Kaspersky Lab Warns of a Massive Rise in Spam Attacks on February 14

Valentine’s Day is an opportunity for personal messages—and for cybercriminals to spread crimeware and steal sensitive data through phishing. Kaspersky Lab urges users to rely on common sense online.

Archive notice: This article was originally published on February 13, 2009. Links and embedded videos are preserved as part of the historical record.

“Surprise—you have received a digital Valentine’s card.” Shortly before Valentine’s Day, who can resist the urge to read such a message of affection? Yet a single click on the link may allow a Trojan to wreak havoc on a PC, steal sensitive data such as bank-account details through a keylogger, or take complete control of the computer. Another variation follows the same pattern: you want to send your sweetheart a free Valentine’s card, click the corresponding link and become the victim yourself.

“Valentine’s Day is traditionally a time of year that warms not only lovers’ hearts, but also those of criminal malware authors,” said Magnus Kalkuhl, Senior Virus Analyst at Kaspersky Lab. “We recommend that internet users keep their antivirus databases and spam filters regularly updated during these days and take greater care than ever not to open e-cards from unknown senders.”

Red Roses—Nasty Surprise

Red roses can also conceal a nasty Valentine’s surprise: a dozen red roses for just five euros including delivery? One quick click on the supposed seller’s website and entry of bank details—and the red roses will certainly never reach the recipient, while the private banking information will reach the cybercriminals. There is no doubt that cybercriminals have an easy time whenever users are less cautious. They exploit this advantage by placing spam or similar malicious code, along with links to infected websites or phishing sites. This happens particularly around occasions such as Valentine’s Day, but also during major local or global events. Even users of instant-messaging services are not immune.

These scams involve large sums of money: estimates of losses resulting from phishing attacks range from €300 to €1.9 billion. Whatever the exact figure, the number of phishing attacks and the associated costs continue to rise. In June 2008, the Anti-Phishing Working Group (APWG) recorded 28,151 phishing reports—a significantly higher number than in previous months.

How can the risk of becoming a phishing victim be minimized? Important tips follow:

The first rule is to use common sense—always remain critical when using the internet.

  • Never use links in an email to reach a website. Instead, type the URL directly into the web browser.
  • Never enter personal, sensitive information through an email form; use only secure websites. Check the URL: sites beginning with https:// are generally safer than those beginning with http://. Also look for the padlock icon in the web browser and double-click it to verify the digital certificate. If in doubt, use the telephone and conduct the transaction the traditional way.
  • Be alert to any email asking you to enter personal data. It is highly unusual for a bank to request such information by email. A company’s IT department is likewise unlikely to ask you to verify a system login or password in this way. If in doubt, call the company and confirm the request.
  • Update your antivirus program regularly. Check whether it blocks phishing sites or install a browser toolbar that warns about known phishing attacks.

  • Make sure you use the latest version of your web browser and have installed all security patches.

  • Review your bank account regularly, including all transactions and credit-card charges. Report anything suspicious to your bank immediately.

If you follow these rules, nothing should stand in the way of a Valentine’s Day beneath a sky full of roses.