What is Phishing?
Phishing is the fraudulent attempt to obtain sensitive information such as usernames, passwords and credit card details by disguising oneself as a trustworthy entity in an electronic communication. Typically carried out by email spoofing or instant messaging, it often directs users to enter personal information at a fake website which matches the look and feel of the legitimate site.
What is Spear Phishing?
Spear-phishing is a targeted attempt to steal sensitive information such as account credentials or financial information from a specific victim, often for malicious reasons. This is achieved by acquiring personal details on the victim such as their friends, hometown, employer, locations they frequent, and what they have recently bought online. The attackers then disguise themselves as a trustworthy friend or entity to acquire sensitive information, typically through email or other online messaging. The main difference betwen Phishing and Spear Phishing, is Spear Phishing is very precise and very targeted in nature.How can you prevent any potential damage of phishing to your brand?
- Develop and run in-house internal user awareness program to computer security regularly
- Over communicate the risks and dangers of phishing to your external customers and suppliers
- Buy all possible spoofable domain names to protect themselves and their suppliers and customers. To make things worse, all web url and email are underlined
- user@woman.com become user@vvoman.com (w is replaced by double v)
- www.woman.com become www.wornan.com (m is replaced by r & n)
- www.catgirl.com become www.catqirl.com (g is replaced by q)
- www.google.com become www.qooqle.com (g is replaced by q)
- It is expensive exercise to do. There are endless combination of these domain.
How can you do to migitate the risks of the impact of phishing?
- Change password at least once a year
- Enable 2FA/MFA for your email accounts (via sms or mobile apps authenticator)
- Enable Windows Defender Browser Protection for Google Chrome Browser
- Enable mail identity protection on your mail server
- SPF - Sender Policy Framework
- DMARC - Domain-based Message Authentication Reporting and Conformance
- DKIM - Domain Keys Identified Mail
- Install a reliable and effective endpoint security software for your PC or Notebook. We recommend that you can try Kaspersky Endpoint Security Cloud Plus. It has Mobile Security and Security for Microsoft Office 365
- If you are using Office 365 (O365) or Microsoft 365 (M365) then you should enable Office 365 Advanced Threat Protection. It has Safe Links, Safe Attachments and ATP anti-phishing protection
- Put in internal control checks to manage any external request to change bank account number
- Check Domain with Domain Dossier https://centralops.net/co/DomainDossier.aspx
- Insist on Offical Signed and Stamped Document
- Land Phone Verification
- Use a verified telephone number taken from namecard
- Do not use the telephone number taken from the email
Related Topics :
very informative. thank you for the info.
ReplyDeleteThanks
Delete