Simple clear advice in plain English

Tax and Christmas spam on the increase

Marked rise in fake tax office emails plus Halloween and Christmas spam, says Symantec

image of HMRC building
crn/1-june-2009/hmrc-building

There has been a surge in the number of phishing emails masquerading as coming from Her Majesty’s Revenue and Customs (HMRC) this month according to Symantec.

In its monthly Messagelabs Intelligence Report for October, the security company said these emails accounted for 81 per cent of all phishing emails in the UK on 13 October.

This coincides with genuine reminders from HMRC about the 31 October deadline for handing in self-assessment paper forms for the 2008-2009 tax year.

The links in these emails take the victim to a website that cleverly mimics the HMRC site but the suffix of the web address is a give away; often being hmrc.co.uk rather than the official .gov suffix.

The Symantec report also showed an increase in Halloween-themed spam throughout October, peaking at 500 million emails globally, circulating on a daily basis as we come to the end of the month.

It said the majority of Halloween-themed emails have originated from one of the largest botnets called Rustock and also the Donbot and appear to be pushing pharmaceutical or software products.

The company warned that Christmas-related spam has started to appear early this year, mostly originating from the Cutwail botnet. These are trying to ‘sell’ replica watches, according to Symantec.

Paul Wood, Messagelabs intelligence senior analyst said: "As is typical with spammers this time of year, we are seeing them try to capitalise on the holiday season.”

However he said the good news is that the number of phishing attacks in general is falling. He believes this is partly due to the reduction in phishing toolkits available for use.

However, he warned that phishing runs in languages other than English, such as French and Italian, do appear to be increasing.

“When it comes to phishing runs,” he said, “we have seen a significant shift in the bad guys’ approach.

"Not only are they experimenting with different languages, they are also turning their attention to targeting online services like web-based email in addition to the financial sector.

“The reason is likely due to the widespread use of email addresses used to authenticate other sites such as social networking, retailing and auction sites.”

Reader Comments

   

Add your comment

All fields must be completed. Your email address will not be displayed or used to send marketing messages.

All messages will be checked by moderators before appearing on the site.

See our Privacy Policy for more information.

Related articles

chronodex-printable-calendar

Plan your year with Chronodex by Scription

A printable diary with a unique approach to showing the time of day

image-of-the-virgin-mobile-broadband-dongle

Virgin alerts customers that are infected with Spyeye Trojan

ISP gets tip-off from Soca that malicious computer software has been unwittingly downloaded by Virgin Media customers and perhaps many more

Skype worm bypasses security software

Virus poses as chat message invites

Question & Answer

Q.How do I store musician and other information about...

> Read the answer

Q.Why can't my browser find the website address I typed...

> Read the answer

Q.All updates have been downloaded, so why won't Windows...

> Read the answer

Best deals on the web

img

LIVESCRIBE Echo 3D In-Ear Recording Headphones - Black

£29.99- Buy it now

img

Belkin Inc Belkin SurgeMaster Gold Series - Surge suppressor - AC 250 V - 7 Output Connector(s) - United Kingdom

£22.40- Buy it now

img

Fellowes Gel Crystals Blue Mouse Pad

£16.79- Buy it now

Great benefits for subscribers!

Poll

Which is your preferred web browser

Jargon Buster

Computing terms explained in plain English

CAD

Computer Aided Design. Software used to create 3D models.

Great shopping deals from Computeractive