Showing posts sorted by relevance for query phishing. Sort by date Show all posts
Showing posts sorted by relevance for query phishing. Sort by date Show all posts

05 December 2019

Spear phishing campaigns - they’re sharper than you think


Even your most security-savvy users may have difficulty identifying honed spear phishing campaigns. Unlike traditional phishing campaigns that are blasted to a large email list in hopes that just one person will bite, advanced spear phishing campaigns are highly targeted and personal. They are so targeted, in fact, that we sometimes refer to them as “laser” phishing. And because these attacks are so focused, even tech-savvy executives and other senior managers have been duped into handing over money and sensitive files by a well-targeted email. That’s how good they are.

Even though spear phishing campaigns can be highly effective, they aren’t foolproof. If you understand how they work, you can put measures in place to reduce their power. Today, we provide an overview of how these campaigns work and steps you can take to better protect your organization and users.


07 August 2017

iOS users beware: You're the biggest target for mobile phishing attacks


A new report from mobile security company Wandera is putting a new face on phishing, especially when it happens on mobile devices. Eighty-one percent of mobile phishing attacks happen outside of email, 63% happen on iOS devices, and 85% of organizations have been phished whether they know it or not.

Phishing attacks on mobile devices is becoming increasingly common, the report says, and may even be the most pressing security issue of 2017, bypassing ransomware and other serious threats.

Mobile phishing attacks are predominantly targeting iOS users—63% of attacks occur on iOS, compared to 37% on Android. That may come as surprise considering how prevalent Android malware is, but it may be precisely because Android malware is common that phishing dominates on iOS.


20 January 2026

Phishing: Spot and report scam emails, texts, websites and calls

 

'Phishing' is when criminals use scam emails, text messages or phone calls to trick their victims. The aim is often to make you visit a website, which may download a virus onto your computer, or steal bank details or other personal information.

This page explains how to report phishing attempts, and protect yourself from scammers.

The National Cyber Security Centre (NCSC) is a UK government organisation that has the power to investigate and take down scam email addresses and websites.

Reporting a scam is free and only takes a minute. By reporting phishing attempts, you can:
reduce the amount of scam communications you receive
make yourself a harder target for scammers
protect others from cyber crime online

Please CLICK HERE to read more, understand the risks & stay safe. 
Need more help or further advice? Contact Donline.

www.ncsc.gov.uk


31 October 2019

Businesses stung by highly convincing Office 365 voicemail scam


Cyber criminals are stealing the login credentials of Microsoft Office 365 users using a phishing campaign that tricks victims into believing they've been left voicemail messages.

In the last few weeks, there's been a surge in the number of employees being sent malicious emails that allege they have a missed call and voicemail message, along with a request to login to their Microsoft accounts.

The phishing emails also contain an HTML file, which varies slightly from victim to victim, but the most recent messages observed include a genuine audio recording, researchers with McAfee Labs have discovered.

When loaded, this HTML file redirects victims to a phishing website that appears to be virtually identical to the Microsoft login prompt, where details are requested and ultimately stolen.

"What sets this phishing campaign apart from others is the fact that it incorporates audio to create a sense of urgency which, in turn, prompts victims to access the malicious link," said McAfee's senior security researcher Oliver Devane.


25 February 2020

Keep your passwords secure: hackers don't break in, they log in!


Hackers don't break in, they log in. That mantra, often repeated by security experts, represents a rule of thumb: The vast majority of breaches are the result of stolen passwords, not high-tech hacking tools.

These break-ins are on the rise. Phishing scams - in which attackers pose as a trustworthy party to trick people into handing over personal details or account information - were the most common type of internet crime last year, according to a recent FBI report. People lost more than $57.8 million in 2019 as the result of phishing, according to the report, with over 114,000 victims targeted in the US.

And as phishing becomes more profitable, hackers are becoming increasingly sophisticated in the methods they use to steal passwords, according to Tanmay Ganacharya, a principal director in Microsoft's Security Research team.

