Protect Yourself from Phishing

Typically, Phishing is a type of fraud that leads to the compromise of your email account. In business settings, the perpetrators try to impersonate a company executive or employee, or another closely associated entity such as suppliers, lawyers, auditors, etc., for financial gains or to get unauthorized access to sensitive information by employing a variety of fraudulent techniques.

In most cases, the main objective of the scammers is to eventuate unauthorized fund transfers. Phishing attackers mostly rely on social engineering. This type of fraud typically does not require sophisticated technical skills such as hacking.

The Motive Behind Phishing

  • Trick the user into passing sensitive information such as user id and password for an account, or credit card information or other information which could be proprietary in nature.
  • Trick the user into initiating a transfer of funds
  • Trick the user into clicking on a malicious link, which in turn may lead to the installation of malware such as ransomware or a virus on the user’s system.

Examples

Let’s look at some examples of phishing messages.

Cleverly Designed Emails

The email shown below looks elegant, and it even uses Intel’s colors and also its logo.

Example of Phishing

If the receiver is fooled into entering his/her password and clicks on the “GRADE MY PASSWORD” button, he/she may end up exposing the password to the scammer or may end up with malware.

However, with little effort, you can easily learn that the email is not from Intel but from someone else.

Here is another example:

Phishing Example

The link would lead the user to some fraudulent website that may look like the official website of the bank. If the user enters his/her authentication information, it will be captured by the scammers. Also, if the user attempts to download the statement, it could result in malware infection.

Finance-related messages are the most popular with scammers as such messages help them to create a sense of panic and urgency in minds of potential victims.

Bogus Invoice Scheme

In such attacks, the scammers have specific information on the person who processes invoices, and the suppliers with whom the organization does business.

Such targeted phishing attacks are known as “spear phishing” or “whaling”, and they can be much more devastating than generic phishing messages.

Bogus Invoice Scheme

Attorney/Auditor Impersonation

In this type of scam, the cybercriminal contacts HR department employees or the CFO of the company and identify themselves as lawyers or auditors, claiming to be handling confidential and time-sensitive matters.

Attorney Impersonation

The main objective of scammers here is to steal sensitive information, which can serve as a jump-off point for more damaging attacks in the future.

Protection Measures Against Phishing

The protection measures can be broadly divided into three categories:

  • Technical Measures
  • Policy Measures
  • Training & Awareness

Technical Measures

The technical measures against phishing are the same generic measures that an IT administrator would take to protect against malware.

  • Deploy MFA (Multi-factor Authentication) for all users. This is easily the most important measure that you can take against account hijacking via phishing.
  • Regularly update the OS and the browser
  • Use reliable antimalware software and ensure that it is updated regularly.
  • Use safe browsing extensions such as the uBlock Origin to protect users against domain forgery and various other online attacks.
  • Regularly update the spam filters to protect users against spam and phishing messages.

Policy Measures

  • Define and implement a company-wide wire transfer policy that would restrict the usage of the wire transfer facility and provide enough checks and balances that would protect against the unwanted transfer of funds.
  • Define and implement a company-wide information exchange policy that would restrict, monitor, and direct the movement of classified/sensitive information such as proprietary knowledge, patents, financial information, confidential information such as deals and negotiations, personal information of employees, etc., especially via email. 

Training & Awareness

The most successful strategy in fighting phishing frauds is to ensure continuous user awareness and training.

Here are useful tips:

  • Do not share your account password with your colleagues or a contractor. This should also be highly discouraged by the IT department at all levels.
  • Do not panic. Phishing messages are designed to elicit the user into action; the attackers try to accomplish this by using words such as “Warning”, “Alert”, “Urgent”, “Penalty”, etc. With the help of such words, the attackers try to wage a psychological war against the targeted victim.
  • Often, such messages are sent towards the end of the day or on a Friday/Saturday evening when the user is almost relaxed and is prepared to leave the office. Such timing further increases the pressure on the recipient. If the victim panics, he/she would be playing in the hands of the attackers and would be doing their will.
  • Such “urgent” situations do not arise on a normal workday and if they do, you would be knowing more about them in advance, and you may even be expecting them. So, if the event or the action described in the email is unexpected, it is better to confirm the same using other channels.
  • In case of funds transfer, if the organization has a policy to direct the electronic transfer of funds, follow the procedure in all circumstances. If large sums are involved, confirm it using other communication channels.
  • If the other person is asking for information that is categorized as sensitive, follow the applicable corporate policy for information transmission and exchange. If the information request is non-routine or unusual, please cross-verify the same using other communication channels.
  • Do not subvert corporate policies, in any case, be it however urgent. Your corporate policies are designed in accordance with compliance requirements, and they are there to protect sensitive information at all times.
  • Beware of Links. Always remember that your one single click can make all the difference; never click on any link if you are not sure what it does or where it will take you. Most importantly, if you click on a link that takes you to a page that asks for your username/password for any account whatsoever, do not enter any information.
  • If you receive a phishing message, you should always report it to your IT department or concerned persons. It will help them improve the spam filters to prevent such messages from reaching your mailbox. Also, other people in your organization may also have received similar messages, and if so, it may indicate an active attack against your organization. In such cases, timely reporting can make a substantial difference.
Recent Posts

LET'S GET IN TOUCH...

Contact Us

Google reCaptcha: Invalid site key.