Dow-103.84down-1.04%
9,908.39
Nasdaq-15.07down-0.70%
2,126.05
S&P-9.45down-0.89%
1,056.74
Smart Spending blog - The best money-saving tips on the Web, featuring MSN Money's Karen Datko, Donna Freedman, Teresa Mears and the best of other sites.
Smart Spending combines the best money-saving tips from MSN Money and the rest of the Web. Our team of experts on stretching dollars:
  • Karen DatkoKaren Datko, lead blogger, is a veteran journalist in small-town Montana, where her mortgage is $310 a month.
  • Teresa MearsTeresa Mears is a veteran writer in Florida. She doesn't clip coupons, but she does shop at Goodwill.
  • Donna FreedmanDonna Freedman, our "Living With Less" columnist, is a student, freelance writer and handywoman in Washington.
See all contributors
Smart Spending Index

Subscribe to this blog RSS feed

  • Subscribe with live.com
  • Subscribe with My Yahoo
  • Subscribe with XML
  • Subscribe with Bloglines
  • Subscribe with My MSN
  • Subscribe with Google
  • Subscribe with Newsgator
  • Follow Smart Spending on Twitter
  • Become a fan of MSN Money on Facebook

The 12 scams of Christmas

Cybercriminals are gearing up to take advantage of the holiday season.

Posted by Karen Datko on Tuesday, November 24, 2009 12:24 PM

This post comes from James Limbach at partner site ConsumerAffairs.com.

 

As cybercriminals begin to take advantage of the holiday season, McAfee Inc. is warning consumers about the "12 Scams of Christmas" -- the 12 most dangerous online scams that computer users should be cautious of.

 

According to Consumer Reports’ 2009 State of the Net Survey, cybercriminals have bilked $8 billion from consumers in the past two years.

"Cybercriminals use their best schemes during the holidays to steal people's money, credit card information, Social Security number and identity," said Jeff Green, senior vice president of McAfee Labs. "These thieves follow seasonal trends and create holiday-related Web sites, scams and other convincing e-mails that can trick even the most cautious users."

 

The 12 Scams of Christmas are:

  • Charity phishing scams. During the holiday season, hackers take advantage of people’s generosity by sending e-mails that appear to be from legitimate charitable organizations. In reality, they are fake Web sites designed to steal donations, credit card information and the identities of donors.
  • Fake invoices from delivery services. During the holidays, cybercriminals often send fake invoices and delivery notifications appearing to be from FedEx, UPS or the U.S. Customs Service. They e-mail consumers asking for credit card details to allegedly credit accounts, or require users to open an online invoice or Customs form to receive the package. Once completed, the person's information is stolen or malware is automatically installed on their computer.
  • Cybercriminal "wants to be your friend." Cybercriminals take advantage of this social time of the year by sending authentic-looking "new friend request" e-mails from social-networking sites. Internet users should beware that clicking on links in these e-mails can automatically install malware on computers and steal personal information.
  • The dangers of holiday e-cards. Cyber thieves cash in on consumers who send holiday e-cards in an effort to be environmentally conscious. Last holiday season, McAfee Labs discovered a worm masked as Hallmark e-cards and McDonald's and Coca-Cola holiday promotions. Holiday-themed PowerPoint e-mail attachments are also popular among cybercriminals. Be careful what you click on.
  • "Luxury" holiday jewelry can come at a high price. McAfee Labs recently uncovered a new holiday campaign that leads shoppers to malware-ridden sites offering "discounted" luxury gifts from Cartier, Gucci and TAG Heuer. Cybercriminals even use fraudulent logos of the Better Business Bureau to trick shoppers into buying products they never receive.
  • Online identity theft in open networks. Forrester Research Inc. predicts online holiday sales will increase this year, as more bargain hunters turn to the Web for deals. While users shop and surf on open hotspots, hackers can spy on their activity in an attempt to steal their personal information. McAfee tells users never to shop online from a public computer or on an open Wi-Fi network.
  • Christmas carol lyrics can be dangerous. During the holidays, hackers create fraudulent holiday-related Web sites for people searching for a holiday ringtone or wallpaper, Christmas carol lyrics or a festive screensaver. Downloading holiday-themed files may infect a computer with spyware, adware or other malware. McAfee found one Christmas carol download site that led searchers to adware, spyware and other potentially unwanted programs.
  • Job-related e-mail scams. The U.S. unemployment rate recently spiked to 10.2%, the highest level since 1983. Scammers are preying on desperate job-seekers in the poor economy, with the promise of high-paying jobs and work-from-home moneymaking opportunities. Once those interested submit their information and pay their "setup" fee, criminals steal their money instead of following through on the promised employment opportunity.
  • Auction site fraud. Scammers often lurk on auction sites during the holiday season. Buyers should beware of auction deals that appear too good to be true, because oftentimes these purchases never reach their new owner.
  • Password stealing scams. Password theft is rampant during the holidays, as thieves use low-cost tools to uncover a person's password and send out malware to record keystrokes, called keylogging. Once criminals have access to one or more passwords, they can gain access to a consumer's bank and credit card details and clean out accounts within minutes. They also commonly send out spam from a user's account to their contacts.
  • E-mail banking scams. Cybercriminals trick consumers into divulging their bank details by sending official-looking e-mails from financial institutions. They ask users to confirm their account information, including a user name and password, with a warning that their account will become invalid if they do not comply. Then they often sell this information through an underground online black market. McAfee Labs believes cybercriminals are more actively scamming consumers with this tactic during the holidays because people are monitoring their purchases closely.
  • Your files for ransom. Hackers gain control of people's computers through several of these holiday scams. They then act as virtual kidnappers to hijack computer files and encrypt them, making them unreadable and inaccessible. The scammer holds the user's files ransom by demanding payment in exchange for getting them back.

