By Steve Levy
Those of us in the domain name community are all too familiar with cybersquatting, phishing, and other online fraud. But it’s important to remember that there are still many individuals and organizations that aren’t steeped in this awareness and remain vulnerable. This becomes especially apparent when a major news organization like the Wall Street Journal does a feature article on the topic.
The town of Surfside Beach, South Carolina, fell victim to a half-million dollar scam in March of this year after one of its directors inadvertently sent the money to an account listed in a phishing email. The town had arranged for some work to be done by a contractor and payments were to be made by cutting a check. However, the director received an email asking that the next payment be made electronically and account details were provided. It turns out that the email used what we all know as a “typosquatted” domain name, replacing a lower-case letter “L” with an upper-case letter “I” as they look nearly identical to the human eye. The cybersquatter also set up a dummy website using the domain name and used its ill-gotten access to the email system to block certain legitimate emails.
Such phishing scams have cost municipalities many billions of dollars over the years and smaller towns and cities don’t always have a sufficient budget for more robust fraud prevention tools. Of course, the advent of artificial intelligence has only increased the risk and sophistication of such attacks.
The unfamiliarity with cybersquatting is apparent as the article reports that “Surfside Beach Mayor Robert Krouse said the emailed payment request appeared genuine” and the town’s Finance Director said “It looked legit to us”. The Mayor went on to say “We don’t see where the town erred,” and he questioned “why we should be paying double” after the contractor requested payment on its still-outstanding invoice. However, the town also said that it is fortifying its financial controls by more closely monitoring electronic money transfer and will also have its contractors use specific passwords. As for the current scam, investigations are ongoing but a recovery of funds seems unlikely given the amount of time that’s passed since the transfer.
Apart from using better email systems that can flag improper email addresses, one of the practices recommended in the article is to use voice verification at a known phone number and with a known person before making high-value money or data transfers. Also, look for other red flags. In this case, the town’s director had been dealing with the contractor’s CEO but the email requesting an online transfer came from someone claiming to be a project manager for the contractor, an unlikely title for someone overriding a CEO’s payment instructions.
The bottom line is that cybersquatting and other types of domain abuse are not mere academic exercises that are detailed in so many UDRP decisions every week. Phishing and fraud through email attacks are very real and can put serious money at risk. More education on how these scams work, provided to individuals at all levels of an organization, can go a long way towards identifying and preventing attacks. I think the best advice in the article came from the operator of a farmer’s market in the town who said that people need to “slow down and breathe and look at what they’re doing.”