"Most of the attackers have now moved to phishing because it's easy. If I can convince you to give me your credentials, it's done. There's nothing more that I need," Ganacharya told Business Insider.


16 August 2018

Windows Defender Browser Protection browser extension for Google Chrome


Protect yourself against online threats, like phishing and malicious websites, with real-time protection from Microsoft.

The Windows Defender Browser Protection extension helps protect you against online threats, such as links in phishing emails and websites designed to trick you into downloading and installing malicious software that can harm your computer. 

If you click a malicious link in an email or navigate to a site designed to trick you into disclosing financial, personal or other sensitive information, or a website that hosts malware, Windows Defender Browser Protection will check it against a constantly updated list of malicious URLs known to Microsoft. 

If the malicious link matches one on the list, Windows Defender Browser Protection will show a red warning screen letting you know that the web page you are about to visit is known to be harmful, giving you a clear path back to safety with one click.

Continuously updated list of reported harmful sites.
Protects against phishing sites and socially engineered malware sites.
Real-time indicator of harmful sites and website status.


30 April 2026

Nearly half of UK businesses pwned last year as phishing keeps doing the job like it's 2005

Nearly half of UK businesses are still getting breached, and in many cases, the attacker's big breakthrough is an employee clicking "sure, why not" on a fake login page.

The UK government's latest Cyber Security Breaches Survey, released on Thursday, puts the hit rate at 43 percent of businesses and 28 percent of charities reporting a cyber incident in the past year, equating to approximately 612,000 UK businesses and 57,000 UK charities, numbers that have barely budged since the last time it asked.

Most of these breaches do not start with anything especially cutting-edge. Phishing leads "by far," usually via impersonation emails that send staff to fake login pages or get them to click links, open attachments, or hand over sensitive information.

Everything else barely gets a look-in. Around 85 percent of businesses that reported a breach or attack said it involved phishing, leaving malware, ransomware, and unauthorized access trailing some distance behind.

www.theregister.com


20 April 2018

Microsoft Ports Anti-Phishing Technology to Google Chrome Extension


Microsoft has released a Chrome extension named "Windows Defender Browser Protection" that ports Windows Defender's —and inherently Edge's— anti-phishing technology to Google Chrome.

The extension works by showing bright red-colored pages whenever users are tricked into accessing malicious links.

The warnings are similar to the ones that Chrome natively shows via the Safe Browsing API, but are powered by Microsoft's database of malicious links —also known as the SmartScreen API.

An NSS Labs benchmark revealed that Edge (with its SmartScreen API) caught 99 percent of all phishing URLs thrown at it during a test last year, while Chrome only detected 87 percent of the malicious links users accessed.

To download the Chrome extension (browser plugin), click here.


04 July 2018

Record number of fake HMRC websites deactivated over past year


As fraudsters continue to target Britain’s micro business community, official figures reveal that a record number of fake HMRC websites were shut down in the last 12 months.

New figures from the tax office have shown that 20,750 malicious sites acting as HMRC were sent requests to be taken down since summer 2017 – an increase of 29% on the previous year.

During the 2017/18 financial year, HMRC responded to almost 1m phishing referrals. Since 2016 it has blocked almost half a billion phishing emails using HMRC in the “from” address.

New technology has contributed to the strong response to scammers, reducing phishing texts by 90%.


24 August 2020

Be aware: phone spear phishing attacks are on the rise


Andy Greenberg at Wired has published an interesting article, describing how there have been a spate of “phone spear phishing” attacks since celebrity accounts on Twitters were very publicly compromised last month.

You will remember that Twitter confirmed that members of staff were rung up by scammers, who then socially engineered their victims into handing over credentials which gave the hackers access to Twitter’s internal tools. Those tools, which should have only been available to authorised personnel (and perhaps, in retrospect, not 1000+ employees and contractors) could then be used to reset passwords and disable two-factor authentication.

