Industry Voice: Defending your brand against use by online criminals
Lucien Taylor, Chief Strategy Officer at the DNS Research Federation, tells us that insurance and health companies need to work together to protect their brands from being industrially weaponised by online criminals
Most of us have received one: a text alert or email from a health insurer, a car hire firm, an airline, a travel insurer or accommodation provider that includes a familiar brand name that looks a little suspicious. It’s become an everyday feature of managing all aspects of our health and travel online.
In Britain today, the average person now receives around 240 scam emails or texts a year, with one in eight receiving double this. According to our latest consumer research, the majority of people (51%) now receive at least one scam message every week. The impact of this for the consumer is very serious. The average amount of money Brits lose to online scams has hit a national average of £1,169 per person, with 7% claiming to have lost more than £7,500 to scammers. Younger people are more likely to fall for online scams – but older people are more likely to lose the most money.
In addition to the consumer, there is also a massive issue for brands. Scammers need to leverage familiar household name brands to make their emails and text messages look legitimate – and today they are infringing and weaponising the integrity of big brands on an industrial scale. Our own consumer research revealed that 97% of UK adults could name one or more brands that had appeared in the attempted scams they had received. This puts people’s safety at risk and, ultimately, damages consumer trust in the brands they deal with every day.
Targeting healthcare
Healthcare, medical insurance, general insurance and travel are all in the sights of the online scammers. Furthermore, since Covid-19, when consumers switched online from the high-street world, more people now research insurance quotes, manage health cover and book holidays online. This exposes more people to the risk of scams – and our focus-group work on the victims of scams suggests that text or email scams often (at a glance) look more legitimate to consumers than the actual messages they get from the brands they deal with.
According to our latest consumer research, the majority of people (51%) now receive at least one scam message every week
To tackle this growing problem, the team of data scientists at the DNS Research Federation has designed a market-leading piece of global analysis that tracks the abuse of the top 500 brands over time. Already 12 months into this mammoth study, we are looking at brands across 17 industry sectors. At the moment, we are analysing, in real time, global intelligence feeds from 93 major sources – the biggest data feed of its kind anywhere in the world. It’s a huge amount of data on online abuse and, over the last year, we have been dividing all of that data into sectors and looking at the prevalence of brands in threat feeds and online attacks. Travel and tourism along with health, financial services and insurance form part of this study.
Abuse of the travel sector
For travel and tourism, the sector currently ranks mid-table, ninth of 17 sectors analysed, with tech and home delivery brands topping the list. Currently, we are reporting 902 abuse reports in the travel and holidays sector in the past 365 days. Each individual abuse report could be an event or a website that could impact thousands or millions of people. These attack URLs (links), as we call them, are typically presented to users in texts and messages, inviting them to follow the link and visit a fake website. Attack links can be used to target many victims and we are looking into better reporting to determine the number of victims per attack site. According to our data, scammers are targeting the travel sector at an average of 26 fake websites per brand.
Concern for the insurance industry
With the insurance and finance sector, the picture is even more concerning. Ranking seventh of 17 sectors, our latest data has identified 1,524 abuse reports – or scam websites – in the last 365 days. At the moment, we are looking at insurers and banks together because so many of the latter also offer insurance products to the general public.
With the analysis of insurers, the big brands are prominently there in the abuse reports; given that the online scammers operate on a global scale in the online world, the allure of big global brands is important to them. The major travel, health and insurance brands are all appearing in our threat and abuse reports, meaning that there are links that are in themselves mini factories for scam. This is where a scammer has built a website, developed a link, which impersonates the brand.
At the moment, we are analysing, in real time, global intelligence feeds from 93 major sources – the biggest data feed of its kind anywhere in the world
People get assurance from choosing big brands, but when you assume you’re going for a safe, trusted brand online, it may not be the case. Furthermore, the evolution of DIY holidays and people buying financial products from different brands creates fragmentation – and this increases the number of text messages and confirmation emails consumers get for a range of purchases. This can leave consumers more vulnerable to falling for a scam on their phone.
In the fight against online crime, our mission at the DNS Research Federation is to make sense of the internet; to gather and analyse threat intelligence and publish research that helps businesses and policymakers to tackle online crime.
And there is a solution – but it requires everyone getting involved. And the clock is ticking.
Brands all need to work together and they need to share threat data – not personal data, but top-level data on suspicious or abuse reports. For health insurers and travel brands that operate in a competitive context, this may seem unnatural, but it urgently needs to be done. Scammers work together, they share information globally and they move very quickly. The days are long gone when any individual brand can even consider the notion of tackling online crime alone.
As part of our work, we participate in – and speak at – the world’s leading industry events and conferences. We meet a lot of people from banks. We meet a lot of internet service providers. We meet the big platforms and law enforcement agencies, of course. Travel brands and health insurers need to be more visible at these gatherings. We all need to work together for the sake of the consumer and the future of a free and open internet.
Trust Checker
In the months ahead, there will be various tools and outputs from the ground-breaking work of our data scientists. As an example, one thing that we think has been missing is something simple, practical and universally available to all consumers. ‘Trust Checker’ is a new tool we have created that allows people to check the validity of links they may receive via text or email. So if you get a message that you think looks a bit dodgy – whether it be from an airline, health insurer, car hire brand or hotel group – put the link into the Trust Checker, and it will give you an instant A, B, C score. It’s a simple tool that can encourage the consumer to stop, take a breath and verify a link before clicking on it. In a world where everyone’s lives are dominated by emails and text messages – confirming bookings, payments and deliveries – Trust Checker can help give consumers some comfort that there are no nasty financial surprises lurking in their phone messages that can ruin a day or empty their bank account.
The DNS Research Federation – one of the world’s leading not-for profit organisations – is committed to advancing the understanding of the Domain Name System’s impact on cybersecurity, policy and technical standards. The team is calling on major brands to support its work and be part of the cooperation and knowledge sharing that is required to tackle online scams and – in doing so – protect the integrity of their brands and the wellbeing of the customer.
To discover more and support the work that the DNS Research Federation is doing, visit dnsrf.org, and visit TrustChecker at trustchecker.co.uk.
January 2025
Issue
In this issue we look at worldwide travel trends for the year ahead; speak to insurance experts about how they go about understanding their customers; examine the pros and cons of living and working in Saudi Arabia; and look at the shift in the international student community.
Lucien Taylor
Lucien is Co-Founder of Oxford Information Labs, a cyber intelligence consultancy, and the DNS Research Federation, a UK not-for-profit aiming to advance the understanding of the Domain Name System’s impact on cybersecurity, policy and technical standards. He and his team have co-designed a number of innovative DNS specialist and security systems, providing services for big tech, non-governmental organisations (NGOs), government, educational and financial organisations. Lucien regularly presents at internet technology, security and governance events, and has taught compact seminars at several universities.