Phishing Awareness


Use Humor to Get Your Employees Serious About Phishing Awareness

Use Humor to Get Your Employees Serious About Phishing Awareness

For most people, phishing scams are not high on the list of potential sources of comedy, although there are plenty of examples of blundering scammers and inept cybercriminals who got their due. 

When it comes to phishing awareness training for organizations, however, humor can be a powerful tool for maintaining complianceConsidering the alarming number of employees who admit to falling for phishing scams even after training, plenty of organizations are ready to change their security training approach.

(more…)

Why More and More Phishing Attacks are Going After Mobile Users

Why More and More Phishing Attacks are Going After Mobile Users

Phishing attacks are hard to stop because hackers are extremely sophisticated and they use every method available. What hackers have discovered is that one of the best methods available is to target mobile devices. As challenging as it is for users to identify well-constructed phishing emails on a desktop, it’s much more difficult on mobile devices and hackers know it. And they’re starting to take advantage of it.

According to an article by security firm cyperscoop, Phishing attacks against mobile devices rise 85 percent annually. Why is that? From the article, “It’s harder to spot phishing websites on mobile devices compared to a desktop computer which puts the most important device in people’s lives at a distinct disadvantage. As a result, mobile users are historically more likely to fall for phishing attacks.”

(more…)

Phishing in the News

Phishing in the News

2018’s Primary Breach Actors Were Malicious Outsiders

According to a Whitepaper by security firm Tripwire, “2018’s primary breach actors were malicious outsiders. They were behind 56 percent of all breaches, followed by

  • accidental loss at 34 per­cent,
  • malicious insiders at 7 percent,
  • hacktivists at 2 percent, and
  • the remain­ing 1 percent falling into unknown.”

(more…)

How Keeping Up With The News Can Get You Hacked

How Keeping Up With The News Can Get You Hacked

One of the easiest ways to get hacked is through a phishing email. Phishing emails contain either a malicious attachment or include an embedded link to a malicious website.

Of course, many people are getting wise to phishing emails and aren’t so easily fooled. But what if you receive a phishing email from the last place you’d ever expected to receive one from? Would you still have your guard up?

A recent study by news agency Axios discovered that only 6% of news organizations deploy DMARC on their email newsletters. DMARC (Domain-based Message Authentication, Reporting and Conformance) is a sophisticated but widely-available technology that ensures emails are authentic.

The study found that of 98 news sites tested, only one had fully operational DMARC. “The list of sites not protected by DMARC includes influential news sources, from the New York Times and USA Today to Fox and NBC networks to Voice of America and major international outlets.”

 

phishing emails

 

Without DMARC deployed, hackers can compromise email newsletters to send out fake news and potentially compromise an election. Or worse. They could use the compromised newsletters to send phishing emails to all the recipients.

Hackers are getting more sophisticated. They target emails they know have a high likelihood of getting the recipients to lower their guard. Until news organization start deploying existing technologies like DMARC to protect their readers, it’s incumbent upon the readers to protect themselves. Fortunately, there are easy-to-deploy, inexpensive, cloud-based email protection solutions like PhishProtection.

To learn more about how PhishProtection can protect you from news organization phishing attacks and many other vulnerabilities,

Deceptive Links Make Phishing Emails Even Harder for Users to Detect

Deceptive Links Make Phishing Emails Even Harder for Users to Detect

If you’ve been trained to detect phishing emails, then you know it’s best not to click on links in an email. And if you do decide to click on a link, you’ve also been trained to hover your mouse over the link to check to see if the link is legitimate. But, what if the hackers are so good they make you think a malicious link is genuine? Would you click on it? You might.

Here is the URL displayed on a mouse over of a link found in an email in the Google phishing quiz:

https://google.com/amp/tunyurl.com/7u8ewlr

Does it look legitimate to you? It did to me. If all you do is what I did and look at the first part of the URL, you’ll be deceived into thinking it’s the real thing. But it’s not! As things turn out google.com is just a subdomain. The actual website is a redirect of the domain tinyurl.com.

Are most users sufficiently trained to recognize these deceptive links? Probably not. That’s why, if you really want to protect your users from phishing emails, it’s best to leave it to technology. Technology that doesn’t get fooled by deceptive links.

 

PhishProtection

 

 

PhishProtection’s email security service doesn’t get fooled by deceptive links. Not only does it scan all embedded email links, but it also scans the websites those links point to. So, no matter what a link “looks” like, if it ultimately leads to a malicious website, PhishProtection will protect you.

If you’re a small business, on a limited budget, but you’d still like to be protected from advanced phishing techniques like these, there’s good news. You can now get advanced phishing technology at a price that fits your budget.

PhishProtection anti-phishing software can help provide phishing attack prevention for your small or mid-size business, even if your email is hosted on a third-party cloud provider like Office 365 with our advanced threat defense office 365 phishing protection solution.

Combating the Threat of Phishing in the Modern Corporation

Combating the Threat of Phishing in the Modern Corporation

Phishing is possibly the single most dangerous form of cyber attack facing individuals and corporations in today’s world because it exploits people rather than systems. At a very high level, phishing is any form of attack that trades on the trust of a person or corporation to reveal some information they wouldn’t normally reveal.

(more…)

Can Phishing Awareness Training Cause More Harm Than Good?

Can Phishing Awareness Training Cause More Harm Than Good?

Filtering and time-of-click protection can produce results where training fails.

First, the facts: Employees who are unaware of the dangers of phishing are far more likely to become victims of phishing attempts than those who understand the process.

The FBI estimates that organizations across the United States lose $1.2 billion every year due to email scams. Since phishing is by far the most popular way to get malicious code into an organization’s network, it follows that training employees to recognize phishing attempts is an effective strategy to prevent phishing attacks.

(more…)

The Top 5 Phishing Scams in History – What You Need to Know

The Top 5 Phishing Scams in History – What You Need to Know

Learn how to protect yourself by studying the biggest phishing scams in history

If we draw an analogy between phishing and fishing, some scam artists are industrial-sized trawling operations that scrape the sea clean.

Automated software and sophisticated tools make it possible for enterprising cybercriminals to scale their fraudulent emails in ways never imagined. Processes that used to be laborious and time-consuming can now be coded into automatic routines that cast a wider net than the previous generations of cybercriminals were ever able to.

(more…)