Hi folks! Think of a message on your mobile saying your bank account will be suspended unless you verify your details within the next 30 minutes. The sender appears legitimate, the branding looks familiar and the message comes with a link that seems to redirect to your bank’s website.
This is a type of scenario phishing attacks are planned to create.
Basically, phishing is a type of cyberattack that exploits deceptive messages, websites, links, files, or calls to deceive people into disclosing confidential information, transferring money, downloading harmful software, or providing malicious actors access to accounts and systems. Cisco and IBM both define phishing as a type of social engineering that depends on deceptive communication and manipulation instead of just exploiting a technical risk.
Phishing has become more problematic to identify these days because malicious actors can fake trusted brands, colleagues, financial institutions, government organizations and even individuals at the victim’s workplace. Hence, it is important to understand how these attacks work and how to stay safe in this complex landscape.
What is Phishing?
Phishing is the act of sending fraudulent messages that look to come from a legitimate and reputable source, generally through email and text messaging. The goal of the attacker here is to steal money, obtain access to confidential information and login details, or to install malware on the victim’s device. Phishing is a harmful, damaging and rapidly growing form of cyberattack.
How Does Phishing Work?
We have all experienced some kind of traditional phishing attempt in our lives. Remember a security alert from IT, a revised vacation policy from HR, or a request from a bank to enter details. These attacks may occur in different forms. Phishing continues to be a favourable method among cyberattackers because of the lower investment and high success rate in obtaining access to confidential data and organizations’ systems.
Phishing attacks exploit social engineering techniques like canvassing your social media feeds to collect sensitive information and create convincing text messages. The combination of social engineering and urgency makes phishing attacks more successful and a constant threat for both individuals and companies. Attackers often pose as executives, senior managers or trusted supply chain partners to trick targeted recipients into taking urgent action on fraudulent requests.
Why is Phishing So Effective?
Phishing is effective because people act based on context and trust. An email from a familiar organization might not immediately raise suspicion. A request from someone who pretends to be a manager can feel more urgent than an unsolicited email. An alert related to a financial account can create more anxiety that the recipient to act before reading the text carefully.
Attackers mainly exploit these reactions. Common psychological triggers include urgency, curiosity, fear, financial incentives, and security concerns. Cisco finds these forms of emotional and behavioural triggers to be common factors used in phishing attacks.
Technology can also play an important role in impersonation. Attackers can recreate logos, writing styles, website layouts and other visual factors that make a fraud attempt look genuine. Hence, poor grammar is no longer an effective way to identify every phishing message.
Common Types of Phishing
Email Phishing
In this form of phishing attack, attackers generally use email as their main method to share malicious links or attachments. This is also known as the most common type of phishing. These emails look familiar and convincing to the victim and they generally include urgent requests or convincing offers to fool people into clicking the links or downloading the attachments.
For instance, an email may fake an established bank, asking the recipient to update their account details by clicking on a URL that redirects to a fake login page created to steal their information.
Spear Phishing
Spear phishing is another type of phishing attack where particular people or entities are targeted with personalized messages. Attackers study their victims from various sources such as social media profiles or company websites to make believable messages. This attack usually contains information relevant to the recipient’s interests, job role, or relationships within the company. For example, an attacker can email a worker impersonating their manager and requesting to share key financial information to finalize a fake urgent transaction.
Whaling
Whaling attacks target high-level executives such as CEOs or CFOs to obtain important confidential information or financial data. People in those positions gain power and trust, and malicious actors take advantage of that to trick people into following their requests.
For instance, an attacker may present himself as CFO and send an email to the manager to urgently transfer money to a business partner.
Smishing
Smishing or SMS phishing is an attack carried out using SMS messages. This is an attack where messages are sent that seem to come from a legitimate source, often with links to malicious websites or instructions to call a fake phone number.
Vishing
Vishing is short for voice phishing, where attackers trick victims into revealing sensitive information like passwords or credit card numbers. An example of a vishing attack would be an attacker pretending to be a bank representative. The attacker calls a target to request verification of their account details over the phone.
Pharming
Pharming is a technique where users are redirected to fraudulent websites even without requiring the victim to click on an obviously malicious URL. This ensures that secure browsing practices and careful verification are mainly important.
What are Common Signs of a Phishing Attack?
