Table of Contents
Introduction
When I started my cybersecurity journey, I thought hackers are incredibly talented individuals who can hack into any account and steal passwords. All they need is a laptop and a good internet connection. Little did I know, that is not possible – without your help! While hackers get the spotlight in the media, it’s not widely known that the cryptographic functions used in storing your login credentials are quite sophisticated and will take years, if not millennia, to crack!
Then how do hackers gain access to millions of user’s credentials that you always hear in the news? You help them make it happen! Unexpected, right? And the most common method through which they can access your sensitive information is via a phishing attack. It is the perfect example of how hackers use the simplest of ways to hack into your accounts.
What is a Phishing Attack?
Phishing (pronounced “fishing”) is one of the most critical cyber threats that we face today. The 2020 Data Breach Investigation Report (DBIR) from Verizon found that over 90% of data breaches start with a successful phishing attack. Why are they so successful? It’s because they prey on the weakest link in any cybersecurity chain – humans.
So, what exactly is Phishing? Similar to “fishing,” hackers use a baited hook to lure potential targets into biting it. The objective is to gain access to sensitive information such as personally identifiable information, banking, and credit card details or downloading malicious software on your device that can further spread throughout the network and create unprecedented havoc.
The most preferred means is via email, but Phishing through phone and SMS is not uncommon. By carefully writing an engaging and enticing email, phone call, or SMS, hackers can convince the victim that they are a trusted entity of some kind – either a company or a real person.
While this is the oldest type of cyberattack, dating back to the 1990s, it is one of the most widespread and efficacious strategies used by hackers to access your personal and company data. As it requires very little capital to implement, some phishing campaigns can cover hundreds, if not thousands, of accounts.
We should not underestimate the power of a phishing attack. It has proved to bring individuals and companies to bankruptcy and even influence elections! There are an estimated 156 million emails sent each day, 16 million make it through the spam filters, and 800,000 out of which are not only opened but the phishing links clicked or attachment downloaded. Out of those who clicked, an estimated 80,000 shared compromising information.
Hackers of all levels widely use this simple, effective, and affordable attack. While it is not possible to completely shield yourself from such an attack, organizations of all sizes should have protections in place to stop and mitigate phishing attacks.
5 Characteristics of Phishing Attacks
While some phishing emails are tough to detect, making it hard for even seasoned cybersecurity professionals to catch them, most phishing attempts are easy to recognize. Phsihing.org suggests the following characteristics that you can use to identify it as an attempt and block the email address.
- Too good to be true – Profitable offers such as “You have won an iPhone, a lottery or any other lavish prize” are a clear indication that the person wants you to click on the link that will harm you or your computer. Remember always to mark such emails as a scam and NEVER click on the link or attachment.
- Sense of Urgency – a tactic used by every conman, creating a sense of urgency prevents people from being cautious to situations. Such attempts revolve around some issue with your account that will result in termination if not fixed immediately. The victims are then asked to quickly update their personal details over the internet, which are then used for accessing their financial and online account details. It is always better to visit the source directly rather than clicking the link on the email.
- Hyperlinks – Hyperlinks allow you to connect a web address to a word in an email or article and is extremely handy in blogging and emails. However, hackers use this tool for nefarious purposes. They hyperlink phrases to lead the user to a malicious website that downloads payloads such as ransomware or other viruses on their computer. Therefore, one should make it a habit of hovering over hyperlinks (before clicking them) to see the web address. If the address is different from the one you expect, do not click it!
- Attachments – Hackers use email attachments to lure unsuspecting individuals into downloading and opening them. These files might contain malicious software that can perform various functions – keylogging, ransomware, and others. Even the files with the extension .pdf or .doc can have malicious software embedded in them. The only file that is safe is a .txt extension. These attacks can even come from an email address you have frequent communication. If you find the subject and body of the email suspicious, it is always better to call and confirm with the sender before opening such an attachment.
- Unusual sender – If you find any email suspicious, whether it be an unknown sender, out of ordinary language or context, make it a general practice to not click on it!
Top 5 Types of Phishing Attacks
There are several ways you can categorize phishing attacks – purpose, method, or target. However, we will focus on the top 5 phishing types relevant to Small and Medium businesses for this blog post.