McAfee advises Internet users to follow these five tips to protect their computers and personal information:

  • Never click on links in e-mails. Go directly to a company or charity's Web site by typing in the address or using a search engine.
  • Use updated security software. Protect your computer from malware, spyware, viruses and other threats with updated security suites.
  • Shop and bank on secure networks. Check bank accounts or shop online only on secure networks at home or work, wired or wireless. Wi-Fi networks should always be password-protected so hackers cannot gain access to them and spy on online activity. Also, remember to shop only on Web sites that begin with https://, instead of http://.
  • Use different passwords. Never use the same password for several online accounts. Diversify passwords and use a complex combination of letters, numbers and symbols.
  • Use common sense. If you are ever in doubt that an offer or product is legitimate, do not click on it. Cybercriminals are behind many of the seemingly "good" deals on the Web, so exercise caution when searching and buying.

 

Related reading at ConsumerAffairs.com:

Join the discussion!
Sort by:
1 - 15 of 19
Friday, December 11, 2009 9:13:27 AM
Tuesday, November 24, 2009 8:12:42 PM
My favorite is the Soupy Sales "send me a dollar,kids" scam....Next to that would have to be the expressway panhandlers looking for food and change. When people coming off the expressway hand them food, they wait 'til they drive off and trash it. Keeping only the change, a local guy was able to collect $75K a year......and drive off in his Benz , parked only blocks away.....Hot
 
"Homeless For The Holidays"
 
Well there's noplace like being homeless for the holidays
No matter how far around town you roam
If you want to act crappy in your usual way
When you call a cardboard box your home sweet home.
 
I met a man who's drunk and stinks of pee
And he was heading for
A highway exit with his "Will Work For Food" sign
And then you see him beg for money, outside the corner store
For some wine to be specific, gee some Mad Dog is terrific
 
Well there's no place like being homeless for the holidays
No matter how far around town you roam
If you want to act crappy in your usual way
When you call a cardboard box your home sweet home...
 
Smelling crude, acting rude, holds a sign, "Will Work For Food"
When he's really bumming money for some wine.
Stinks so bad, hold your nose, slugs some Wild Irish Rose
Then you see why this bum's not fine
 
I met a man who's drunk and stinks of pee
And he was heading for
A highway exit with his "Will Work For Food" sign,
Then you'll see him beg for money, outside the corner store
For some wine to be specific, gee some Night Train is terrific
 
Well there's no place like being homeless for the holidays
No matter how far around town you roam
If you want to act crappy in your usual way,
When you call a cardboard box your home sweet home,
When you call a cardboard box your home.....sweet.....home!!!
 
