PDA

View Full Version : New California Law makes phishing illegal


jokach
October 4th, 2005, 01:47 PM
It seems that California has taken the first steps towards punishing scammers who attempt to steal peoples personal information, I wonder if other states, or even the federal government, will follow suit? :confused:

I think the problem might come in when it comes to finding the person or persons who sent the emails, or setup the fraudulent website, because they are sometimes hard to track.

reposted from:
http://www.computerworld.com/securitytopics/security/cybercrime/story/0,10801,105143,00.html?source=NLT_AM&nid=105143


New California law makes phishing illegal
The Anti-Phishing Act of 2005 allows for fines of thousands of dollars
News Story by Robert McMillan

OCTOBER 04, 2005 (IDG NEWS SERVICE) - The state of California has passed the country's first antiphishing law, making this form of identity theft punishable by thousands of dollars in fines.

The law, entitled the Anti-Phishing Act of 2005, was proposed by state Sen. Kevin Murray and signed into law on Friday. It is the first such legislation to be enacted in the U.S., according to backers of the bill.

"It's something that adds another tool in the quiver for consumers and businesses to reduce this kind of really bad behavior," said Michael Wendy, a spokesman for the Computing Technology Industry Association, an IT trade association that has supported the law.

Phishing victims are typically sent fraudulent e-mail designed to trick them into revealing personal information, like bank account numbers, usernames and passwords.

Under the Anti-Phishing Act, these victims may seek to recover either the cost of the damages they have suffered or $500,000, whichever is greater; government prosecutors can also seek penalties of up to $2,500 per phishing violation.

While it may have been possible to prosecute phishers under existing antifraud laws, the new legislation will make it easier for victims and government to go after phishers, Wendy said.

It may also serve to inspire other legislation, perhaps even at the federal level, he said. "You can't discourage the symbolic purpose of this," he added. "It's a statement to these guys that this is not acceptable behavior."

The new law is unlikely to cut down on phishing, however, at least in the short term, according to Jordan Ritter, chief technology officer at antispam software vendor Cloudmark Inc. However, if the law is held up in court and actually serves to help victims recover damages, phishers may take note, he said.

Ritter agreed that the Anti-Phishing Act also may serve a symbolic purpose. "Anything that raises people's awareness and improves people's education on the extent of the problem ... is going to improve things," he said.

Phishing attacks have been on the rise. Research firm Gartner Inc. estimates that 73 million U.S. Internet users received phishing e-mails during the 12 months leading up to May 2005, up 28% from the previous year.


jokach

mercinary
October 4th, 2005, 02:14 PM
It seems funny to me that California was the first state to make laws that apply to matrix scams, and now they are the first to directly address phishing scams. A big "Hoorah" for the state of Cali. :D

-Merc

MatrixWatch
October 4th, 2005, 05:09 PM
It would be nice if hotmail and yahoo had a link on their menu bars which read, "Report a Phisher Email", or something like that. It would automatically format the email to full headers, and send it to the proper department for further review.

Little steps like this would help the public to report these scams more easily. Also, if the legal system allowed there to be some sort of "reward" for reporting a phisher, it might give consumers and businesses more incentives to crack down on these new forms of fraud.

surfer
October 4th, 2005, 06:09 PM
That would be a nice email feature. :)

Of course, email providers don't really care.

It would be nice to see a few more of these
scammers getting busted and suffering the
maximum penalties.

MatrixWatch
October 4th, 2005, 06:45 PM
I agree. In my experience from interacting with both scammers and victims, I have learned that one of the major hurdles victims have (and that scammers take advantage of) is the difficulty in bringing them to justice.

Let's face it. A stodgy old professor with an email account who falls victim to a phisher scam doesn't know what full headers are, or which abuse@ address to send it to.

surfer
October 4th, 2005, 06:53 PM
lol

Well, other than forwarding on the PayPal
ones I receive, I simply delete all the others.

I don't take the time to look up every bank
and credit card company to find their fraud
addresses.

Since the web is so much like the Wild West,
maybe internet fraud should temporarily be a
capital offense. :eek:

mercinary
October 5th, 2005, 10:14 AM
You know what? I think this brings up an interesting idea...

I'm going to start a thread (click here) (http://www.matrixwatch.org/forums/showthread.php?p=28213#post28213) where people can post phisher emails. The Matrixwatch community will then find the correct place to report the email, and will report it.

-Merc

MatrixWatch
October 5th, 2005, 07:03 PM
Excellent idea Merc. :)