- Deceptive Phishing – in this most-used phishing attack, fraudsters impersonate a legitimate company to steal people’s personal data or login credentials. These emails frequently use fear and urgency to scare victims into clicking on malicious links or attachments. For example, a phishing attempt could claim to be from IRS that requests you update your details to avoid penal action.
- Spear Phishing – this kind of attack, as the name suggests, is analogous to a fisherman aiming at one fish and using a spear to catch it as opposed to casting a wide net to catch several fish. Hackers using this technique identify their targets after extensive reconnaissance of the company via its publicly available information (LinkedIn, News, social media). They then use spoofed email addresses to send emails to the target that seem to come from their coworkers or managers. In the majority of the cases, the target is to transfer funds on short notice.
- Whaling – This is a form of spear phishing that targets the CEO or other high-value targets such as the Board members. While this method might take some time, it can be advantageous for the hacker as the targets have high authority and access to sensitive company data.
- Vishing – while email is the most common means for delivering a phishing attack, many hackers rely on phone calls for the same goal. Through a Voice over Internet Protocol (VoIP) server, the hacker can mimic various entities to steal sensitive data and funds. Like a conman, the confidence of hackers can circumvent most suspicions of the victims.
- Smishing – relying on the SMS medium to deliver a phishing attack, hackers send malicious text messages to fool users into clicking on a malicious link or transferring funds unknowingly. Alternatively, attackers can also download a malicious app to the victim’s phone to steal financial information or remotely control their devices.
Phishing is now a child’s play
As the internet users are increasing, so are the hackers. Nowadays, a new hacker does not need an exact skillset to attack a person or a company. With free hacking tools available over the dark web, anyone worldwide with access to a browser and a credit card can rent out such tools or services.
There are several phishing kits available that make it easy for cybercriminals to launch phishing campaigns. After installing the kits on a server, an attacker only needs to send out emails to potential victims.
These kits create a cloned version of a legitimate website and change the login page to a credential-stealing script. The quality of these cloned websites are getting better each day, and it is becoming hard for even the most seasoned cybersecurity professionals to detect them.
Phishtank and OpenPhish are crowd-sourced lists of known phishing kits. There are more than 5000 phishing kits available at the time of writing this article. Some of these kits specialize in spoofing trusted brands such as Microsoft, PayPal, and Dropbox.
Famous Examples of successful Phishing attacks
Federal Trade Commission filed the first phishing lawsuit in 2004 against a teenager who created an imitation of the “America Online” website. Through this fake website, he collected sensitive information from users, which allowed him access to credit card details and ultimately withdrew money from their accounts.
Cybercriminals targeted corporate CEOs with emails that claimed to have an FBI subpoenas attached in a whaling attack. Preying on the executives’ fear, they could download keyloggers onto the executives’ computers to steal essential credentials. With a success rate of 10%, the hackers were able to dupe almost 2,000 victims!
The cloud security company Armorblox explained that it had come across a phishing attack attempt targeted towards the top 50 innovative companies in the world in 2019. The attack email used spoofing techniques to share an “internal financial report” to trick its recipient. It then redirected recipients to a fake Office 365 login page to steal their credentials.
Israeli Startup and VC Company – Deploying a successful MITM attack, the hacker could walk away with $1 million of startup seed money by creating a fake domain with an extra “s” at the end and tricked both sides into routing emails through the attacker’s servers.
Leoni AG, a large German manufacture of optical fiber, wire, and related products, was a victim of the CEO Fraud/BEC attack in August 2016. The hacker had studied the company’s payment process after a successful phishing attack in detail and stole $44 million from the company. The attacker convinced the CFO that the funds transfer request was from its senior executives in Germany.
Ubiquiti Networks were victims of multiple CEO Fraud/BEC attacks that resulted in the company transferring $46.7 million to cybercriminals in June 2015. This spear-phishing attack used a simple email address spoofing and targeted Ubiquiti’s finance department.
Hillary Clinton Campaign Hacked! – One of the most powerful phishing attacks in history! Many work-related emails were leaked to the public, with Hillary Clinton Campaign’s chair falling prey to a spear-phishing attack. It had a massive impact on the 2016 elections, which ruled in favor of Donald Trump.
Fappening Phishing Attack – In this attack, many intimate photos of several celebrities were made public. This hack is a prime example of how a simple cyberattack can ruin people’s lives and careers forever.
The University of Kansas – in 2016, the employees responded to a phishing email and handed over access to their paycheck deposit information to the attackers, resulting in them losing pay.