According to New York-based security outfit Unit 221b, which has been helping the FBI with its investigation into the Twitter hack, the same “voice phishing” techniques have been used against banks, web hosts, and cryptocurrency exchanges, in recent weeks.


27 April 2026

Fake calendar invites are spreading - here’s how to remove them and prevent more

 

Malwarebytes writes: We’re seeing a surge in phishing calendar invites that users can’t delete, or that keep coming back because they sync across devices. The good news is you can remove them and block future spam by changing a few settings.

Most of these unwanted calendar entries are there for phishing purposes. Most of them warn you about a “impending payment” but the difference is in the subject and the action they want the target to take. Sometimes they want you to call a number, and sometimes they invite you to an actual meeting.

We haven’t followed up on these scams, but when attackers want you to call them or join a meeting, the end goal is almost always financial. They might use a tech support scam approach and ask you to install a Remote Monitoring and Management tool, sell you an overpriced product, or simply ask for your banking details.

The sources are usually distributed as email attachments or as download links in messaging apps. READ MORE -or- contact DONLINE.

www.malwarebytes.com


10 May 2018

HMRC urges people to be aware and vigilant of fraudster texts and emails


HMRC is urging people to stay vigilant and aware of fraudsters who are using emails and text messages to con people out of their money.

Tricksters are sending messages that promise tax rebates to trick people into giving out their banking and personal details.

HMRC advises customers to:

Recognise the signs – Banks and HMRC will never contact you out of the blue to ask for your PIN, password or bank details

Stay safe – Do not give out private information, reply to text messages, download attachments or click on links in emails you weren’t expecting

Take action – Forward suspicious emails claiming to be from HMRC to phishing@hmrc.gsi.gov.uk and texts to 60599, or contact Action Fraud on 0300 123 2040 to report any suspicious calls or use its online fraud reporting tool


If you think you have received an HMRC-related phishing/bogus email or text message, you can check it against the examples shown in this guide.



08 June 2022

Humans are still the weakest link in cybersecurity

According to Proofpoint’s 2022 Human Factor report, 55% of U.S. workers admitted to taking a risky action in 2021. Twenty-six percent clicked an email link that led to a suspicious website, 17% accidentally compromised their credentials and only half were able to correctly identify the term phishing.

“The other part to this equation is that threat actors have gotten a lot better at employing social engineering in their attacks,” said Ryan Kalember, Proofpoint’s executive vice president of cybersecurity strategy. “We see threat actors leverage real life events to solicit an immediate, emotional response, such as with the Ukraine conflict. We also see threat actors employ a combination of email, call centers and live interactions to sell the idea that the communication is legitimate.”

Key to the successful execution of these email-based phishing attacks is trust, the report said. More than ever, hackers today are using stolen credentials to not only gain access to networks and systems but also execute business email compromise and privilege escalation attacks.

www.techrepublic.com


25 June 2019

Office 365 Proves Popular with Phishers


With 180 million active users it's no wonder that Microsoft Office 365 has caught the attention of online criminals. According to Microsoft, one in five business workers are now using an Office 365 cloud-based service, with adoption particularly popular in the financial services and manufacturing sectors. And these industries, of course, can provide rich pickings for cybercriminals.

So, it's no surprise to me to learn that phishing attacks targeting Office 365 users outstrip the attacks seen against the likes of Netflix and PayPal, or online banks.

What makes phishing attacks against Office 365 more threatening, of course, is that they're not just after a user's login credentials.

Instead, attackers frequently want to exploit their unauthorised access to an Office 365 account by sending messages from the legitimate account to the victim's business partners or colleagues. A stolen Office 365 password may only raise a tiny amount of money if sold on an underground cybercrime forum compared to the fortunes that can be made through a Business Email Compromise (BEC) attack that requests money be wired to an overseas bank account.


