insidious types of Internet fraud. Its aim is to trick the user out of personal data (authorization data, bank card numbers and other confidential information) and, ultimately, money.

What Are the Dangers?

Fake websites are usually distributed in the form of links via email or messengers. Scammers are masterful at designing such messages, copying the style of real organizations as much as possible. They choose the most popular companies and resources - social networks, online stores, banks, streaming services or government agencies. In these messages they refer to the questions that might be most relevant or concerning for users.

Another type of phishing is cloning one’s friends or colleagues’ social networks and messengers accounts. In this case, scammers copy all of the user’s publicly available information and photos and then try to attract subscribers to the fake site, justifying it with an explanation that the previous account has been hacked. From bad to worse: subscribers receive messages with a phishing link, which, for example, asks them to go and support a mutual friend in voting, as well as to distribute this link to their own contacts.

The main problem is that there is no software that guarantees 100% protection against phishing. It all depends on the potential victim, i.e. whether the person will be able to recognize the fake in time and not fall for the scam.

How to Recognize Phishing?

Phishing emails use social engineering techniques, that is, they lure the recipient with gifts and bonuses, intimidate with urgency or authority, press on a sore spot or arouse curiosity. Even if it's hard to immediately understand what emotion the message is trying to evoke, don't rush to respond or follow the instructions in the message - look for the important details first.  

For example:

  • The subject line of the email is as eye-catching as possible. For example, unprecedented discounts, promotions, compensation, account hacking or blocking. 
  • An urgent call to action. The main marker words are "urgent", "faster", "discount only today". 
  • A strange sender address. A jumble of random letters and numbers or a strange domain in the sender's email address.
  • A link in the email to some obscure domain address or an attached document with popular extensions (e.g. installation files (.exe, .scr, .msi, .com, .dmg, .apk), Microsoft Office documents (.doc, .docx, .xls,.xlsx, .ppt, .pptx, .rtf), archives (.jar, .zip, .rar), and .pdf files).

If you notice several or even one of these “bait” emails, it's most likely a phishing mass mailing email.

How Can I Protect Myself? 

If you have received an unexpected email from an organization or online shop, or a message from a friend you haven't written to in a while, you should be wary. If possible, check your accounts, contact the sender by other means, and check whether they have actually written the message. For example, a message from your bank can be verified by calling the phone number on the back of its plastic card. Go to the social network by typing the address manually. Check the information about the drawing on the company's official website. However, under no circumstances should you follow links or open attachments unless you are sure they are genuine.

It is particularly important to be careful during some mass events that generate excitement and widespread interest. You can also encounter a fake website in a search engine, for example, when entering very popular queries for goods or services. Therefore, contact only trusted resources, do not fall for super tempting offers and low prices. Always try to analyze links (URLs) - pay attention to the presence of the https security protocol and the lock icon used by trusted resources. Although this cannot be considered a 100% security guarantee, the absence of an "s" at the end of the http protocol and the lock icon is a clear warning of the lack of enhanced security measures.

When making online purchases, the most important advice is to avoid making prepayments on unverified sites, and to use a dedicated bank card for online payments.

And remember, even if you clicked on a link and realized in time that it is a phishing site, never enter your personal data and do not try to authorize on this site. One of the best ways to protect yourself from phishing is to switch to passwordless methods of logging into accounts. For example, for VK ID, we recommend using OnePass as your only login method.

If you still use a password to log in to the service, use strong passwords (more than 12 characters with numbers, symbols and letters in different cases, without names, dates of birth and numerical sequences), store them in password managers and make sure you enable two-factor authentication. And remember, if you suddenly notice suspicious activity on your account, immediately change your password and/or terminate third-party sessions to thwart any malicious attempts.