Welcome to the Password Coach Cyber Security Training Academy – Module 6 – The tell-tale
signs of a scam website.
Scam websites stick out a mile when you know what to look for.
In this module, we'll look at how scammers create phony websites to install damaging
viruses, trick us into handing over sensitive data such as account numbers and passwords,
and pull off a good old-fashioned con-trick.
At the end of this module, you will know the common characteristics of a scam website,
and be equipped to spot a phoney the second that you see one.
In July of 2017, Google reported that it had detected over 1 million malicious and scam
websites operating on the web.
That's up over 300% since 2014.
Scam websites are an increasingly popular way for scammers to hit us, with thousands
of new ones popping up each and every day.
Scam websites fall into three categories:
Phishing websites – which imitate legitimate websites and attempt to con us into handing
over sensitive data such as account numbers or login credentials.
Rip-off websites – which peddle fake products and services, often way too good to be true
Malware websites – which automatically install malicious software designed to capture sensitive
data (such as banking details), take control of our devices or hold our data to ransom.
From here, we will cover off the 7 tell-tale signs of a scam website and investigate a
set of checks that we can apply to ensure that we are always on the lookout for a scam.
First up, let's look at how to spot scam website links.
To get us to visit their scam websites, scammers will send us links in their messages
Links are those parts of a message that take us some place else when we click on them.
Links can appear as highlighted text, or as a clickable button or image.
Links are increasingly dangerous because scammers have found ways to infect our devices automatically.
All that we need to do is to click on a malicious link in an email, text, chat or social media
post and we could get infected.
To assess the safety of a link, we need to know where that link is going to take us.
Before we can do that, we need to understand the anatomy of a link.
Links come in two parts:
The first part is the description – i.e. the text that we see displayed on the screen
The second part is the destination - i.e. the place that we are going to be taken when
we click on the link's description.
By default, the link's destination is hidden.
Because a link's description can be absolutely anything, scammers will use the description
to try and trick us into thinking that the destination is safe and legitimate.
This is why it is critical to review both the description and the destination before
clicking on any link.
To reveal a link's destination, we simply hover the mouse pointer over the link (without clicking)
In a browser, the link's destination will be displayed in the bottom left corner of
the window.
In an application, such as Microsoft Outlook or Apple Mail, the destination will be displayed
in a popup box close to the link.
On a mobile device, the link will be displayed in a popup box, but only if we tap and hold
down on the link.
Be sure not to click on the link until 100% certain of the legitimacy of the destination
URL.
Before moving on to look at the checks that we need to make to determine the safety and
legitimacy of a website, let's look at a couple of ways in which scammers will use
links to try and trick us into clicking.
Let's quickly review a few link spoofs.
Link Spoof #1 The link destination cannot be confirmed
To make sharing on social media easier, companies such as Google and Twitter provide a 'link
shortening' service that will chop down a long and cumbersome URL into something more
compact and manageable.
When we click on a shortened URL, we will automatically be routed to the original, unshortened
destination.
The problem with shortened URLs is that the hover technique that we use to assess the
safety of a link doesn't work.
When we hover over the description of a shortened link, all that we can see is the shortened
link itself – we have no way of determining the final destination, and so the safety,
of the link.
Shortened links are commonly used by legitimate organisations, but they are also used by scammers.
Given that simply visiting the wrong website can result in a malware infection, we should
never click on a link unless we are 100% sure of the legitimacy of the destination.
To find out how to reveal the destination of some of the more common types of shortened
links, search for 'shortened link checker' using your favourite search engine.
Link Spoof #2 The link's description and destination are
wildly different
In a legitimate link, the description and the destination should be aligned.
This means that the destination should make sense given the description.
Either the destination is a letter for letter match with the description, or the destination
is related to the description in some meaningful and credible way.
If the description and the destination are wildly different, then this is a tell-tale
sign of a scam link.
Scammers will use all manner of URL spoofs to try and get us to visit, or interact with
their scam websites.
It is our job to safety-check the URL the instant that we see it…
either in a link …
or at the start of a visit.
Globally, there are about 700 legitimate websites that scammers are attempting to imitate.
For every single one of those 700 websites, there is 1 legitimate URL
and about 400 or so scam URLs
Remember, just because a recognised company name appears somewhere in the URL,
it doesn't make that URL safe and legitimate.
This is why we always need to be on our guard, and ensure that we are…
100% certain of the safety of a link's destination URL before clicking…
and 100% sure of the legitimacy of a website's URL before interacting with that website
Scam websites are easy to spot when you know what you are looking for.
From here we will cover off a series of checks that we can make to test the safety and legitimacy
of a website URL – either in a link or in the browser's address bar.
Check #1 Is the website secure?
