Symantec blogs today on phishers using 1-800 phone numbers to steal information instead of malicious URLs.
In this new type of attack, phishers send an e-mail posing as your bank. The e-mail attempts to trick you into dialing a malicious “1-800” phone number to “verify your account status”. Upon calling the number, you are directed to enter personal information to validate your account. These sound very official, and since many of us have been trained to enter items like social security numbers and bank account numbers when calling our banks, its very easy to get fooled by such a scam.