07 May 2020

Protecting your organisation against password spray attacks


When hackers plan an attack, they often engage in a numbers game. They can invest significant time pursing a single, high-value target—someone in the C-suite for example and do “spear phishing.” Or if they just need low-level access to gain a foothold in an organization or do reconnaissance, they target a huge volume of people and spend less time on each one which is called “password spray.” Last December Seema Kathuria and I described an example of the first approach in Spear phishing campaigns—they’re sharper than you think! Today, I want to talk about a high-volume tactic: password spray.

In a password spray attack, adversaries “spray” passwords at a large volume of usernames. When I talk to security professionals in the field, I often compare password spray to a brute force attack. Brute force is targeted. The hacker goes after specific users and cycles through as many passwords as possible using either a full dictionary or one that’s edited to common passwords. An even more targeted password guessing attack is when the hacker selects a person and conducts research to see if they can guess the user’s password—discovering family names through social media posts, for example. And then trying those variants against an account to gain access. Password spray is the opposite. Adversaries acquire a list of accounts and attempt to sign into all of them using a small subset of the most popular, or most likely, passwords. Until they get a hit. This blog describes the steps adversaries use to conduct these attacks and how you can reduce the risk to your organisation.

Three steps to a successful password spray attack:
Step 1: Acquire a list of usernames
Step 2: Spray passwords
Step 3: Gain access


14 February 2022

What is a SIM swap attack?

SIM swapping is a scam in which malicious parties target cell phone carriers to gain access to victims’ bank accounts, virtual currency accounts and additional sensitive information by using social engineering, insider threat or phishing techniques. Social engineering involves a criminal to impersonate the victim’s mobile number by tricking the cell phone carrier into switching the victim’s mobile number to a SIM card that is in the criminal’s possession, allowing the malicious party to access the victim’s calls, texts and other data, but this is only one of the three methods used to steal funds from victims.

Insider threat takes place when a criminal actor pays off a mobile carrier employee to switch the victim’s SIM to a card currently in the criminal’s possession. Malicious parties can also employ phishing techniques to access victims’ sensitive data, and steal funds from the victim through their banking data or third-party services like PayPal or Venmo. This level of access to a victim’s cell data then allows a malicious party entry to everything from text message verification to SMS based two-factor authentication to exploit victims’ sensitive information.

“Service providers must move from more simplistic means of validating identity to more sophisticated ones,” Clements said. “PIN codes unique to each user’s account can be one way of adding additional security to the process, and ‘out of wallet’ questions are another alternative that works by verifying much harder to compromise information such as last three home addresses or cars. It may be more of a hassle for everyone, but it’s simply no longer viable to rely on information that has been routinely compromised to validate a person’s identity.”

The FBI encourages both cell phone users and the companies that provide service to take additional security measures in protecting their personal information. For cell phone users, the agency outlines the following tips:

Do not advertise information about financial assets, including ownership or investment of cryptocurrency, on social media websites and forums.

Do not provide your mobile number account information over the phone to representatives that request your account password or pin. Verify the call by dialing the customer service line of your mobile carrier.

Avoid posting personal information online, such as mobile phone number, address or other personal identifying information.

Use a variation of unique passwords to access online accounts.

Be aware of any changes in SMS-based connectivity.

Use strong multi-factor authentication methods such as biometrics, physical security tokens, or standalone authentication applications to access online accounts.

Do not store passwords, usernames or other information for easy login on mobile device applications.

www.techrepublic.com


14 December 2018

Iranian phishers bypass 2fa protections offered by Yahoo Mail and Gmail


A recent phishing campaign targeting US government officials, activists, and journalists is notable for using a technique that allowed the attackers to bypass two-factor authentication protections offered by services such as Gmail and Yahoo Mail, researchers said Thursday. The event underscores the risks of 2fa that relies on one-tap logins or one-time passwords, particularly if the latter are sent in SMS messages to phones.

Attackers working on behalf of the Iranian government collected detailed information on targets and used that knowledge to write spear-phishing emails that were tailored to the targets’ level of operational security, researchers with security firm Certfa Lab said in a blog post. The emails contained a hidden image that alerted the attackers in real time when targets viewed the messages. When targets entered passwords into a fake Gmail or Yahoo security page, the attackers would almost simultaneously enter the credentials into a real login page. In the event targets’ accounts were protected by 2fa, the attackers redirected targets to a new page that requested a one-time password.

