Many college students are newbies at managing their own finances, making them attractive targets for a new type of phone scam that aims to steal their money and personal information.
The scam is a variation of the “imposter” telephone scam:
The scammer calls college students and claims to be from the FBI or
other U.S. government agency, “spoofing” a local telephone number to
appear legitimate on the receiver’s caller ID. The scammer tells the
student he or she owes money on student loans, unpaid taxes, or
outstanding parking tickets. He then threatens the student with arrest
or failure to graduate unless the student immediately settles the fees.
Payments are required via untraceable methods such as MoneyGram, some
other preloaded debit gift card, wire transfer, or cashier’s check.
According to the FBI, the scam targeting college students has occurred in over eight states so far: North and South Carolina, Georgia, Oklahoma, Kentucky, Nebraska, Montana, and Washington.
While the criminal’s primary goal is to coerce college students into
sending money, there’s a second, more pernicious scam going on: to trick
students into sharing their personal information to supposedly help
expedite the process. That can easily morph into ID theft.
Phone Protection 101
It’s never too early to learn how to spot and avoid common scams. Start by following these three steps:
Don’t believe what you hear. Government agencies will never call
you out of the blue—not the FBI, the IRS, financial institutions, or
the judicial system. They will never ask for payment or personal
information over the phone.
Don’t believe what you see. Caller ID can be—and
often is—spoofed. If you want to verify a call, look up the website or
telephone number yourself. Don’t assume that the link or customer
service number provided is legitimate; it may lead you right back to
scammers.
Do check your credit report regularly. Signs of identity theft often first show up in your credit report. The government-sanctioned website AnnualCreditReport.com
allows you to get a free copy of your credit report from each of the
three major credit reporting companies every 12 months—in other words,
once every quarter. Reviewing your reports regularly helps you spot
signs of identity theft early. You will be asked to supply your date of
birth and Social Security Number.
Tax day is a little more than a month away, which means phishing season is in full swing
.
View photo
FILE - In this Feb. 27, 2013,
file photo illustration, hands type on a computer keyboard in Los
Angeles. As tax day nears, phishing season is in full swing. The IRS
says it’s seen a “surge” in phishing emails in 2016. And thieves are
also baiting special hooks for payroll and human resources workers, in
hopes of snagging a company’s entire stash of employee information. (AP
Photo/Damian Dovarganes, File)
NEW YORK (AP) -- Tax day is a little more than a month away, which means phishing season is in full swing.
The IRS says it's seen a "surge" this year in
phishing emails, with thieves baiting special hooks for payroll and
human-resources workers in hopes of snagging a company's entire stash of
employee Social Security numbers and other personal information.
Meanwhile,
tax-season phishing attacks against individuals are also up. Last
month, the IRS said it had seen a quadrupling of phishing- and
malware-related incidents for this year's tax season.
Experts warn
that phishing emails often masquerade as legitimate communication from
your bank, human resources department or email provider. But in reality,
they're part of a scheme designed to steal the confidential information
stored in your computer, or to gain access to the network it's attached
to. And this time of year, that information can be used to file a false
tax return.
While people are more aware of the danger of phishing
more than ever before, the lures continue to evolve and increase in
sophistication, making it tough for the average person to discern which
emails are legitimate and which ones aren't.
Here are a few answers to common questions about phishing:
___
WHY IS IT SO BAD THIS TIME OF YEAR?
Phishing
peaks during tax season, partially because it's a time of year that
many people are accustomed to entering their most personal information —
such as their Social Security number or bank account information — on
websites, Satnam Narang, senior security-response manager for security
software maker Symantec, says.
Thieves can then use that captured information to file a false return.
Phishing
also spikes around Christmas, with attacks in the form of fake delivery
notifications. Thieves also often tie phishing emails to major sporting
events, or natural disasters like overseas earthquakes, says Raj
Samani, chief technology officer for Europe, the Middle East and Africa
at Intel Security.
"They're very much up with the latest news and
information," Samani says. "If they can spend a little more time and get
a 0.1 percent increase in click-throughs, then their campaign becomes
hugely more profitable and successful."
___
WHAT'S THE DIFERENCE BETWEEN PHISHING AND SPEAR FISHING?
Narang
likens phishing to a person casually throwing a rod in a lake and
waiting for a bite. Phishing emails don't contain a lot of specifics,
but are quick and easy to send out in mass quantities.
"Spear
phishing" is much more targeted and personalized. The people behind
those attacks spend time researching their targets in order to create
highly customized emails that look much more legitimate and are much
more likely to be clicked on.
The rise of social media has made
this a lot easier. Thanks to Facebook and Twitter, details including a
person's place of employment, where they bank, like to shop and the
names and ages of their children are just a few clicks away.
___
WHAT OTHER RED FLAGS SHOULD I BE ON THE LOOKOUT FOR?
In
an effort to get more people to click on a link before thinking about
the possible consequences, many phishing emails will give an impression
of scarcity, or include some kind of time limit.
For example, an
email made to appear to be from a person's bank or email provider may
state that if that person doesn't click on the enclosed link within 24
hours, they will be locked out of their account.
