A recent study at Indiana University states that (simulated) phishing attempts were much more efficient when phishers purported to be "friends" of the same community. Overwhelming 72% of all addressees were willing to return personal data (their university ID and password) when they thought the phishers to be friends (a control group that received "normal" spam asking for the same data was less talkative (16%)).
Countermeasures are recommended as usual, but I think for most people this kind of problem is too abstract and they don't get the point that a user's mistrust is her best protection.
« On Order | Main | On The Course Of Time »
On Being Unsuspicious
TrackBack
TrackBack URL for this entry:
http://www.mabuse.de/cgi-bin/MT/mt-tb.cgi/74