Five tips to avoid getting phished

By Joan Goodchild, CSO |  Security, phishing Add a new comment

The criminal art of spear phishing, email spoofing that aims to get the recipient to click on a bad link or attachment, has been around for years. But that doesn't mean it's become any less effective. According to figures from the U.S. Computer Emergency Readiness Team (US-CERT), which compiles information from federal, state and local governments, commercial enterprises, U.S. citizens and foreign CERT teams, phishing attacks accounted for 53% of all security incidents in 2010.

What has changed recently is that more phishing attempts are direct, targeted efforts aimed at specific individuals within an organization. In fact, after the recent breach of an email database maintained by marketing firm Epsilon, security experts warned that banking customers should worry about a wave of spear phishing attacks utilizing the information gained from the break in.

The days when phishers would blast out hundreds of generic messages and hope for a few hits are ending. Criminals now realize a message with specialized, social engineering content that is directed to one person, or a small group of people, can be much more successful. After all, it typically only takes one machine to compromise an entire network.

"We now see more of the scenarios involving just two or three emails targeting the executive team, which spoofs the legal team and contains a malware attachment that talks about pending litigation," said Jim Hansen of the security awareness consultancy PhishMe.

Also see: Phishing: The Basics

PhishMe has designed spear-phishing-awareness training that focuses on changing user behavior. Hansen gave us five tips his team offers clients to help them avoid getting hooked by a phony message.

Be skeptical of all emails

Ask yourself: Who is this email from? If the sender is someone you do not recognize, chances are this email is either some form of unsolicited spam or it is a phishing email, said Hansen. Search for the domain through Google or some search engine to see where the domain comes from, he advised.

"Slow down, take a breath and think about what you're doing," said Hansen. "We are all busy people, but if you take a few minutes, it's not going to disrupt your day."

Be wary of attachments

If you do open the email and you are prompted to download images or attachments, don't, said Hansen. These "images" and attachments could contain malicious content that you don't want on your computer. At best, said Hansen, you are slammed with a ton of spam and advertisements. At worst your computer could be an open book to an attacker trying to get your information.

If the message comes from a sender you don't recognize, or even if it is a sender that you do recognize, get confirmation before downloading any attachment.

Ignore commands and requests for action

If the email is urging you to do something, stop and think before you fall into their trap, said Hansen. If it is too good to be true or seems too farfetched, it probably is.

"There are two motivations a criminal will try to appeal to: reward or authority," said Hansen.

In an authority-based scam, the email may say you need to act upon something and the message comes from someone in a position of authority, such as an IT team member telling you your computer is infected, or an HR person asking you to fill out a company survey. These kinds of messages may also try to fool you into thinking you have a package that was "undeliverable" or that your bank account has been breached.

The reward scenarios usually involve some kind of prize for entering a raffle or filling out a survey. Ignore them all, said Hansen.

Check out the link

Where does that link actually go? Almost all phishing emails have a link in them that they want you to click, said Hansen. The link says it is going to your Facebook page or to your bank website, but where is it really going?

The easiest way to find out is to hover your mouse over the link and look at the bottom left corner of your browser window. There you should be able to see the exact URL that you will be directed to if you click on the link. If this link shows as an IP address (example :192.168.1.1) then most likely this is not a place that you want to go.

Use the phone


Originally published on CSO |  Click here to read the original story.

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question