June Report on Online Fraud
In June, there was a notable rise in phishing scams that impersonate bonus point programs, with particular attention to misleading websites claiming to offer JRE POINT rewards. The report analyzes monthly scam websites and identifies trends in fraudulent activity, stressing the importance of consumer awareness.
Increase in Bonus Point Phishing Sites
The trend for phishing scams has shifted recently from alarming users with messages such as "Unauthorized access detected!" to promising enticing bonuses like "Earn points" or "Exclusive offers." These enticing promotions leverage the fact that many legitimate QR code payment and web service platforms are running actual rewards campaigns, making it easy for users to mistakenly assume a scam is legitimate. On examining sites and emails promoting point bonuses, consumers are urged to avoid clicking on suspicious links and to always check through official platforms and apps.
In addition to point-related scams, the report also notes a rise in investment fraud that masquerades as official communications from the Prime Minister's Office. Ads on social media channels are directing individuals to counterfeit investment websites, prompting formal alerts from government websites. Given that prominent figures are often used in these scams, consumers are advised to seek official information before trusting such promotions.
Attention Required for LINE and Ministry of Internal Affairs Phishing
Data indicates a surge in phishing scams posing as LINE communications or those related to labor surveys by the Ministry of Internal Affairs. These schemes not only seek to retrieve login IDs and passwords but often encourage users to add suspicious accounts on LINE. Thus, users must be wary of unknown messages, especially since similar scams leveraging national census data were widespread earlier in the year.
Current fraudulent communications also demand personal information under the threat of legal consequences, claiming that failure to respond will result in penalties. Users are reminded to verify any correspondence purportedly from the Ministry through official channels.
Additionally, scams imitating ticket sales platforms like e-plus are on the rise. Emails or texts that mention purchasing tickets or checking lottery results should be treated with caution, with users advised to access services directly through official websites rather than following links from messages.
Ranking of Phishing Brands
Phishing sites pretended to represent Apple the most in June, with those impersonating JRE POINT ranking 8th and investment scams from the Prime Minister's Office following closely in 10th place. Metrics from this report show that the composition of phishing sites linked to web services has increased, while financial motifs have diminished following a decline in fraudulent sites linked to specific brokers.
Key Preventive Measures Against Phishing Scams
To mitigate the risk of phishing attacks, users should:
- - Verify URLs in Emails or Messages: Confirm the legitimacy of any links appearing in correspondence by comparing them against saved bookmarks or through web searches before accessing.
- - Beware of Requests for Personal Information: No reputable organization will request personal or credit card information via email or text; hence, users need to exercise extreme caution when encountering such requests.
- - Avoid Using the Same Login Credentials: Using the same login details across multiple platforms increases the risk of being exploited following a phishing attack. Users should create unique credentials for each service to minimize risks.
- - Implement Security Software: Cybercriminals continuously adapt, rendering previous defense strategies obsolete. Installing anti-virus and web fraud protection software can help signal potential threats before users navigate to malicious sites.
Free Diagnostic Tool: Phishing Site Checker
For those uncertain about a website's safety, the free "Phishing Site Checker" can be employed. This service evaluates if a targeted URL is flagged as fraudulent based on data from cyber fraud detection tools and government databases.
Website:
https://checker.miyabull.jp/
Commentary from Professor Tatsuya Mori
June's report highlights a concerning rise in bonus point-themed phishing activities. The JRE POINT barely makes the top ten branding list as these tactics become normalized. Notably, methods have evolved to exploit user psychology, transitioning from urgency-driven tactics to appealing offers that tempt users to act quickly. This adaptation creates challenges in prudently distinguishing between genuine rewards campaigns and scams. As the autumn approaches, vigilance against governmental phishing tactics, especially those leveraging survey data, will be essential. Historical patterns indicate a spike in fraudulent activities surrounding national surveys, making it crucial for users to resist clicking on unknown links and to interact only with verified platforms. By sharing insights from this report with family and friends, consumers can cultivate a more cautious approach to reward offers or payment requests that lack proper verification.
Author's Profile
Tatsuya Mori
Professor at Waseda University's Science and Engineering Faculty
Recipient of the 2021 Minister's Award for Science and Technology
Visiting Expert at NICT Cybersecurity Research Institute
Company Overview
Company Name: BBSS, Inc.
Location: 1-7-1 Kaigan, Minato-ku, Tokyo, Japan, WeWork Tokyo Port City Takeshiba
CEO: Shinya Honda
Established: January 17, 2006
Shareholder: 100% owned by SB C&S Inc.
Business Activities: Development and provision of consumer software and IoT services and B2B license sales
Website:
https://www.bbss.co.jp/