
Okay, first off, let me apologize for the lameness of my title. My writers have the week off. It was a poor attempt of a parody of an outdated Nelly Song.
I read this week in the Tech & Gadgets Blog on MSN that Hotmail as well as Yahoo, Gmail, and AOL have all been targeted by phishing attacks over the weekend. The phishing attack harvested at least 10, 000 passwords from Hotmail and numerous other passwords from the other email sites.
I have had a Hotmail account since fifth grade. It was the first tool I used to communicate over the internet with my friends. I know that many people have had a Hotmail account for a long time. One of the practices that Microsoft recommends is for users to change their passwords every 90 days. However I did NOT know that. I have had the same password for my Hotmail account for about five years. This is one tip I urge you to follow after reading this blog.
Along with this advice here is a summary of the five tips from PC World that will help you avoid becoming a victim of phishing attacks:
1) Be skeptical. Don't give out personal information including your user name, password, or account numbers via email. Don't reply to suspicious emails and if you aren't positive that a message is legitimate assume it is not.
2) Contact directly. Whenever you do get an email from a "trusted" source that wants you to give them information or click on a link you should contact them directly. Go see them in person or contact them on the telephone.
3) Analyze statements. Check your bank statements for suspicious activity. Internet banking is a good tool here so you can check if you have suspicious charges or withdrawals. If anything turns up contact your financial institution.
4) Use current web browsers. The newest web browsers such as Internet Explorer 8 and Firefox 3.5 have built-in phishing protection. They can find malicious sites and warn you in advance.
5) Report attacks. If you think you are being a victim of phishing, report it. Report the suspicious emails to your ISP and to the Federal Trade Commission.
Some of these are common sense. Others I hadn't thought of. I had never thought of reporting suspicious activity to my ISP or the FTC. I don't really pay attention to phishing protection either. What about you? When's the last time you changed your password? Do you follow these steps? Have you recieved any suspicious emails?
