e9

Preventing Phishing Scams at a glance

Site Genre: Pattern Group e


magnify imageFigure E9.1 PayPal (owned by eBay) periodically sends out e-mails that teach its customers about online scams and how to identify them.

Background

Many PERSONAL E-COMMERCE (A1), ENABLING INTRANET (A11), and banking sites have faced a rash of online phishing scams in recent years that have resulted in significant financial loss to their customers. These scams often masquerade as legitimate E-MAIL SUBSCRIPTIONS (E2) and E-MAIL NOTIFICATIONS (E7) from a Web site and can cause great harm to your SITE BRANDING (E1).

Close

PROBLEM

Your customers may inadvertently give personal and financial information to online scammers who use your business as part of their scams.

buy the book to find out more

SOLUTION

magnify image Figure E9.4 Educate your customers about how to protect themselves through e-mails and Web pages on your site. In addition, design your Web site assuming that some customers will be phished; that is, make it more difficult for phished accounts to cause harm to individuals.

Train your customers about the risks of online phishing scams and how to identify such scams. Protective tactics include telling your customers what types of information you will request and when, making it more difficult for phished accounts to cause harm to individuals, requiring multiple forms of identification, and actively searching for Web sites that use your brand name.

Other Patterns to Consider

It is important for PERSONAL E-COMMERCE (A1), ENABLING INTRANET (A11), and banking sites to help protect their customers from online phishing scams that can cause significant financial loss to customers, as well as hurt your SITE BRANDING (E1). Inform your customers about the kinds of information you will and will not request. Do this after the customer has created an account or has signed in via the SIGN-IN/NEW ACCOUNT (H2) process. You might also provide periodic E-MAIL SUBSCRIPTIONS (E2) warning your customers about scams, and include information about protecting your customers from online scams on your ABOUT US (E5) and PRIVACY POLICY (E4) pages. Use these e-mail notifications and Web pages to educate your customers about how to detect online scams and what to do if they have been phished. Finally, in E-MAIL SUBSCRIPTIONS (E2) and E-MAIL NOTIFICATIONS (E7), avoid having OBVIOUS LINKS (K10) that lead to a SIGN-IN/NEW ACCOUNT (H2) page.

Close

 

Pattern Resources

PATTERN COMMENTS

POST A COMMENT and/or EXAMPLE WEB SITE

Sign in Form

(required)

(required, but not displayed)

Have a idea for a new pattern group? Join our disscussion on new pattern ideas.