Phishing


What Makes Government Departments A Prime Target For Cybercrime Such As Phishing Attacks?

What Makes Government Departments A Prime Target For Cybercrime Such As Phishing Attacks?

Cybercrime is one of the primary forms of menace in the online world. Threats like phishing and ransomware attacks have been around for a long time now. Despite the best effort of agencies, both public and private, it does not seem to slow down. From breaking into information system networks to stealing data to impersonations, cybercrime has covered it all. With time, it has grown exponentially. And government departments are highly vulnerable to such attacks due to various reasons.

(more…)

Phishing Attacks In The Manufacturing Industry: Why Is It A Lucrative Target For Phishers

Phishing Attacks In The Manufacturing Industry: Why Is It A Lucrative Target For Phishers

Various industries have fallen victim to phishing globally, and the manufacturing sector is no exception due to decentralized IT infrastructure and fragmented controls, besides many other reasons. Since the beginning of 2020, cyber intruders have exploited several manufacturing units’ vulnerabilities and used them for financial benefits and brand impersonation. Moreover, the lower degree of cybersecurity, policy enforcement, and lack of centralized visibility makes the task easier for malicious actors.

(more…)

Cybersecurity In Insurance Industry: Why Has It Become A Lucrative Target For Threat Actors?

Cybersecurity In Insurance Industry: Why Has It Become A Lucrative Target For Threat Actors?

Insurers deal with enormous risks every day. Risk management is an inherent part of the insurance business. However, the sector has lagged behind other financial services sectors, such as banking, cyber focus, investment, and capabilities when it comes to the cybersecurity front. The banking sector’s increased cyber resilience has been due to the rising number of phishing and other cyber-attacks, which have compelled them to act quickly to protect their customers and reputations. However, the anti-phishing cyberwar has been quieter in the insurance sector.

(more…)

Phishing Threats That Got Reinforced In 2020, And Will Likely Continue in 2021

Phishing Threats That Got Reinforced In 2020, And Will Likely Continue in 2021

With the Pandemic raging across the length and breadth of the world, there has been a lot of chaos and confusion amongst organizations’ workforce. Industries of every hue have suffered, and the end to it is yet to be seen. However, that has not stopped malicious actors from continuing their nefarious activities. 2020 has seen no let-up in phishing attempts, and IT Security specialists have been sleepless at work trying to overcome the relentless menace. Such threats are likely to spill over to the new year. Here is an account of the phishing trends unearthed in 2020 that will likely continue in 2021.

(more…)

What Makes Healthcare Sector A Prime Target And What Can Be Done To Avoid These Phishing Attacks?

What Makes Healthcare Sector A Prime Target And What Can Be Done To Avoid These Phishing Attacks?

The medical world has been one of the domains that have seen unprecedented advancement.  Medical science has advanced over the years, and life expectancy has improved vastly. However, all is not well with the healthcare sector. Phishing and cyber-attacks on its systems have been relentless and mostly successful.

Numerous instances of system disruption and loss of records have been reported from around the world. For example, one victim from last year was Montana-based Kalispell Regional Healthcare, which stated that the breached data has led to the disclosure of 140,000 patients’ information. The phishing attacks happened over three months.

(more…)

The Rise Of Package Delivery Phishing Scams In COVID Times

The Rise Of Package Delivery Phishing Scams In COVID Times

In times of the Coronavirus Pandemic, when people are too apprehensive of walking to the local stores and malls, the internet and online shopping come as a relief to shoppers. Almost every day, package tracking, order confirmation, or cancellation messages from FedEx, Amazon, UPS, DHL, and other organizations pop up in the inbox. Hence, receiving fake package delivery messages look neither unusual nor suspicious.

(more…)

Rising Phishing Attacks On Schools And Colleges As Online Education Becomes More Prevalent Than Ever

Rising Phishing Attacks On Schools And Colleges As Online Education Becomes More Prevalent Than Ever

As online education has become more prevalent than ever, schools and colleges face tremendous challenges due to COVID-19. There is growing uncertainty on the revival of regular classes for students. Many educational institutions have resorted to online education as an alternative. However, online education comes with its disadvantages. Cyber adversaries now have one more sector to target. By the looks of it, schools and colleges have become easy targets for these malicious actors. Let us discuss why it is so and how to avoid the threat.

(more…)

Covid-related Phishing Attacks are Just Getting Started

Covid-related Phishing Attacks are Just Getting Started

Covid has been around for more than seven months now. And in that time, it has become the number one source of phishing attacks worldwide. We even detailed ten ways hackers use Covid to phish you in a recent post. It’s been so widespread, almost everyone is wary of Covid-related phishing emails by now. You might think that would put an end to them, but nothing could be further from the truth. When it comes to fraudsters, Covid is the gift that keeps on giving.

(more…)

An Email Phishing Test That Totally Backfired

An Email Phishing Test That Totally Backfired

How good are your employees at spotting phishing emails? There’s a really easy way to find out. Send each one of them a fake phishing email and see how many click. And that’s exactly what Tribune Publishing, publishers of the Chicago Tribune, did recently, and boy did it backfire.

