Showing posts with label protection from phishing attacks. Show all posts
Showing posts with label protection from phishing attacks. Show all posts

Tuesday, April 9, 2019

Whaling, SMiShing, and Vishing…Oh My!


credit card with fish hook speared through it


Cybercriminals use types of social engineering—manipulating people into doing what they want—as the most common way to steal information and money. Social engineering is at the heart of all types of phishing attacks—those conducted via email, SMS, and phone calls. Technology makes these sorts of attacks easy and very low risk for the attacker. Make sure you're on the lookout for these variants on the traditional, mass emailed phishing attack.
  • Spear phishing: This kind of attack involves often very well-crafted messages that come from what looks like a trusted VIP source, often in a hurry, targeting those who can conduct financial transactions on behalf of your organization (sometimes called "whaling").
  • SMiShing: Literally, phishing attacks via SMS, these scams attempt to trick users into supplying content or clicking on links in SMS messages on their mobile devices. Flaws in how caller ID and phone number verification work make this an increasingly popular attack that is hard to stop.
  • Vishing: Voice phishing, these are calls from attackers claiming to be government agencies such as the IRS, software vendors like Microsoft, or services offering to help with benefits or credit card rates. Attackers will often appear to be calling from a local number close to yours. As with SMiShing, flaws in how caller ID and phone number verification work make this a dangerous attack vector.
No matter the medium, follow these techniques to help prevent getting tricked by these social engineering attacks:
  • Don't react to scare tactics: All of these attacks depend on scaring the recipient, such as with a lawsuit, that their computer is full of viruses, or that they might miss out on a chance at a great interest rate. Don't fall for it!
  • Verify contacts independently: Financial transactions should always follow a defined set of procedures, which includes a way to verify legitimacy outside email or an inbound phone call. Legitimate companies and service providers will give you a real business address and a way for you to contact them back, which you can independently verify on a company website, support line, etc. Don't trust people who contact you out of the blue claiming to represent your company.
  • Know the signs: Does the message/phone call start with a vague information, a generic company name like "card services," an urgent request, and/or an offer that seems impossibly good? Hang up or click that delete button!
For further information on how a phishing attack affected this undergraduate students view this video:




Information Security Awareness Training Video: "Phishing: E-Safe"


View this video for strategies on how to address illegal robocalls:

FCC Chairman provides some tips to help consumers confront illegal robocalls and maliciously spoofed calls.

Partially reposted from: Educause Campus Security Awareness Campaign 2019: April 2019: Whaling, SMiShing, and Vishing…Oh My!

Monday, April 1, 2019

Another day, another phishing email.

This morning ITS detected a phishing email and quarantined the email. A redacted version of the email is shown below.

1 Apr 2019 05:56:19 -0700
From: "manhattan.edu" <admin@support.com>
To: ██████.██████@manhattan.edu
Message-ID: <20190401055619.AF1B5635B08A35FE@support.com>
Matched rules


Dear ██████.██████,    
Your Email Account (██████.██████@manhattan.edu) password is set to expire 
in 3 days, it will expire on. 
*4 Apr 2019*.
We recommend you to click the Email Settings below to confirm your email 
password to avoid login interruptions.
Email Setings
Best Regards,
*Note:**Please do not ignore this message.*
2019 ⓒ manhattan.edu account team.


The link, which is removed in the above, appears to go to google.com but actually redirects to a malicious site.

https://www.google.com/url?hl=3Den&amp;q=3Dhttps://yahoo.com

The above link is similar to the malicious URL, and uses yahoo.com instead of the malicious site. Google is currently blocking this redirection, which is for the best.

Screenshot showing Google blocking this redirection phishing exploit.

ITS reported the email with full headers using the Google reporting form. Also ITS blocked access to the malicious website from our campus. Any off-campus user can still accidentally visit the website though. Thankfully this email was not delivered to a single inbox within our organization.

Monday, December 5, 2016

Managing Your Online Reputation


More adults are using social media to stay connected both personally and professionally, which means recruiters (for college, sports, and jobs) may be using social media more frequently to assess candidates’ qualifications. The type of information shared on social media can also provide fodder for phishing attacks and even identity theft, or allow people to make assumptions about you based on the groups that you are affiliated with. Remember to check your social media privacy and security settings frequently to ensure careful online reputation management.

Get the Word Out

Newsletter Content

You should understand how to present yourself on social networking sites and how to safeguard your information. What many may consider temporary or fleeting will most likely remain on the Internet forever. As a result, keep these dos and don’ts in mind when sharing online.

Dos

Remember Last Night? Your Social Network Does. It Loves to Share!
  • Ask questions about who can access the information you are posting online, who controls and owns the information, and what is shared with third party.
  • Maintain a backup of the content you post on professional networking sites (e.g., LinkedIn).
  • Understand the default privacy settings on the social networking sites you use and how to change them to match your comfort level.
  • Keep your personal information private. Assess whether it’s necessary to share sensitive information such as your birthday, mailing address, phone number, e-mail, mother’s maiden name, sexual orientation, or Social Security number.
  • Be cautious about accepting requests to connect online. Connect only to people you trust who will not misuse the information you post.
  • Check the location settings on photos and videos you post to social networking sites.
  • Avoid joining online groups where you don’t know all the members or what they stand for.
  • Use passphrases to protect your social media accounts. A passphrase is a set of words that create a phrase that is 20 to 30 characters long.

Don’ts

  • Don’t share too much information that could be used to complete a profile about you. For example, share your birthday, but not the year you were born. Or share your hometown, but not the address where you live.
  • Don’t share any information that is being used for verification purposes such as your mother’s maiden name, the name of your first pet, or the street where first lived. Consider making up alternate answers to those questions that only you would know.
  • Don’t post when you are traveling or going out of town on vacation. It’s an open invitation letting criminals know that you are in a different location and that your home is vacant.
  • Don’t post photos of inappropriate or illegal activities.
  • Don’t click on attachments or links without checking the source.
  • Don’t “check in” to every place you visit. That information could be used to identify you in a vulnerable location.
  • Don’t use weak passwords, and never share your passwords!



Social Posts

  • Our general rule: Never post anything #online you wouldn’t want your grandmother to see! #SocialMediaSafety
  • Or to put it another way, if you wouldn’t want to see it on a billboard, keep it offline. #SocialMediaSafety
  • The Internet is forever. Protect your online reputation—your older self will thank you! #SocialMediaSafety
  • Keep your personal information private. Assess whether sensitive info is really necessary to share. #SocialMediaSafety
  • Remember to check your social media privacy & security settings often! #SocialMediaSafety

Resources


reposted from: http://er.educause.edu/blogs/2016/6/december-managing-your-online-reputation