Proofpoint: Security, Compliance and the Cloud

January 13, 2009

Phone Phishing: Coming Soon to a Hotel Near You

Night-audit We regularly warn consumers and enterprises about the dangers of email-based phishing attacks and provide tips for staying safe online, but it's easy to forget that phishing emails are really just an evolution of the classic confidence scam. The social engineering techniques that are behind every sort of phishing scam (whether it's a Nigerian "419" scam or a more sophisticated spoof aimed at online banking users) have analogs in the real world.

A friend in the travel and tourism industry told me about an identity theft scam that hit one of their hotels—and a hotel guest—in the last couple of days:

During the night shift, the hotel received a phone call asking for "Mr. Jones." The night auditor working the font desk transferred the call to a room where one "Mr. Jones" was, in fact, staying.

When the guest answered the call, the caller identified himself as the night auditor and explained that the hotel was having trouble with the guest's credit card... and could he please verify the card number, expiration date, etc.

The next day, Mr. Jones was contacted by his credit card company because they had seen suspicious use of the card -- to the tune of several thousand dollars.

Now, if you received an email like this, you wouldn't answer it, of course. But I wonder how many of us—awakened in the middle of the night—might not bat an eye at providing that info over the phone.

The hotel has since adopted stricter phone screening measures to avoid this type of thing in the future, but it's always good, as a consumer, to be reminded of how scams work... and that, really, you can't be too careful when it comes to protecting personal information. Security begins with education.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a010535f33a5b970c010536c40df9970b

Listed below are links to weblogs that reference Phone Phishing: Coming Soon to a Hotel Near You:

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Archives

Blog Search

Email Security Gateways, 2011

Magic Quadrant

Tweets

What people are saying right now about us.

©2012 Proofpoint, Inc.
threat protection: Proofpoint Enterprise Protection compliance: Proofpoint Enterprise Privacy governance: Proofpoint Enterprise Archive secure communication: Proofpoint Encryption