Phishing Scams

PHISHING

This is most common way to scam innocent, unsuspecting victims by using social engineering tactics. In this ploy, fraudsters can impersonate legitimate company or friend to steal people’s personal data including login credentials. e.g Bogus emails use threats and a sense of urgency to scare users into doing what the attackers want. Phishing attacks continue to play dominant role in the digital threat landscape.

Digital fraudsters show no signs of slowing down their phishing activities. Some attacks leveraged Office 365 as a lure and target accounts used for single sign on. The rise of phishing attacks poses a significant threat to organizations and individuals everywhere. It is good to be familiar with some of these techniques that malicious actors use to pull off these scams.

Common types of phishing attacks and some tips to reduce them includes:

1 Deceptive Phishing (Generic attack)

This leverage on how close a fake email resembles official correspondence but from a spoofed source. Users should inspect all (Uniform Resource Locator) URLs carefully to see if they redirect to suspicious website. it mostly comes with generic salutations, grammar mistakes, and spelling errors.

Never click links in the email, they can be very dangerous.

2 Spear Phishing (Specific personnel attack)

Organizations should discourages workers from publishing sensitive personal or corporate information on social media. Analyze inbound emails for known malicious links/email attachments.

3 Whaling (CEO fraud attack)

Whaling attacks occur mostly when executives often do not participate in security awareness training with their employees. Multi-Factor Authentication (MFA) integration is highly advisable.

4. Vishing (Phishing through voice calls)

Users should avoid or be careful when answering calls from unknown numbers, never give out personal information over the phone, and consider using caller ID app.

5 Smishing (Phishing through SMS)

Defend against this attacks by researching unknown phone numbers SMS and by verifying the sender’s credentials spotted in unsolicited SMS messages.

6 Pharming (malicious code injection on computer or server)

You are encouraged to enter your credentials only on HTTPS-protected websites and use a trusted Internet Service Provider (ISP).

Phishing scam is constantly evolving. With that in mind, it’s imperative that organizations conduct routine security awareness training so that their employees and executives can stay on top of “Phishing’s evolution”.

You Install NETCRAFT toolbar extension from https://www.netcraft.com/ for your preferred browser to help you spot out phishing websites.

Thanks


Engr. Chikwado Okeke
Cybersecurity Professional
https://possibond.com.
+234(0)8127944123