Posted in

Fighting Back Against Phishing: A Workplace Concern

Is someone phishing in your inbox? It’s more likely than you think. Phishing attacks are common online attacks that aim to steal useful information, from account credentials to personal data. Unlike traditional hacking, though, what sets phishing apart is its personal nature “ the person behind a phishing scam typically pretends to be someone else, someone you would be inclined to trust, in order to obtain this information. Even the classic Nigerian Prince scam is technically a form of phishing, but today’s phishing scams are more nuanced and harder to identify.

Phishing For Whales

Workplaces are especially vulnerable to phishing in its newest guise, known as whaling. Whalers target those higher up in a company, such as managers or c-suite executives, with the aim of attaining confidential company information; they may even pretend to be the CEO or president of that very business because most people won’t check with their boss to confirm the email‘s source, especially if they’re away on travel. Whalers know where the power is within a company, and they know exactly what they’re looking for, from financials to credentials with wide-ranging access. But while whaling attacks and other types of phishing can be hard to identify at times, they are fairly easy to avoid.

Finding And Fighting The Phishers

Phishing scams almost always take the form of emails, but there are several subtypes within these scams. First, there are phishing emails that imitate an outside company “ maybe your bank or another financial institution or an e-commerce business you have an account with. These messages will typically include a link and try to lure you through that link, where you’ll be prompted to update information. These are among the most common because they’re not very specific in their targeting, and they can be sidestepped by simply not clicking on the link; if a company wants you to update information, go directly to their site, via your browser bar. This is a key part of security awareness, and you should be training employees to recognize the risk.

A more nuanced type of phishing attack is generally company specific “ an entire team of hackers may be working to obtain information from your business. In these cases, phishers may assemble various elements from sites, such as email accounts listed in LinkedIn, and use that information to hijack actual internal email accounts and send messages. By making it appear that these are internal messages, these phishers make it more likely that targets will respond to their messages. To detect these messages, staff members should be attentive to any unusual stylistic changes in the writing or messages from individuals who wouldn’t ordinarily contact them. Ask yourself, if you never work with this individual, why are they contacting you now?

Know The Targets

Overall, phishing attacks have specific targets, so it’s important to be alert to existing or major trends. For example, SaaS credentials are increasingly targeted, and cybercriminals even sell those credentials on eBay. Such attacks were among the most common of 2018, and we’ll likely see their continued prevalence this year.

Workers should also be alert for phishing scams delivered via messenger app. Though these attacks typically leverage email, with a growing shift to messengers like Slack and G-Chat, phishers have had to adapt. Team members should be equally suspicious of such messages and attempt to independently navigate to any relevant links, rather than clicking on messenger connections. It’s also important to recognize that these platforms can be even more hazardous because they lack the built-in security infrastructure of email.

Phishing attacks belong in your Spam inbox, but too many are making their way through, and professionals in all fields need to stay alert. Even if you don’t think you have valuable information, you may still be the target of a phishing attack. Sometimes an attacker’s only goal is to get their foot in the door.

Larry Alton is a professional blogger, writer and researcher who contributes to a number of reputable online media outlets and news sources, including Entrepreneur.com, HuffingtonPost.com, and Business.com, among others. In addition to journalism, technical writing and in-depth research, he’s also active in his community and spends weekends volunteering with a local non-profit literacy organization and rock climbing. Follow him on Twitter and LinkedIn.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.