Home / Industry

Open Phishing Season

For retailers and consumers, Cyber Monday marked the beginning of the online holiday shopping season. For cybercriminals, however, it marked the opening of their winter phishing season.

Here at MarkMonitor, we are currently seeing an uptick in cybercriminal activity targeting online retailers' brands. Linked here is an example of a phish attack involving a well-known national retailer.

Clearly, brand-based phish and malware attacks such as this one, possess great potential to harm consumers. They also pose a great risk to customer trust and loyalty in your brand. As a result, the range of advice which you can give to your customers to promote safe online holiday shopping is extensive. Customers should:

  • confirm emails from retailers which request their action through links and attachments
  • confirm retailers who are highly ranked in search engine results, but are obscure or little known
  • be wary of website download files
  • ensure an https connection when entering financial credentials into a website
  • use temporary credit card numbers
  • use up-to-date anti-virus/malware software
  • check their financial statements regularly

These are all useful recommendations. Unfortunately, the consumer attitude toward security, and the preventive actions they are willing to take, depends on the convenience of those actions. Consumers choose to shop online, after all, because they value convenience over other considerations, including concern about using their credit cards online.

When brand-based attacks harm consumers, they damage retailers' brands, customer relationships, and the trust which customers have in Internet channels. As a result, these attacks present a very real business problem.

We recommend that online retailers adopt a proactive security stance toward phish and malware. This approach should include adopting preventive measures against brand hijackings and attacks in the planning stages, quickly detecting attacks which are underway, immediately responding with layered security, and analyzing attack data to refine security strategy and tactics. By educating customers and putting in place a proactive security strategy against phish and malware attacks, retailers can ensure a more enjoyable holiday season for customers and retailers alike.

About MarkMonitor

MarkMonitor

MarkMonitor®, the world leader in enterprise brand protection and a Thomson Reuters Intellectual Property & Science business, uses a SaaS delivery model to provide advanced technology and expertise that protects the revenues and reputations of the world's leading brands. (Learn More)

Related topics: Cybercrime, Cybersquatting, Domain Names, Malware, Security, Spam, Web

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

Minds + Machines in 2014 and 2015

DNW Podcast Interview with Antony Van Couvering

TLD Registry and Right of the Dot Establish a Domain Name Industry "Dream Team"

"Chinese Domaining Masterclass" to be Presented at NamesCon Las Vegas in January 2015

Q3 2014 DDoS Trends: Attacks Exceeding 10 Gbps on the Rise

LogicBoxes Announces Automation Solutions for ccTLD

TLD Registry Wins Best Marketing Award at China New gTLD Roadshow

Update on Minds + Machines' Top-Level Domain Launches

ICANN Los Angeles Recap Webinar

TLD Registry Appoints First China General Manager, Mr Jin Wang

TLD Registry Opens China Headquarters in "China's Silicon Valley"

.nyc Goes Public to Brand the Big Apple

pink.host: Breast Cancer Awareness by Bluehost

3 Questions to Ask Your DNS Host About DDoS

Afilias Partners With Internet Society to Sponsor Deploy360 ION Conference Series Through 2016

Infographic: Where in the World Do Chinese People Live?

Neustar to Build Multiple Tbps DDoS Mitigation Platform

Mobile Web Traffic: A Dive Into the Data

Auctions Update: MMX Wins .law and .vip

The Latest Internet Plague: Random Subdomain Attacks

Sponsored Topics

Afilias

DNSSEC

Sponsored by
Afilias
dotMobi

Mobile

Sponsored by
dotMobi
Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
Verisign

Security

Sponsored by
Verisign