Skip to content

Computer Science · Ch 11 — Societal Impact

Phishing and Fraud Emails

11.5.2

Phishing and Fraud Emails

Phishing is an unlawful activity in which fake websites or emails that look original or authentic are presented to a user in order to fraudulently collect sensitive and personal details — particularly usernames, passwords, banking and credit card details.

How phishing works — email spoofing

The most common phishing method is email spoofing: a fake or forged email address is used, and the user presumes the message comes from an authentic source.

The tell-tale pattern:

  • You receive an email from an address that looks similar to your bank or educational institution, asking for your information.
  • Look carefully and you will find the URL address is fake.
  • Phishers often use the logos of the original organisation, making the fake very difficult to distinguish from the real thing.

Phishing is no longer confined to email — attempts through phone calls and text messages are also common these days.

A safety warning

Accepting links from untrusted emails can be hazardous: such links may carry a virus or lead to a malicious website. Open an email link or attachment only when it comes from a trusted source and does not look doubtful.

(A) Identity Theft

Identity thieves increasingly use personal information stolen from computers or computer networks to commit fraud with the data gained unlawfully. What gets stolen is a user's identifiable personal data, such as:

  • demographic details,
  • email ID,
  • banking credentials,
  • passport details,
  • PAN,
  • Aadhaar number, and similar personal data.

The hacker then misuses this identity on behalf of the victim. Identity theft is a type of phishing attack whose intention is largely monetary gain.

Ways a stolen identity is exploited

The criminal can take advantage of a stolen identity in many ways; the book gives three named examples: …