“In other words, they check victims’ usernames and passwords in realtime on their own servers, and even if 2 factor authentication such as text message, authenticator app or one-tap login are enabled they can trick targets and steal that information too,” Certfa Lab researchers wrote.


18 April 2017

Phishing with Unicode Domains - scary stuff!


If I told you that "www.apple.com" (see above) could be a phishing site, would you believe me? Check out the proof-of-concept - works in Chrome & Firefox.

Punycode makes it possible to register domains with foreign characters. It works by converting individual domain label to an alternative format using only ASCII characters. For example, the domain "xn--s7y.co" is equivalent to "短.co".

From a security perspective, Unicode domains can be problematic because many Unicode characters are difficult to distinguish from common ASCII characters. It is possible to register domains such as "xn--pple-43d.com", which is equivalent to "аpple.com". It may not be obvious at first glance, but "аpple.com" uses the Cyrillic "а" (U+0430) rather than the ASCII "a" (U+0041). This is known as a homograph attack.

Be careful out there, readers. 
On the Web, make sure that you truly are on the site that you want to visit.
There are some bad people out there!


23 August 2019

How to avoid ransomware attacks: 10 tips


Nigerian princes are no longer the only menaces lurking in an employee's inbox. For healthcare organizations, schools, government agencies and many businesses, ransomware attacks—an especially sinister type of malware delivered through spear phishing emails that locks up valuable data assets and demands a ransom to release them—are a rapidly-growing security threat.

"We're currently seeing a massive explosion in innovation in the types of ransomware and the ways it's getting into organizations," says Rick McElroy, security strategist for cyber security company Carbon Black Enterprise Response. "It's a big business, and the return on investment to attackers is there—it's going to get worse."

To prevent a ransomware attack, experts say IT and information security leaders should do the following:

  1. Keep clear inventories of all of your digital assets and their locations, so cyber criminals do not attack a system you are unaware of.
  2. Keep all software up to date, including operating systems and applications.
  3. Back up all information every day, including information on employee devices, so you can restore encrypted data if attacked.
  4. Back up all information to a secure, offsite location.
  5. Segment your network: Don't place all data on one file share accessed by everyone in the company.
  6. Train staff on cyber security practices, emphasizing not opening attachments or links from unknown sources.
  7. Develop a communication strategy to inform employees if a virus reaches the company network.
  8. Before an attack happens, work with your board to determine if your company will plan to pay a ransom or launch an investigation.
  9. Perform a threat analysis in communication with vendors to go over the cyber security throughout the lifecycle of a particular device or application.
  10. Instruct information security teams to perform penetration testing to find any vulnerabilities.

24 August 2022

7 cybersecurity terms every hybrid employee should know

An employee working from home opens an attachment in an existing email thread with coworkers. Someone else quickly types in a URL to look something up while working on a project, without noticing they made a small typo. A new colleague receives an email that looks like it comes from a payroll company and responds with their Social Security number and bank account information.

Each of these scenarios could be just part of a normal day for an employee who spends most of their time working at a computer. But they’re also opportunities for a cyber attack that could wreak havoc for an entire company, its employees, and its customers. Now that more employees are working remotely for all or part of the work week, outside of the security of a company’s internal IT systems, the threat is even greater. In the first few months of the pandemic, cyber attacks on cloud infrastructure skyrocketed by 600%.

“Employees have a role to play, but more sophisticated attacks make it next-to-impossible to spot them,” says Ian Pratt, global head of security for Personal Systems at HP. “That’s why it’s key that employees feel empowered to inform IT when something looks off.”

1. Ransomware

2. Spear phishing

3. Spoofing

4. Pretexting

5. Typosquatting

6. Shoulder surfing

7. Zero-click attack

Click here to find out more & protect yourself & your business.

www.hp.com