Andrew Ellson
Win luxury hampers plus Waitrose vouchers & guidebooks

Civil servants exposed almost half of the British population to the threat of identity theft this week when they lost the names, addresses, dates of birth and account details of 25 million people. The debacle, which cost Paul Gray, the chairman of HM Revenue & Customs, his job, highlighted how little control we have over our personal data. But while the Government’s cavalier approach to information security has put millions at risk of fraud, security experts say that the greatest threat to our personal data and account details is online. Internet fraud is now so common that the House of Lords Science and Technology Committee recently branded the internet a lawless “Wild West”, while the US Treasury believes cyber crime is worth more than the illegal drugs trade.
GetSafeOnline.org, a joint initiative between the Government and the Serious Organised Crime Agency (SOCA), estimates that the average loss to cyber crime is £541. More worrying still, it says that one person in five knows nothing about internet security. Women are twice as likely as men not to know how to surf the web safely.
Methods of cyber crime fall broadly into two categories. In the first, fraudsters try to trick people into revealing account details and other personal data to steal money or create false identities. In the second, hackers break into a PC’s system to find these details or to sabotage the PC, making it slow or unusable. Con-men even hijack home computers to send spam to other people.
A common form of fraud is known as “phishing” because it involves con-men trawling the web to elicit account details. This is usually done through fake e-mails that look to be from legitimate companies such as eBay or Amazon. One recent example appeared to come from Revenue & Customs and suggested that recipients were due a tax refund of £172. The e-mail directed unsuspecting internet users to a fake website that appeared identical to the legitimate website and asked them to enter debit or credit card details so that the repayment could be credited to their account. People who followed the instructions will have had their account emptied or card plundered.
Experts believe that almost half of phishing thefts last year were committed by groups operating through the Russian Business Network, a web hosting company based in St Petersburg and run by a figure known as “Flyman”. Dubbed “the mother of cyber crime”, RBN has also been linked to child pornography, corporate blackmail, spam attacks and online identity theft. A report by Veri-Sign, one of the world’s largest internet security firms, suggested that Rock Group, a criminal gang specialising in phishing, used RBN’s network to steal about £75 million from bank accounts last year. RBN is also said to have developed fake software such as antivirus programs to dupe internet users into giving it access to their computers in the mistaken belief that they were protecting themselves.
Fraudsters also exploit our willingness to share personal details on social networking sites. One in four of the ten million Britons registered to Facebook, MySpace or Bebo has posted information such as their phone number, address or e-mail on their online profile, making them vulnerable to identity fraud. Tony Neate, the head of GetSafeOnline.org, says: “These details may provide rich pickings. Your date of birth and address is enough for someone to set up a credit card in your name.”
There are simple steps we can all take to protect ourselves and our computer from the myriad threats online. The first is awareness. “Reputable companies don’t ask customers for passwords or account details in an e-mail,” says Graham Cluley, a senior technology consultant at Sophos, an internet security company. “Even if you think an e-mail may be legitimate, don’t respond; ring the company or visit their website. Never click on links within dubious-looking e-mails; go to your web browser and type in the address.”
There are often telltale signs that an e-mail or website is a forgery. Fraudsters may have perfected web technology but they rarely master written English. Phishing e-mails and fake websites often contain spelling mistakes or poor grammar. The URL or internet address at the top of a web browser can be another giveaway. The addresses on most phishing websites differ from the genuine version. For example, the site purporting to be HMRC started with the web address gastager-weltreisen. de, suggesting that it is hosted in Germany, rather than the hmrc.gov.uk of the legitimate site.
There are simple ways to minimise the risk of hackers stealing your account details, passwords and personal details. Cluley says: “Be cautious about opening attachments and downloading files from e-mails or the internet, no matter who they are from; you may be infecting your computer with malicious spyware or viruses.” Spyware is software that infiltrates your PC to monitor your activity, scan personal information or give hackers control of your system.
Ensure that your computer has a regularly updated firewall and virus protection software. Microsoft offers Windows Vista users a free firewall, which should be adequate for most users. Free updates are available at www.windowsupdate.com. Companies such as Norton, McAfee and Symantec also sell automatically updated firewalls and virus protection software but there are also free alternatives such as Grisoft’s AVG, available for download at www.free. grisoft.com. For other options visit www.GetSafeOnline.org.
Internet shoppers can also check whether a website uses encryption technology to protect personal details before making a purchase. If the website is on a secure server it should start with “https://” (“s” for security) rather than the usual “http://”. Also look for a padlock symbol on your browser’s status bar. MasterCard’s SecureCode or Verified by Visa program offer another layer of protection. These secure payment systems require subscribers to enter a password when they make purchases with their cards at participating websites. Sadly, however, no amount of protection software or fancy electronic gizmos will protect you from the many “real world” scams that are increasingly conducted over the internet. Says Cluley: “Always have your wits about you when you go online.”
Read the training tips and advice that helped our London Triathletes
Times Online's new TV show helps you make the right decisions for your pet
Read our exclusive 100 Years of Fleming and Bond interactive timeline, packed with original Times articles and reviews
The latest travel news plus the best hotels and gadgets for business travellers
Shortcuts to help you find sections and articles

A treasure trove of baubles, booty and stylish quests


2007
£47,995
2008
£42,945
06/2006
£40,850
Great car insurance deals online
£33,000
Macmillan Cancer Support
Central/South West
£50k
NHS
Nationwide
£
£30k OTE
Meltwater News
Nationwide
circa £70k
Central Office of Information
London
5% below developer pre-launch price!
Luxury Appts, beautiful gardens w/ Thames views
Great Homes Available on a shared Ownership Basis
Great Investment, River Views
Visit the ‘entertainment capital of the world’
at great sale prices!
Christmas Cruises
From only £995pp
APTs East Coast now from only
£2425pp.
Great travel insurance deals online
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times. Globrix Property Search - find property for sale and rent in the UK. Visit our classified services and find jobs, used cars, property or holidays. Use our dating service, read our births, marriages and deaths announcements, or place your advertisement.
Copyright 2008 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.
I dont know if this helps much now-a-days but it should: -
1) Dont surf the net logged on as "administrator" type user; this would potentially allow malicious software to install software aimed at stealing or manipulating your sensitive data (passwords, usernames, credit card, etc.); surf the web using a "limited user" account without the ability to install software
2) When typing in sensitive data dont type it in normally, type characters out of sequence, e.g. if your password is "123" typing the "2", "3" & "1" would be logged by a key-logger (malicious software designed to record your keystrokes and thus reveal your sensitive data, while you use genuine websites) as "231"; just doing this with only 1 or 2 characters can make a difference.
This used to be of help in the early days.
Jack Sprat, Bristol, UK
Why no guidance about the many anti-phishing services available from Google, Yahoo or Mozilla? Why no guidance about new generation secure firewall routers like the Z100G from Checkpoint/ZoneAlarm? This advice is so last decade it is no wonder that British consumers are being ripped off.
If the UK does'nt get real about computer security it will be back to the quill pen pretty soon.
Nick, Charlotte, NC, USA
On Internet Explorer 7 the padlock symbol has been moved from the bottom status bar up to a position on the right of the address bar . It's function remains the same.
Robin Hector, worcester, United Kingdom