card image

WHAT IS PHISHING?

Phishing is a cyber crime that leverages deceptive emails, websites, and text messages to steal confidential personal and corporate information.

Victims are tricked into giving up personal information such as their credit card data, phone number, mailing address, company information, etc. This information is then used by criminals to steal the victim’s identity and commit further crimes using this stolen identity.

Criminals who use phishing tactics are successful because they carefully hide behind emails and websites familiar to the intended victim. For example, the email address might be administrator@paypal.org.com instead of administrator@paypal.com and urge the recipient to update their account credentials to protect them from fraud.

Phishing is a type of social engineering that criminals use to steal data, infect computers, and infiltrate company networks

What are the different types of Phishing?

Email

This is the most common phishing tactic. An email is sent to multiple recipients urging them to update personal information, verify account details, or change passwords.

Typically, the email is worded to promote a sense of urgency, sometimes highlighting the recipient’s need to protect themselves or their organization. The email is designed to appear to come from a legitimate source, such as customer service for PayPal, Apple, Microsoft, a bank, or other known companies.

 

Content Injection

A familiar-looking webpage, like an email account login page or online banking page, is injected with malicious content. The content can include a link, form, or pop-up that directs people to a secondary website where they are urged to confirm personal information, update credit card details, change passwords, etc.

 

Link Manipulation

A carefully worded email arrives with a malicious link to a familiar website such as Amazon or another popular website. When the link is clicked, it takes people to a fake website designed to look exactly like the known website, where they are then prompted to update their account information or verify account details.

 

CEO Fraud

This common type of domain spoofing includes sending emails that masquerade as coming from the CEO, human resources, or a colleague. The email may ask the recipient to transfer funds, confirm an e-transfer or wire transfer, or send tax information.

 

Fake Websites

Hackers create fake websites that look just like a highly frequented website. This fake website has a slightly different domain, for example, outlook.you.live.com instead of outlook.live.com. People believe they’re on the right website and accidentally open themselves to identity theft.

 

Mobile Phishing

Mobile phishing can involve fraudulent SMS, social media, voice mail, or other in-app messages informing the recipient that their account has been closed, compromised, or is expiring. The message includes a link, video, or message to steal personal information or install malware on the mobile device.

 

Spear Phishing

Spear phishing is advanced targeted email phishing. The criminal targets a specific individual or organization and uses focused, personalized messages to steal data that goes beyond personal credit card information. For example, infiltrating a hospital, bank, or university to steal data severely compromises the organization.

 

Voice Phishing

With voice phishing or vishing, a phone caller leaves a strongly worded voicemail or reads from a script that urges the recipient to call another phone number. Often these calls are designed to be urgent and encourage the recipient to act before their bank account is suspended or, worse, they may be charged with a crime.

 

Session Hijacking

This type of phishing requires sophisticated techniques that allow criminals to violate a web server and steal information stored on the server.

 

Malvertising

This type of malware uses online advertisements or pop-ups to encourage people to click a link that installs malware on the computer.

 

Malware

Malware happens with a person clicks an email attachment and inadvertently installs software that mines the computer and network for information. Keylogging is one type of malware that tracks keystrokes to discover passwords. A trojan horse is another type of malware that tricks someone into entering personal information.

 

Man-In-The-Middle

With man-in-the-middle phishing attacks, the criminal tricks two people into sending information to each other. The phisher or criminal may send fake requests to each party or alter the information being sent and received. The people involved believe they are communicating with each other and have no idea a third party is manipulating them.

 

Evil Twin Wi-Fi

A fake Wi-Fi access point is created that acts as a legitimate Wi-Fi hot spot. This tactic is common in coffee shops, airports, hospitals, or locations where people routinely need Wi-Fi access. People log into this Wi-Fi access point thinking they’re using the legitimate spot, allowing criminals to intercept any data communicated on this fake Wi-Fi account.

These different types of phishing are part of a greater social engineering scheme. Social engineering is a savvy way to trick people into giving up information, access, and details they know they should keep secure and private.

How Common is Phishing?

In a word: extremely.

The reality is simple – three billion fraudulent emails are sent out every day as part of phishing schemes aimed at accessing or compromising sensitive information. According to Verizon’s 2021 Data Breach Investigations Report, more than a third of data breaches in 2021 leveraged some kind of phishing component. In addition, nearly 75% of phishing scams used HTTPS sites to perpetuate their attacks, which makes those threats more challenging to spot and avoid.

As unprecedented digital transformation continues to impact many industries worldwide, all organizations must bolster the human side of their cyber security practices through current, multifaceted phishing simulation and awareness training initiatives.

For more information on global phishing benchmarks collected through the Gone Phishing Tournament, as well as expert tips on how you can minimize related risk, download your free copy of the full report.

How to Prevent Phishing

  1. Educate your employees about phishing. Take advantage of free phishing simulation tools to educate and identify phishing risks.
  2. Use proven security awareness training and phishing simulation platforms to keep employees' phishing and social engineering risks top of mind. Create internal cyber security heroes committed to keeping your organization cyber secure.
  3. Remind your security leaders and cyber security heroes to regularly monitor employee phishing awareness with phishing simulation tools. Take advantage of phishing microlearning modules to educate, train, and change behavior.
  4. Provide ongoing communication and campaigns about cyber security and phishing. This includes establishing strong password policies and reminding employees about the risks that can come in the format of attachments, emails and URLs.
  5. Establish network access rules that limit the use of personal devices and the sharing of information outside of your corporate network.
  6. Ensure that all applications, operating systems, network tools, and internal software are up-to-date and secure. Install malware protection and anti-spam software.
  7. Incorporate cyber security awareness campaigns, training, support and education into your corporate culture

What is a Phishing Simulation?

Phishing simulation is the best way to raise awareness of phishing risks and identify which employees are at risk for phishing.

Phishing simulation allows you to incorporate cyber security awareness into your organization in an interactive and informative format.

Real-time phishing simulations are a fast and effective way to educate people and increase alertness levels to phishing attacks. People see first-hand how CEO fraud, emails, fake websites, malware and spear phishing are used to steal personal and corporate information.

What are the Top 10 Benefits of a Phishing Simulation?

  1. Measure the degrees of corporate and employee vulnerability
  2. Eliminate the cyber threat risk level
  3. Increase user alertness to phishing risks
  4. Instill a cyber security culture and create cyber security heroes
  5. Change behavior to eliminate the automatic trust response
  6. Deploy targeted anti-phishing solutions
  7. Protect valuable corporate and personal data
  8. Meet industry compliance obligations
  9. Assess the impacts of cyber security awareness training
  10. Segment phishing simulation

Related Case Studies

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam.

What is Ransomware

What is Ransomware Ransomware is a type of malware and cybercrime that holds data for ransom. Access to data on computer networks, mobile devices, and servers is locked until the victim pays a ransom. APP WordPress CATEGORY Development LINK www.example.com What Are the Main Types of Ransomware? Crypto Ransomware Crypto ransomware prevents access to personal

View Case Studie Details

What is Social Engineering

Social engineering is a manipulation technique used by cybercriminals to trick people into giving up confidential information.

View Case Studie Details

Our Valuable Clients