How to stop your executives from being harpooned

'Whaling' is a growing security threat that uses personalized phishing techniques to get your most sensitive data and access to your key networks

By Bob Violino, InfoWorld |  Security, phishing Add a new comment

Last year, a senior executive in charge of customer satisfaction at his company opened an email with the subject "customer complaint" that appeared to be sent from the Better Business Bureau. He followed a link to see details of the complaint. "If he had stopped to examine the URL carefully, he would have seen that it was a trap" -- known as a whaling attack and based on spear-phishing techniques -- intended to gather information about the company, says Jonathan Gossels, president of SystemExperts, a security consulting firm. "But during a busy work day, that hardly happens."

In another recent case, an attacker researched the background of a systems administrator, then sent him an email about a reduced premium health care plan for families of four or more. This appealed to the administrator, who has five children, and enticed him to open the attached form. The form had embedded malware that compromised the target's computer and gave the attacker a foothold into his corporate network. It also allowed the attacker to impersonate the administrator and garner sensitive information about the company's operations, says Rohyt Belani, CEO of Intrepidus Group, a security consulting and training firm.

[ Master your security with InfoWorld's interactive Security iGuide and our Deep Dive PDF guides on browser security, Windows 7 security, and malware defense. | Stay up to date on the latest security developments with InfoWorld's Security Central newsletter. ]

These whaling attacks are a form of personalized phishing, or spear phishing, aimed at senior executives or others in an organization who have access to lots of valuable or competitive information. While phishers generally go after consumers for bank account data, passwords, credit card numbers, and the like for financial gain, whalers most often target people who have inside information or can provide ongoing access to systems. Thus, the cost of being harpooned can be huge.

Whaling attacks are harder to detect than phishing expeditions. There's no obvious signature to detect as in phishing, such as seeing hundreds of copies of a phishing email enter your server. Whaling attacks are also hard to defend against because they often play on executives' feelings and sense of self-importance.

And security experts say these types of attacks are on the rise.

"As more private information becomes public, through social media sites and otherwise, targeting specific individuals within companies has become easier for hackers and thus a preferred method of attack," says Kim Peretti, a director in the forensic services practice at the PricewaterhouseCoopers consulting firm.

"This proliferation of information on individuals -- where they work, with whom they interact socially and professionally, what conferences they attend, when and where they vacation -- has enabled hackers to determine not only which individuals at companies may hold the keys to the kingdom, but also to which messages these [people] are most likely be duped into responding," Peretti says.

What can you do to protect your corporate whales from getting harpooned? Follow these five best practices, experts tell InfoWorld.

1. Learn what a whaling attack is and how to identify actual threats and attacks. How do you know if you're the target of a whaling attack? Unfortunately, if the whaler has done lots of research and effectively copied the signature and other known characteristics of your email, you generally won't know you're being attacked because there really aren't any obvious tell-tale signs, says Robert Siciliano, a security consultant and identity theft expert.


Originally published on InfoWorld |  Click here to read the original story.

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question