Phishing attempts can be hard to spot, but with a bit of vigilance, some basic guidelines and a little common sense you can greatly reduce the odds of success. Look for unusual elements or oddities in the email. Use the 'smell test' to see if something is wrong. Trust your instincts, but do not get afraid, as phishing attacks often exploit fear to drive your actions. Some of the most common signs of a phishing attack are:
Email promoting an offer that appears too good to be true
The sender looks similar but is not someone you usually interact with
The message triggers fear
The message contains unexpected or unusual attachments
The message contains links that seem fraudulent
Real-World Cases
Colonial Pipeline Attack in 2021
The fuel supplier, Colonial Pipeline, based in the USA, was strongly affected by a phishing attack in 2021. The entity stopped operations after its business networks and billing systems were attacked. It had a huge impact on the US economy too, with almost half of the US East Coast Oil supply shut down for a week.
The company had to pay $4.4 million in ransom. However, it appears that the attackers used phishing to obtain access to Colonial Pipeline systems.
Levitas Capital Attack in 2020
A whaling attack was attempted against the co-founder of the Australian hedge fund Levitas Capital in 2020. The co-founder received an email with a fraudulent Zoom meeting link. The moment he clicked the link, malware was injected into the corporate network of the hedge fund. This resulted in a financial loss of almost $8.7 million.
US Interior Department Attack in 2020
The malicious actors also attacked the US Department of the Interior’s computer systems. They used the impactful twin phishing method wherein people are deceived into connecting to a fake Wi-Fi access point managed by an attacker. Such a technique allowed the attackers to steal data and obtain access to the department’s WiFi network.
What Can Happen After a Successful Phishing Attack?
The impact of phishing can cover both personal and professional vulnerabilities.
Personal phishing risks involve:
Money theft from your bank account
Fraudulent charges on credit cards
Lost access to pictures, videos, and files
Fake social media posts created in your accounts
Cyberattacks impersonating you and jeopardizing your friends and family.
Professional risks include:
Loss of company money
Exposing personal information of partners, colleagues, and clients
Locked and inaccessible files
Reputation damage to the organization
How to Prevent Phishing Attacks?
Make Use of a Spam Filter
For an organization, this is likely the most fundamental preventative step. Spam filters in the majority of email programs, such as G Suite and Outlook, automatically weed out known spammers.
Turn on Multi-factor Verification
More information is needed to log in and gain access when using multi-factor authentication. This is essential when a con artist has already obtained certain employees' personal information. Attackers can be prevented in the first place by turning on MFA.
Update Your Security Software Every Day
Businesses should make sure that all of their security protocols are up to date. This can detect and delete malicious content or malware that may have been downloaded inadvertently to an employee’s machine via a phishing scam. Also, it is important to update security policies to include password complexity and expiration.
Make a Backup of Your Data
All critical data should be secured and backed up in the event of a breach or compromise.
Avoid Clicking on Links or Attachments
Do not click on dubious links and train employees to identify fraudulent links and attachments.
Block Unknown Websites
A web filter should be implemented to block access to malicious websites if an employee unknowingly clicks on a harmful link.
Phishing vs. Other Cyberattacks
Phishing is often confused with malware, ransomware and other forms of cyberattacks. However, phishing is more of a deceptive method utilized to persuade someone to make urgent decisions. On the other hand, malware is better understood as malicious software. Ransomware is a different type of malware created to reject the access to data or systems, often through encryption.
These forms of cyberattacks can overlap. For instance, a phishing email may have an attachment that installs ransomware. Another phishing text may steal sensitive information without installing malware.
Phishing in the Age of AI
Traditional phishing attacks often occur in chat rooms. Nevertheless, phishing has developed into a sophisticated tactic that can result in ransomware, email account takeover, and company email penetration. According to Cisco, phishing emails were the source of 80% of ransomware outbreaks.
By correcting spelling errors and personalising communications, AI has made it simpler for attackers to carry out sophisticated and focused attacks in recent years. For example, cybercriminals gather information about persons or groups they wish to attack and then use that knowledge.
Frequently Asked Questions
What is phishing?
It is a type of cybercrime where attackers attempt to access confidential information through email, text or calls with fraudulent intent.
How does phishing work?
Attackers pretend to be legitimate entities and send messages that appear genuine and urgent and ultimately trapping the victims into taking action, like clicking a link or downloading an attachment.
What is spear phishing?
Spear phishing is a highly personalized cyberattack where malicious actors personalize messages to particular people or entities using collected data.
Is phishing a cybercrime?
Yes, phishing is a cybercrime as it includes fraudulent transactions.
What are the different types of phishing?
Most common types include spear phishing, whaling, BEC, vishing, etc.