According to The Big Lead, “The media giant has spent the last few years cutting staff at newspapers across the country, leaving workers underpaid and overworked. On Wednesday the company sent out emails to employees suggesting they would be getting raises for all their hard work. It turns out it was a test to see how susceptible they were to a phishing scam. Needless to say, the employees were furious.”

(more…)

The Phishing Attack You Knew Was Bound to Happen

The Phishing Attack You Knew Was Bound to Happen

When it comes to preventing phishing attacks, companies are often torn between how to spend their security dollars. The choice they make is usually between two options: employee awareness training and email security hardware/software. The first choice assumes your employees can protect you from phishing attacks if only they can be taught to spot them. The second choice assumes there’s not enough training in the world for you employees to stop every phishing attack—it’s better to leave that to technology.

(more…)

Here Come the Election-Related Phishing Attacks

Here Come the Election-Related Phishing Attacks

If it’s time for a big election, you can be sure the scammers will take advantage of that in the next round of phishing attacks. But, election-related phishing attacks may not target who you think. Rather than go after voters, who aren’t accustomed to having to provide credentials in response to an election-related email, the hackers “target political parties and campaigns, think tanks, civic organizations, and associated individuals,” according to CISA (Cybersecurity & Infrastructure Security Agency), a U.S. federal agency responsible for the nation’s cyber infrastructure and readiness, which issued the warning.

(more…)

The Surprising Facts Behind Brand Impersonation Attacks

The Surprising Facts Behind Brand Impersonation Attacks

As far as phishing attacks go, brand impersonation is the go-to tactic for attackers. This is especially true for credential phishing and business email compromise attacks (BEC). And according to a recent analysis, there are some pretty surprising discoveries regarding brand impersonation.

For starters, is the top 10 list of most phished brands. Many are recognizable like Microsoft, Google, PayPal and NetFlix. But there were also some lower profile organizations that surprisingly made the top 10 list including Maersk, DHL and WeTransfer. Not exactly household names.

(more…)

Phishing Attacks are no Longer Just Malicious Links in Emails

Phishing Attacks are no Longer Just Malicious Links in Emails

Combating phishing attacks used to be just a matter of not clicking on malicious links in an email. If you could spot the suspect link in an email, and didn’t click it, you were pretty much guaranteed to be safe. Not anymore. Oh sure, hackers still want you to click on a malicious link, but their techniques for disguising them is nothing short of remarkable.

(more…)

Is There Something Worse Than Getting a Layoff Notice?

Is There Something Worse Than Getting a Layoff Notice?

There are two really scary aspects to getting a layoff notice. First, of course, is that you’re being laid off, which stinks. The other is that it almost always comes without warning and catches you off guard. When you get the notice, your heart starts racing, you may even panic a little. The last thing you’re prepared to do is to identify the email as a phishing scam. And that’s exactly what the scammers are counting on.

(more…)

If These Guys Can Get Phished Anyone Can

If These Guys Can Get Phished Anyone Can

Who would you expect to be the last organization taken in by a phishing attack? How about the “largest source for information security training and security certification in the world?” That’s right. The SANS Institute, around since 1989, training more than 165,000 security professionals around the world, was just breached as the result of a phishing attack.

(more…)

It Doesn’t Take Long for a Phishing Attack to do its Damage

It Doesn’t Take Long for a Phishing Attack to do its Damage

Given how widespread phishing attacks are, you might think that not only are there a lot of phishing attacks, but that each one lasts a long time. While it’s true that there are a lot of phishing attacks, most phishing attacks do their damage in a really short time.

Research conducted by USENIX recently examined 4.8 million victims who visited phishing pages in a one-year period. And what was the average time of an attack measured by the researchers? “[F]rom the time they first come online, to email distribution, to visitor traffic, to ecosystem detection, and finally to account compromise, we find the average campaign from start to the last victim takes just 21 hours.” Twenty-one hours! It’s over in less than a day.

(more…)

You’ll Never Guess What was Behind the Great Twitter Hack: Phishing

You’ll Never Guess What was Behind the Great Twitter Hack: Phishing

If you haven’t already heard, Twitter was hacked recently and some pretty high-profile people like Barack Obama and Elon Musk had their accounts compromised. When such a powerful tech company as Twitter gets taken like that, the first impulse is to assume it’s some band of sophisticated hackers or a rogue nation employing some leading-edge network penetration technology that does the damage. But in the case of Twitter, as with most high-profile attacks, nothing could be further from the truth.

(more…)

When it Comes to Phishing You Can no Longer Trust Trusted Services

When it Comes to Phishing You Can no Longer Trust Trusted Services

At this point, it’s probably impossible to find a company that doesn’t rely on some cloud-based trusted services. Trusted services are services offered by companies so well recognized and respected, that we never give it another thought whether to trust them or not. Companies like Google, Microsoft and Dropbox. We all use them and we all trust them. And that’s exactly what hackers are counting on.

(more…)

The Numbers are in: You Can’t Stop Email Impersonation Without Help

The Numbers are in: You Can’t Stop Email Impersonation Without Help

Email impersonation is one of the most prevalent and effective types of phishing attacks. Why is that? Because this type of phishing email supposedly comes from someone or some company you know, so you let your guard down. “As the professional community continues to work in a remote environment, email impersonations present the perfect way for opportunistic fraudsters to take advantage of human vulnerabilities.”

(more…)