(With apologies to Perry Como and Karen Carpenter.)
Wednesday, November 25, 2009 10:17:33 PM
Hi, Answer62.  They're just talking about websites where you buy things.  The "https://" prefix means the site is secure, or encrypted, so sending your credit card information is OK.  Regular websites that just convey information, like this site, only need to use the "http://" prefix because there is no information being passed that needs to be encrypted.
Wednesday, November 25, 2009 12:17:36 PM
the above article states, https:// is okay. http:// is not. in my url now is http://
Wednesday, November 25, 2009 11:19:58 AM
Let’s not forget about the impact on employers. Each Year employers simply accept the fact that starting the Monday after Thanksgiving until December 24th employees will be using the organization’s Internet to shop. While some personal use of business resources is expected the loss of productivity due to online shopping during the holiday season can really hurt businesses, not to mention the potential for some sort of security breach due to increased traffic and downloading during this time.
Wednesday, November 25, 2009 8:49:29 AM
Unless you have a friend or relative who really needs something, don't buy for the sake of wrapping and giving another piece of kitsch to their already cluttered home--Give food or heat money or just spend time with them.  Give the gift of your time!  We don't need more made in China junk or cute artsy craftsy dust collectors in our lives.  We do need good friends!
Wednesday, November 25, 2009 8:43:23 AM
Commonsense....please don't shop for your Scotch on line.....you will get scamed.  It's "Johnnie Walker" not Johnny Walker.  I perfer the Gold myself.
Wednesday, November 25, 2009 8:25:26 AM
I had Windows now have Linux Jaunty Jackalope on my Vaio. Let's see them install malware on THAT. With Macs you CAN get trojans if you put in the requested code. But the "security by obscurity" arguement Microsoft uses is a bunch of BS. Their system architecture is horrendous
Tuesday, November 24, 2009 11:50:35 PM
A virus by clicking a link?  It doesn't exactly work like that, unless you allow all activeX controls without a prompt....which would be very unusual.  Hackers use social engineering.  Which means they trick the user into giving up their security.  Just clicking a link doesn't download viruses.
Tuesday, November 24, 2009 9:14:32 PM
No presents this year.  christmas is no longer about going into debt.  Just a dinner and the real meaning of the Holiday.
Tuesday, November 24, 2009 8:38:20 PM
SadIt is indeed "sad" as the emoticon depicts, that Holidays have become as commercialized as life itself on Planet Earth...maybe we should all just stay at home and enjoy our families and not participate in the scams, the cons, the hype, the come-ons, or the spending needlessly.  Let's all take back our holidays!
Tuesday, November 24, 2009 8:21:09 PM
Holiday Scam ? What about Santa himself ? I Just found out that he ,himself,the biggest perpetrator of this whole Holiday mumbo jumbo , is Not Real ?!?!?!?!?45 years and , now , I have my ballon burst. I'm beginning to wonder about the Easter Bunny and Tooth Fairy......Hot
Tuesday, November 24, 2009 8:18:32 PM
Hank- Do you prefer Johnny Walker Red or Black for the holidays, you drunken grumpy scrooge of an old sack.......Hot
Tuesday, November 24, 2009 8:17:17 PM
All I can hope for you holiday naysayers is that your business dies at the busiest time of year....effewHot
Tuesday, November 24, 2009 8:15:11 PM

Another good scam is the parking scam, filling up lots which don;t belong to those being paid to park the cars. Better yet, the guys park you ,take your money ,and walk away to call the cops and a tow truck.....Hot

Tuesday, November 24, 2009 8:12:42 PM
My favorite is the Soupy Sales "send me a dollar,kids" scam....Next to that would have to be the expressway panhandlers looking for food and change. When people coming off the expressway hand them food, they wait 'til they drive off and trash it. Keeping only the change, a local guy was able to collect $75K a year......and drive off in his Benz , parked only blocks away.....Hot
1 - 15 of 19
To add a comment, pleasesign in

5 hottest deals from DealNews

Latest deals from Deal News

Featured Tools

Quizzes