What Are Some Types of Phishing Scams to Watch Out For?
Phishing scams may occur in many different ways. The most common forms include scams perpetrated by postal mail or vishing, which is a voice phishing scam conducted over the phone.
Newer forms of phishing scams that individuals should watch out for include:
- Malware-based Phishing: This is where the scammer uses fake malware or antivirus ads to obtain the individual’s information.
- For example, the scam may involve a fake pop-up ad stating that the person needs to provide their credit card info in order to purchase new firewalls or antivirus software.
- SMiShing: This involves SMS or text messaging on a cell phone.
- Here, the victim may receive a fake text alert asking for their password or bank account number.
- Search Engine Phishing: This type of phishing uses search engines to reroute an individual to a different website while searching for info online.
- The website is fake and usually requires the user to fill out a form to proceed.
- Spear Phishing: This is where the perpetrator sends mass fake e-mail messages to companies and businesses, hoping to obtain employee information and other company data.
Essentially, any new form of communication, especially electronic or digital messages that are sent over the internet, are prone to being used as a tool for perpetrating a phishing scam. Therefore, it is important that an individual only share their personal information with parties they trust and that they do so over a secure internet connection.
What Are Quishing Scams?
Quishing scams, which are also called QR code tampering scams, are types of scams where hackers hide malicious website addresses inside of QR codes. A Quick Response code, or QR code, is a two-dimensional barcode that stores data in grids of black and white squares.
A scammer may put a fake QR code sticker over a real QR code sticker at many different types of locations, such as parking meters or restaurants, or they may be sent out in emails. When a person comes along and scans the fake QR code, they will be directed to a fake website where the scammer can steal their passwords, information, or money.
What Is Identity Theft?
The United States Department of Justice broadly defines identity theft as a phrase that applies to all crimes that involve acquiring and using another individual’s data through fraud or deception for their financial gain. For example, suppose an individual saves their credit card data on their computer, to a web browser, or in a pre-filled form on a website.
If a hacker gains access to this information and uses it to purchase something, it would be deemed an act of identity theft. Another way identity theft may occur is when an individual is not cautious with their data in public.
For example, if an individual provides information such as their social security number or credit card number over the phone when they are in a public place. In these instances, a criminal can easily overhear it and write down the details for later use.
The internet has provided criminals with many more opportunities to perpetrate these crimes than they have before the advent of technology. Thus, it is essential for an individual to use safeguards to protect their online and offline data.
Otherwise, an individual may end up with numerous issues all because an individual decided to steal their identity, including:
- A criminal history
- Fraudulent tax records
- A poor credit score
How Can Your Identity Be Stolen?
There are numerous ways to steal an individual’s identity. Aside from the examples that were discussed above, some of the more prevalent methods which are used to steal an individual’s identity include:
- Robbery: A perpetrator can physically steal an individual’s data by robbing them of specific items, such as their:
- driver’s license
- social security card
- debit or credit cards
- other items
- Computer Fraud: Computer fraud goes beyond standard hacking. This phrase may also apply to:
- deceitful website schemes
- deleting sensitive government files
- romance scams
- any other online activity which results in an individual becoming a victim of identity fraud
- Social Media: Although this offense may fall under computer fraud, a criminal can impersonate someone by:
- using their social media
- looking for clues about the individual that would reveal password hints;
- finding details saved to their social media account, for example, a linked bank account
- messaging their contacts for records or sensitive information
- Mail Theft: A criminal can intercept an individual’s physical mail to get personal data. Sources of mail which may have vital details for thieves include:
- bank statements
- credit card statements
- pre-approved credit card offers
- Dumpster Diving: An offender may also dig through an individual’s trash to search for personal or financial data. Therefore, it is essential to tear up paperwork that displays:
- bank accounts
- credit card numbers
- handwritten passwords
- other personal information
So How Do I Avoid Falling Victim to These Phishing Scams?
There are several suggestions that an individual can use to help them avoid falling for these types of scams.
Check With the Company Itself
Legitimate companies will never ask for sensitive financial information via an email, so if an individual receives an email asking them to provide this type of information, even if it looks like it is legitimate, it should be deleted.
Instead, the individual may want to check the company’s official website as well as e-mailing them or calling them at an address or phone number the individual knows actually belongs to the company.
Do Not Send Confidential Information Via Email
It is important not to send any confidential financial information via email. E-mail is not a secure source. Instead, an individual should give that information through a secure website, such as one where the address begins with “https” instead of just “http.”
Even in these situations, it is important to be cautious about what information an individual is giving away and not to give away any private financial information unless it is absolutely necessary.
