February 20, 2008 12:56 PM PST

The IRS seeks brand protection

Washington D.C. -- Like the Bank of America brand name, the United States Internal Revenue Service is a brand that also needs online protection. On Wednesday, Special Agent Andy Fried with the U.S. Treasury Department gave a second keynote address to start off Black Hat DC 2008. He said as of February 19 this year, there were 1,630 phishing sites using the IRS name or logo, marking a 12 percent to 17 percent increase over last year.

Although the IRS phishing sites may be taken down with an hour or so, that's still long enough for a victim to volunteer personal information online. Fried stated that the IRS does not contact people via e-mail. He also noted that many of the phishing sites and e-mails came "out of Eastern Europe."

E-mails pretending to be from the IRS may link to phishing sites, but they can also launch malware, said Fried. He cited one example where late at night he saw a new IRS-themed e-mail containing malicious code and also found that none of the major antivirus sites had signatures in place to block the sample. He said the antivirus vendors frequently missed malware associated with IRS e-mail spam.

While he was concerned about ordinary people getting hit, he called upon the antivirus community to immunize their applications before the IRS staff reported for work in the morning. His concern was the IRS itself, which, in the morning would start to get forwarded examples of the e-mail and could potentially infect the IRS with malware.

In January 2008, Fried said that the IRS reached a full one percent of all spam traded on the Internet--a record for the agency.

Fried also warned against using peer-to-peer applications on the same desktop with your tax information on it. He and his investigators will periodically fire up LimeWire and find hundreds of copies of people's tax returns available for downloading. "If you don't know what you are doing with P2P," said Fried, "don't use it."

Fried said he expected more IRS-themed Internet activity in May when the U.S. government plans to issue tax rebates to qualified individuals, but declined to specify what he expected.

Recent posts from Defense in Depth
PayPal XSS vulnerability affects EV SSL
Fake codec found in AOL forum
Carpet bombing networks in cyberspace
The good (and bad) news about electronic voting
ZoneAlarm virtualizes the desktop Internet browser
Add a Comment (Log in or register) 1 comment (Page 1 of 1)
Great audit excuse
by PortVista February 20, 2008 1:33 PM PST
This story comes around every tax season. If you ever get audited just tell the IRS you accidentally file shared your tax return which was a work in progress and someone must have sent it in by accident.
Reply to this comment
Powered by Jive Software
advertisement
  • About Defense in Depth

  • With over eight years at CNET covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews with the top security researchers making the news as well as offering the hands-on, non-technical advice you'll need to stay safe online.

Add this feed to your online news reader
Google
Yahoo
MSN

Most popular stories

  1. Images: Microsoft telescope puts universe on your desktop

  2. Photos: Cracking open the Atari 2600

  3. This VC forecast scares the pants off of me

  4. End of Intel, AMD duopoly near? Via readies Isaiah chip

  5. The Internet thrives on dark energy

Latest tech news headlines

Featured blogs

Beyond Binary by Ina Fried

Coop's Corner by Charles Cooper

Geek Gestalt by Daniel Terdiman

Green Tech

One More Thing by Tom Krazit

Outside the Lines by Dan Farber

The Iconoclast by Declan McCullagh

The Social by Caroline McCarthy

Underexposed by Stephen Shankland

Resource center from News.com sponsors

advertisement
Click Here
On TV.com: MILEY CYRUS photographs
Advanced
search
Advanced
search
Visit other CNET Networks sites: