Alert! Alert!
I never, I mean NEVER, do it. You probably don’t either, but with potentially hundreds of thousands, if not millions, of messages hitting consumers over the Internet, who knows how many individuals fall for it.
Regardless of the entreaty, the wording, or even warning that it is required, I will not give my Social Security number in response to Internet inquiries.
It’s called phishing, an egregious method of stealing a victim’s identity, and it is rampant.
I am warning about this because last week, in a single day, I received three attempts to steal enough of my personal data to allow the crooks to access my brokerage account and my bank account.
The filters I use with my e-mail identified the senders’ messages as spam, although not all filters will do that. Even without the [SPAM] label in the subject line, it was easy to see that there was something screwy about the messages. Although they appeared authentic, each having the logo of the financial institution (Smith Barney, Washington Mutual, and Regions Bank), the body of the message was exactly the same for each:
(Official corporate logo here)
Dear (name of financial institution) customer,
Technical services of the (name of financial institution) are carrying out a planned software upgrade.
We earnestly ask you to visit the following link to start the procedure of confirmation of customers’ data.
(Author’s note: The invalid www: Internet address used in the instructions was inserted at this point, but is being intentionally omitted in this column.)
This instruction has been sent to all (name of financial institution) customers and is obligatory to follow.
Customers support service
If the recipient of the e-mail clicked on the link to the fake site, a series of questions would be asked, in which he would be called on to respond by providing his account number, log-in, password, and personal identification number. If he did that, bingo! The operators of the scam site could immediately access his account, creating mischief at best, disaster at worst.
But suppose after entering the fraudulent site he realized what was happening and closed the link. He saved himself some potentially very serious problems, but didn’t escape without doing minor damage.
By opening the site he confirmed to the sender that the e-mail address to which they sent the message was valid, inviting additional attempts. He can expect to receive more e-mail efforts at stealing his identity, although it is probable that the format and style of the future messages will be different.
How pervasive is this? How bold are the bad guys? Try this one: They are now phishing with e-mails that appear to be from (I am NOT making this up) the Internet Crime Complaint Center, which is a partnership between the FBI and the National White Collar Crime Center. Check it out at their Web site www.ifccfbi.gov. (I encourage you to visit this site regularly to stay informed of what scams are being perpetrated via the Internet, as well as being able to report fraudulent Internet activity.)
Folks, it is getting spookier. In the middle of writing the last paragraph my computer signaled that I received mail, so I checked my in-box. Two more of the damned things!
Be careful; make certain that your employees, family and friends know what is happening. Help them avoid what is becoming a major national financial problem – identity theft.
Last month, before all this e-mail garbage happened, I promised to write this column about additional screens that serious investors could use in their selection process. I felt that the e-mail subject was more important.
After all, if someone scams you out of your money, what are you going to invest with?
Next month, the screens – I promise.
Clark Davis is a 34-year investment veteran and CEO of Saint Louis Investment Advisors, a specialized money-management company.