And while poor
English and long, complex web links were previously sure signs of
phishing, they're not as prevalent anymore. Many overseas hackers are no
longer using clunky translation websites, because there are fluent
English speakers who specialize in translating phishing emails for a
fee, Samani says.
Meanwhile, it's become easier to shorten the Web links that direct a people to fake websites, he says.
Narang
adds that people should be wary of emails purported to be from banks,
or other companies they do business with, but didn't opt into emails
from. He also notes that banks generally don't include Web links in
emails.
Those links will likely take a person to a fake website
where they will be asked to login and those credentials will ultimately
be stolen, he says.
And attacks don't just come in the form of
email. They can come as text messages too, with those links often
containing viruses, Samani says.
___
IS THERE ANY WAY TO PREVENT IT?
Basic
cyberhygiene can go a long way toward preventing a data breach, even if
a link in a phishing email gets accidentally clicked on.
Using
different passwords for different accounts, two-factor authentication
and changing passwords frequently all can be a big help. In addition,
companies should test their employees by periodically sending out fake
phishing emails to see who falls for them, Narang says.
And
companies need to make sure their security keys are up to date, along
with their anti-spam filters, so past bad senders don't keep getting
through, Samani says.
"I think common sense goes a considerable long way," Samani says.
He
adds that with any email communications, it's always better to just go
straight to the main website of the entity it purports to be from, just
to be on the safe side.
"I can't remember the last time I clicked on a link in an email," Samani says. "I just don't do it."
Dylan Ciamacco, 25, first went to the Los Angeles
outpost of international megachurch C3 as a teen. His mom thought a lot
of the young people there—in skinny jeans, chunky sweaters, and leather
jackets—dressed like him. He’d emerged recently from a “sick” (as in
awesome) atheist phase, he says, mocking himself, and was looking to go
back to church.
A
typical service, Ciamacco says, opens with a band that would fit in at
the Coachella festival, were it not for the Jesus lyrics: “What a
savior, my Redeemer/Friend of sinners, one like me.” (In one podcast, a
pastor, sermonizing about society’s obsession with markers of
achievement, uses an Internet-approved term of endearment to channel his
audience, asking, “When am I going to get my own bae?”) At the end, a
member of the “worship team” will call on parishioners to tithe and pass
the collection plate. But not all people reach into their wallet. Many
take out their phone instead.
Ciamacco
gives each week, using the Tithe.ly app. It takes fewer than five taps,
and built-in geolocation means he can contribute at any of the 1,000
churches that subscribe—a feature that’s especially useful around
holidays like Easter, when many people travel. Tithe.ly lets worshipers
set up automatic recurring payments, but because Ciamacco’s paycheck
fluctuates with his work as a freelance video producer, he tithes on
demand—usually about 10 percent of whatever he’s brought in.
Although
churches are saying a collective hallelujah that a new generation of
devotees is filling pews, a youthful congregation has its limitations.
Twentysomethings might find religion, but not a lot of them have found
that six-figure job. They don’t carry cash—and what, exactly, is a
personal check? Still, about a quarter of them use mobile payment apps
such as PayPal and Venmo regularly, according to a recent Accenture
survey. And enormously popular services such as Seamless, Uber, and
Amazon.com have normalized one-tap payments—91 percent of millennials
use their phone to buy something at least once a month, market-research
firm Statista says.
Tithe.ly
is one of a handful of apps leveraging that spending behavior for the
good of the church. Pushpay, which about 3,000 congregations employ,
works similarly; worshipers decide whether to donate to a general budget
or a specific program the institution designates. Another, EasyTithe,
features a text-to-give option. It also provides technology for a
Square-like credit card reader to await the faithful in church lobbies.
Regardless of which app a congregation chooses, the point is
convenience. “We call it frictionless giving,” says Dean Sweetman,
Tithe.ly’s co-founder and a former minister at C3 Atlanta. He designed
the app with C3’s wallet-light clientele in mind: “We see people giving
all times of day and night. Nothing stands in the way.”
Apparently
not. Churches using tithing apps report they see more donations, more
often, from more people. (Subscribing establishments either pay a
monthly fee or allow the app to collect a cut of each gift. Tithe.ly
lets donators cover this; Pushpay promises churches a 5 percent spike in
donations or their money back.) But getting parishes with pastors and
members older than 40 to sign on has been more Job-like. Tradition is
hard to overcome. “In some churches, if you let the plate go by and you
don’t put something in, you feel a little guilty,” says Brad Hill, who
works in platform services at EasyTithe. To combat that, some
congregations print out cards that say, “I gave online.”
Ciamacco’s
friend James Crocker, also 25, says it’s much more awkward to donate
the old way: “Putting your personal credit card details on a piece of
paper and leaving it there? For millennials, there’s no way.” Ciamacco
agrees, if for different reasons. “I was so anti writing my name on an
envelope—it was a holier-than-thou thing,” he says. “When Tithe.ly
came out, I was like, ‘Hell, yeah.’ ”
Culled from Bloomberg.com