Use Anti-virus Software
Install anti-virus software on the computer and keep it updated. In some cases, a phisher may send software with their emails that either harm the computer or track where the individual goes on the Internet without their knowledge.
How Can I Avoid Being a Victim of Quishing Scams?
There are some steps that someone can take to avoid becoming a victim of quishing scams, which are discussed below.
Look Out for Warning Signs
There are usually warning signs that will signal when a communication may be a phishing scam, such as:
- Requests for banking information, passwords, or Social Security numbers
- A website link that is slightly different from the company name or is misspelled
- A sender rushing for payment or action on the part of the recipient
- An email that starts with “Dear Customer” instead of an individual’s name
Go To the Business Website
One step an individual can take to avoid quishing scams is to navigate directly to an official business website or call the business organization itself using the official phone number instead of clicking on a link in an unexpected email or text message link.
Creating a Code Word
Another step a person can take to prevent being a quishing scam victim is to create a verbal code word to use with family and friends so that their identity may be verified by the individual during any urgent or unexpected phone calls.
Do Not Make Any Up-Front Payments
An individual should not make any up-front payments in certain situations to avoid scams. A legitimate employer will not request payments in order for the individual to get a job. Legitimate companies will not ask for payments using wire transfers, cryptocurrency, or gift cards.
If something does not seem right or legitimate, an individual should contact the company or business directly using their direct website or phone number. It is always better to double check, as businesses are aware that scams are perpetrated and are patient and appreciative when customers are checking with the business to avoid them.
Are There Any Legal Penalties for Phishing Scams?
Individuals or groups who are caught perpetrating phishing scams can face legal consequences. In certain cases, these scams may result in serious misdemeanor charges that can be punished by jail time or criminal fines.
A phishing scam that involves the altering or manipulation of a federal website or the deceit of a federal official may result in federal felony charges.
What Are the Legal Consequences of Quishing Scams?
Under phishing laws, a scammer may face severe legal consequences for engaging quishing scams and other types of phishing scams. These punishments may include incarceration and substantial criminal fines. Quishing scammers may be prosecuted for a federal crime, a state crime, or even both, such as wire fraud or identity theft.
It is important to be aware that both states and the federal government can have criminal statutes for wire fraud. This means that the potential charges and penalties for quishing scammers can vary depending on the location, facts, and circumstances of the offense. Under federal laws, a quishing scammer who is convicted of wire fraud can face no more than 20 years in prison and no more than $1,000,000 in criminal fines, or a combination of both, for each act of criminal fraud.
Similarly, identity theft may also be charged at the federal and state levels, depending on the location and facts of the incident. A convicted defendant may face a variety of potential punishments, which may include incarceration, criminal fines, restitution, as well as forfeiture of property that is related to the offense.
If the negligence of the business entity itself allowed the quishing scam or data breach to occur, the business may face compliance penalties, regulatory fines, or a class-action lawsuit from the victims.
What Should I Do if I Have Fallen Victim to a Phisher?
If an individual finds out they have provided private financial information to what later turned out to be a phisher, the first thing they should do is to contact their bank and credit card companies to inform them to monitor any transactions made on the account or card the phisher may have access to. An individual may also want to file a complaint with the Federal Trade Commission (FTC) so they are aware of the extent of the scam.
In addition, if the identity of the phisher is determined, an individual may wish to consult with a fraud lawyer who can advise them whether they may be entitled to money damages.
What Should I Do if I’ve Been the Victim of a Quishing Scam?
When someone has become a victim of a quishing scam, they should act as quickly as possible to protect both their money and their identity. It is important that they take several steps, which include, but may not be limited to:
- Securing their financial accounts by changing all passwords for any compromised accounts or other accounts that use the same or similar password
- Using or installing anti-virus software on the device that was used in the scam to check for malware
- Calling their bank and credit card companies to inform them of the issues, freezing any accounts that were affected, canceling any cards that were affected, and disputing any unauthorized charges
- Placing a free fraud alert, which can be done by contacting one of the three major credit bureaus, including TransUnion, Equifax, or Experian
- Filing an official report with the Federal Trade Commission (FTC) and the FBI Internet Crime Complaint Center
Do I Need a Lawyer for Help with Phishing Scam Issues?
Phishing scams are common and may catch large numbers of unsuspecting consumers each year. It may be helpful to hire a fraud lawyer if you suspect that you or your company has been the victim of a phishing scam.
Your attorney can help you determine if there was a violation and whether or not you have legal resources available to you. In addition, your attorney can represent you in court if necessary.