The sort of information leaked by poorly designed Web sites won't let anyone else run up charges on your credit card. But the ease with which someone can build a profile of your interests and activities is more than a little creepy.

And the information harvested can be used to create targeted spam or individualized phishing attempts that leverage information about you - "Special for Boston Red Sox fans!" - to extract more valuable data, such as account numbers and passwords.

Considering how easy it is to prevent such attacks, Web site operators have no excuse not to take the steps needed to protect their customers or members.

Get the full story at BusinessWeek