Press Releases

Wednesday, December 01, 2004
Cyota FraudAction Reduces the Lifespan of Phishing Attacks to 5 Hours Compared to Industry Average of 6.4 Days; Service Reduces Banks’ Phishing-related Fraud Losses
Cyota announces key results from its anti-phishing service

New York, NY— [In December 2005 RSA Security acquired Cyota, a New York-based anti-fraud company.]

Cyota, the leading provider of anti-fraud and security solutions for financial institutions, today revealed several key results of its anti-phishing service, FraudAction. Cyota’s anti-phishing solution was developed in mid-2003, the company publicly announced the solution in January 2004. Today FraudAction is live and in use by 5 top American and British banks.

FraudAction is a comprehensive anti-phishing service, including real-time alerts, detailed severity assessments, site shutdown services, forensic work and proprietary counter-measures. The service is deployed by Cyota’s 24x7 Anti-Fraud Command Center (AFCC), which also supports Cyota’s various anti-fraud and security services, as well as identifies and analyzes new trends in the phishing and online fraud industry. Cyota’s suite of anti-fraud solutions is in use by 8 of the top 12 banks in the world.

Key results of Cyota FraudAction to date:
  • Cyota’s AFCC has handled hundreds of distinct phishing attacks per month.
  • Cyota shut down over 60% of attacks in less than 5 hours. Several sites have been shut down in even less than one hour.
  • Cyota has lowered the lifespan of a typical phishing site to 5 hours, compared to the industry average of 153 hours (6.4 days) reported by the Anti-Phishing Working Group.
  • Cyota’s AFCC has found that 2/3 of attacks are hosted internationally; domestically-hosted sites typically take less time to shutdown.
  • Cyota deployed its patent-pending counter-measures in 72% of the attacks.
  • Cyota alerted the bank it is under attack 4 hours prior to the first customer call (on average).
  • One bank benchmarked its phishing-related fraud losses before and after using Cyota’s service, and confirmed that FraudAction lowered its losses by over 50%.
  • Cyota’s AFCC has found that 59% of phishing attacks are hosted on hijacked computers.

"Cyota’s FraudAction delivers immediate results to our clients. By deploying our counter-measures and forensic work and rapidly shutting down the phishing websites, only a fraction of the bank’s customers fall victim to phishing," said Naftali Bennett, Cyota CEO, "We are determined to deal with the bank’s headache – the bank can sleep soundly at night while Cyota works on its behalf to fight phishing and online fraud. FraudAction can be deployed within days – it is extremely effective."

About RSA Cyota Consumer Solutions

RSA Cyota Consumer Solutions, a division of RSA Security Inc., offers proven solutions for online banking and e-commerce that range from adaptive authentication – with risk-based technology, one-time-passwords and transaction-signing – to anti-phishing services and real-time transaction monitoring that controls fraud and manages risk. The company’s eFraudNetwork community is the world’s most effective cross-bank collaborative online fraud network. Today, many of the world’s top 50 banks, including nine of the top 12 banks in North America and the UK, use RSA Cyota solutions to protect approximately 430 million consumers.

About RSA Security Inc.

RSA Security Inc. is the expert in protecting online identities and digital assets. The inventor of core security technologies for the Internet, the Company leads the way in strong authentication and encryption, bringing trust to millions of user identities and the transactions that they perform. RSA Security’s portfolio of award-winning identity & access management solutions helps businesses to establish who’s who online – and what they can do.

With a strong reputation built on a 20-year history of ingenuity, leadership and proven technologies, we serve approximately 20,000 customers around the globe and interoperate with more than 1,000 technology and integration partners. For more information, please visit www.rsasecurity.com