Who are the targets for Phishing Attacks?
When protecting your organization, the first step should be to identify your most valued targets. Recognizing these targets will help you in implementing effective security measures to protect your organization against hackers. The following departments and positions are the most vulnerable to phishing attempts:
- Finance department – As this department deals with all sorts of wire transfers, they are quite susceptible to a phishing attack. Too often, sloppy internal policies only require an email from the CEO or other senior person to initiate the transfer, which hackers can easily exploit.
- HR Department – This is one of the most vulnerable departments in an organization. As the email contact is publicly available, hackers can send resumes with spyware (or any other malicious software) included gaining access to the employee database, including social security numbers, payrolls, and tax information.
- Executive Team – often considered a high-value target, they have financial authority and access to confidential data. If hacked, the attackers can access all sorts of information and be truly devastating for the company. Such accounts should have high security.
- IT Department - As these accounts are usually the administrators in the company network, they are prime targets for hackers. IT departments have authority over access control and password database and email accounts of the entire organization. Hackers can access every part of the organization by Phishing these accounts. It is rare for hackers to phish these accounts directly. They usually work their way up to these accounts by first compromising other company accounts with low authority.
How to prevent phishing attacks
Now that we understand what a phishing attack is and how devastating it can be for an organization let us look at the measures we can implement to prevent and mitigate phishing attacks.
Increase Awareness
Learn to spot Phishing attempts – the best strategy to prevent a successful phishing attempt is to identify them! Online resources like one from Lehigh University have the most recent examples of phishing attempts. Regularly reviewing them will keep you updated with the new phishing attacks and decrease your cyber risk.
Security Awareness Training – This training is the best long-term strategy to prevent phishing attacks against your company. As a successful phishing attack is a gateway to further attacks, training your employees to recognize, stop, and report such attacks can go a long way in improving your organization’s cybersecurity.
Regular Phishing Tests – Along with training, many online tools can allow you to implement phishing tests to evaluate your weakest links frequently. Through regular and innovative tests, you can identify the people that are repeatedly failing to recognize phishing tests. Following which you can implement tighter security around their account and have a one on one training session with them.
Double-check the spelling of the email address and domain – Hackers add an extra letter or change one of the letters in the domain or email address that may seem authentic at a glance. Such attacks are quite useful. There are many recorded cases where the hackers could walk away with a large sum of money impersonating an executive requesting a transfer of funds to an unknown offshore account.
If in doubt, don’t click – implement and promote a culture that prevents people from clicking links that they find even a little suspicious.
Change in Organization Policies – To add a security layer to protect against phishing attacks, an organization should implement robust security policies, especially regarding payments. For example, the finance department should require more than an email from the CEO to transfer money.
Technical Controls
Implement Spam Filters – Although not 100% effective, it’s a necessary measure that we shouldn’t overlook. You can do various things to implement a strong spam filter and prevent such emails from reaching your employee’s email accounts. This Infosec article provides useful information on how you can set up phishing filters on Outlook and Google Chrome.
Sandboxing inbound email – This can protect you against phishing attacks that want to install malicious software on your computer. Before delivering the inbound email, the email client opens the attachments in a “sandbox” to see anything malicious. If not, it forwards it to your inbox. If it suspects malicious activity, then it removed the email. This article can help you set sandboxing in GSuite.
Change your browser settings – all the popular browsers have a list of fake websites that help prevent your employees from accessing such websites by blocking them on your company devices.
Implement Domain Spoof Protection - Register, as many organization domains slightly different from the actual organization domain (look-alike-domains) as possible. Create Intrusion detection system rules that flag emails with extensions that are like company email. Alternatively, you can flag all non-organization domain emails as “External” to make it easier for employees to recognize phishing attempts.
Implement MFA for high-value accounts – Implementing multi-factor authentication will help you mitigate a successful phishing attack. If the hacker tries to log in, you will be alerted and can then change your password immediately.
Conclusion
Phishing attacks are the most used method by hackers to access your company’s sensitive data, financial activity, and internal network. Luckily, the solution to this problem is well within any organization to implement. First, identify your high-value accounts that will be prime targets for such attacks. Then, ensure that you have reasonable technical controls like spam filters and sandboxing to prevent most phishing attacks. Lastly, have a strong security awareness culture in your organization so that your employees know this threat and ensure that they take responsibility for protecting the organization against such threats.