One the easiest ways to assess the safety of a website is to check the website's protocol.
You will recall from our URL Unpacking technique that the protocol is the very first part of the URL,
located before the :// punctuation mark.
Where website safety is concerned, there are two protocol values that we need to care about...
Http
And https
Https is secure.
Http is not.
The S stands for Secure
The legitimate websites of large (and often imitated) organisations are always secure.
Scam websites are sometimes secure, but more often insecure.
If a website that appears to be part of a large and credible organisation is using the
insecure http protocol, then that is a tell-tale sign of a scam.
When visiting a website, we can also double-check that it is safe by referring to the website's
safety indicators located in the top left of the browser's window (the address bar).
Specifically, we will look for …
The presence of a locked padlock icon
The word 'Secure' or the company name presented to the left of the website address
The presence of 'https' protocol
Before doing anything on the website, we need to confirm that all three safety indicators
are present and that they are coloured a friendly green.
Much like traffic lights, we only go on green.
Not all web browsers display website security information in the same way.
If your current browser is not displaying all three green security symbols when you
visit a secure site like Google or ebay, then,
for the sake of clarity and peace of mind,
you may want to consider switching to one that does (for example, Google Chrome).
Check #2 Is the website address safe and legitimate?
In module 5, we looked at some of the sneaky tricks that scammers use to disguise the identity,
and location, of their scam websites.
In this second check, we are going to look for signs that the website's address has
been spoofed using one or more of these tricks.
One of the most obvious signs of a scam is a website address that isn't the real deal.
So let's remind ourselves of how scammers impersonate legitimate websites.
And do a quick recap of the Top 10 website address spoofs.
Website Address Spoof #1.
Misspelling the organisation's name.
Slightly.
Website Address Spoof #2.
Stuffing an organisation's name in the Subdomain.
Website Address Spoof #3.
Stuffing an organisation's name in the Domain
Website Address Spoof #4.
Putting the country code in the Domain
Website Address Spoof #5.
Putting the organisation's name in the Page.
Website Address Spoof #6.
Using someone else's hacked website.
Website Address Spoof #7.
Omitting the Subdomain (a.k.a. the punctuation hack)
Website Address Spoof #8.
Using a cute Top-level Domain.
Website Address Spoof #9.
Padding out the website address with symbols and numbers.
Website Address Spoof #10.
The URL includes a bunch of numbers.
That brings us to the end of our recap of the Top 10 website address spoofs.
Let's now move onto Check #3, and look for the presence of fake social media buttons.
Many websites include social media buttons, which allow content to be easily shared
with friends and followers
To make a scam website look credible,
scammers will include social media share buttons on their scam websites.
But because the scammers have no social media presence,
the buttons are going to be fake
i.e. they cannot be clicked and they cannot be used to share a page in the normal way.
To check the legitimacy of a social media button,
check the destination URL by hovering over the button.
Do you see a credible destination being displayed?
The presence of fake social media buttons is a tell-tale sign of a scam website.
Check #4 Are there any contact details on the site?
Websites that don't have any means of contact aren't normal.
If we can't find any credible contact details, then we are looking at a tell-tale sign of a scam.
Check #5
Are there any reviews, testimonials or references to established publications?
Websites, especially e-commerce sites, will typically post reviews and testimonials
from happy customers. But are they believable and real?
If a site is touting a series of publications that it has been 'featured in',
do those links go to a real article on the publication's website? Or are they just fake?
Fake customer reviews, testimonials and publication references are all tell-tale signs of a scam website.
Check #6 Does the website look right?
In module 3, when we looked for the tell-tale signs of a scam message, we asked
'Does the message look right?'.
The same question applies when safety-checking a website…
Does the website look and feel right?
Does it use the right colours and fonts?
Are there any spelling mistakes or grammatical errors?
Does the logo look fake?
Is the website peddling an offer that is believable?
Or is it too good to be true?
If the offer is too good to be true, then we are looking at a tell-tale sign of a scam website
Check #7 How does the website make you feel?
Scammers often use a sense of urgency to get us to act impulsively.
The item's stock may be dangerously low or the super-awesome deal on offer may end
today.
There may only be 2 tickets left.
If the website is attempting to create a sense of urgency, then that is a tell-tale sign
of a scam.
Scammers will also target our emotions to trick us into doing what they want us to do.
If the website is appealing to emotions such as fear, doubt, curiosity, greed, excitement,
guilt, sympathy or desire, then these are all tell-tale signs of a scam.
Excellent work!
You now know what a scam website looks like, and have the skills to avoid being taken in
by a scam.
In the final module in this course, we will focus on identifying and avoiding the most
dangerous part of a scam message - the attachment.
No comments:
Post a Comment