Phishers not making as much money as originally thought

Phishing is not as lucrative as generally thought, according to a report from Microsoft.

Phishing is not as lucrative as generally thought, according to a report from Microsoft.

Cormac Herley and Dinei Florencio, who both work in research for Microsoft, have written a report claiming that phishing is a low-paid, low-skills enterprise and the average phisher makes hundreds, not thousands, of dollars a year.

The researchers argue that public estimates of phishing losses are overstated and come from ‘unverified' numbers; they calculate that actual phishing revenue is around $61 million in the U.S. - nowhere near Gartner's estimates of $3.2 billion in 2007.

Herley and Florencio estimate that about 0.37 per cent of users are phished each year, and that only about half of them actually have their accounts compromised. They say the cybercriminals don't always get to convert that data before their servers are discovered, users change their passwords after realising their mistakes, or banks spot fraudulent activity.

Herley said: “The more automated, the lower the barrier to entry, and the lower the effective return. When it's automated, it becomes a low-skill endeavour, and low-skill jobs pay like low-skill jobs. And like any organised crime organisation, the foot soldiers don't make the big money. It's likely that the money from phishing is unevenly divided, with some doing way better than others.”

The report, meanwhile, concludes that the high volume of phishing activity demonstrates its lack of success, and that users should not consider phishing to be a non-issue.

The report said: “We would like to emphasise and re-emphasise that, even if the dollar losses are smaller than often believed, we believe that phishing is a major problem. There are many types of crime where the dollars gained by the criminal are small relative to the damage they inflict. This appears to be the case with phishing. If the dollar losses were zero, the erosion of trust among web users and destruction of email as a means of communicating would still be a major problem.”

Avivah Litan, vice president and analyst at Gartner, told Dark Reading: “They are assuming their economic theories apply here - there is no hard evidence that they do. Phishing remains one very effective means and end users are still falling for phishing attacks that are often combined with malware-based attacks.

“We also know that fraud losses are increasing, which is why there is so much demand for security and fraud detection products. Debating whether or not individual phishers can make as much money as they used to is frankly a somewhat-useless academic argument and does nothing to improve the fraud situation.”

See original article on scmagazineus.com
Copyright © SC Magazine, US edition
Phishers not making as much money as originally thought

What are your thoughts on this article? Add your comment below.

To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.

NOTE: You must be a registered member of SC Magazine to post a comment.

Click here to login | Click here to register
comments powered by Disqus
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read