Skip to content

Informatics Practices · Ch 6 — Societal Impacts

Phishing and Fraud Emails

6.6.2

Phishing and Fraud Emails

Phishing is an unlawful activity in which fake websites or emails that look original or authentic are presented to a user in order to fraudulently collect sensitive and personal details — particularly usernames, passwords, and banking and credit-card details. The most common phishing method is email spoofing, where a fake or forged email address is used and the user presumes it comes from an authentic source. You might, for example, receive an email from an address that looks like your bank or your educational institution asking for your information — but a careful look reveals the URL address is fake. Phishers often use the logos of the original organisation, making the fake very difficult to tell from the real. Phishing attempts through phone calls or text messages are also common these days. …

(A)

Identity Theft

Identity thieves increasingly use personal information stolen from computers or computer networks to commit fraud with the unlawfully gained data. A user's identifiable personal data — demographic details, email ID, banking credentials, passport, PAN, Aadhaar number and other such personal data — are stolen and then misused by the hacker on behalf of the victim: the criminal acts in the victim's name.

The textbook classifies identity theft as one type of phishing attack, and its intention is largely monetary gain. Once an identity is stolen, there are many ways a criminal can take advantage of it. The book gives three examples:

  • Financial identity theft — the stolen identity is used for financial gain (for example, transacting or borrowing as the victim).
  • Criminal identity theft — criminals use a victim's stolen identity to avoid detection of their own true identity, so the trail points to the victim instead of the offender.
  • Medical identity theft — criminals seek medical drugs or treatment using a stolen identity. …