Fighting Against Phishing

Data Breach Today

Richard Conti of Children's Hospital of Philadelphia on Risk Mitigation Steps Because phishing attacks are so pervasive, aggressive staff educational efforts are essential, says Richard Conti of The Children's Hospital of Philadelphia, who also discusses other risk mitigation steps

Half of all Phishing Sites Now Have the Padlock

Krebs on Security

Maybe you were once advised to “look for the padlock” as a means of telling legitimate e-commerce sites from phishing or malware traps. A live Paypal phishing site that uses [link] (has the green padlock). A live Facebook phish that uses SSL (has the green padlock).

Phishing, Ransomware Attacks Continue to Menace Healthcare

Data Breach Today

Arizona Cancer Center a Recent Victim of Major Phishing Attack As the year winds down, phishing and ransomware attacks continue to plague the healthcare sector, as illustrated by recent breach reports.

Voice Phishing Scams Are Getting More Clever

Krebs on Security

Most of us have been trained to be wary of clicking on links and attachments that arrive in emails unexpected, but it’s easy to forget scam artists are constantly dreaming up innovations that put a new shine on old-fashioned telephone-based phishing scams. FULLY AUTOMATED PHONE PHISHING.

SMS Phishing + Cardless ATM = Profit

Krebs on Security

Thieves are combining SMS-based phishing attacks with new “cardless” ATMs to rapidly convert phished bank account credentials into cash. Phone-based phishing attacks are getting way more clever and are even snaring technology experts, as last month’s story shows.

Phishing Scams in Healthcare: A Persistent Threat

Data Breach Today

Breach Tally Shows Hacking Attacks Involving Email Continue to Plague the Sector With the year nearly over, hacking attacks - especially those involving phishing and other email attacks - continue to rack up big victim counts for health data breaches reported to federal regulators in 2018

Sophisticated Voice Phishing Scams

Schneier on Security

Brian Krebs is reporting on some new and sophisticated phishing scams over the telephone. fraud phishing scams socialengineeringI second his advice: "never give out any information about yourself in response to an unsolicited phone call."

Google: Security Keys Neutralized Employee Phishing

Krebs on Security

Google has not had any of its 85,000+ employees successfully phished on their work-related accounts since early 2017, when it began requiring all employees to use physical Security Keys in place of passwords and one-time codes, the company told KrebsOnSecurity.

The Art of the Steal: FIN7's Highly Effective Phishing

Data Breach Today

Cybercrime Gang Phoned Victims to Increase Phishing Attack Success Rates The FIN7 cybercrime gang regularly phoned victims, posing as buyers, to trick victims into opening phishing emails and attachments with malware, federal prosecutors allege.

Very trivial Spotify phishing campaign uncovered by experts

Security Affairs

Researchers at AppRiver uncovered a very trivial phishing campaign targeting the streaming service Spotify, anyway, it is important to share info about it. Security researchers at AppRiver uncovered a phishing campaign targeting the popular streaming service Spotify.

FIFA caught hook, line and sinker in phishing attack

IT Governance

Football world-governing body FIFA has admitted that its systems suffered a sustained phishing hack earlier this year. It is believed that the breach was caused by an employee falling for a phishing scam.

Lazarus Hackers Phish For Bitcoins, Researchers Warn

Data Breach Today

Bitcoin Exchange Job Lure Traces to Hackers Tied to North Korea Bitcoin-seeking phishing attacks have been trying to socially engineer would-be cryptocurrency exchange executives, warn researchers at Secureworks.

A Successful Strategy for Fighting Phishing

Data Breach Today

Brent Maher of Johnson Financial Group Offers Real-World Lessons Learned The key to lowering the risk of employees becoming victims of phishing is to adopt an "adult learning" approach to training, says Brent Maher, CISO at Johnson Financial Group

Phishing Exposed Medicaid Details for 30,000 Floridians

Data Breach Today

No Misuse of Exposed Data Has Been Reported - Yet Personal details for 30,000 Medicaid recipients in Florida may have been exposed after a government employee fell victim to a phishing attack, state officials warn.

Nation-State Spear Phishing Attacks Remain Alive and Well

Data Breach Today

Russians Tied to Hack Attacks, But 'Two-Factor' No Silver Bullet, Google Warns Spear phishing attacks are in the news again following the Justice Department's indictment of Russian military intelligence officers for alleged attacks against U.S. Here's how to play better phishing defense

The People Factor: Fight back Against Phishing

Data Breach Today

Phishing remains the top attack vector, and an organization's people of course remain the top target. But how can these same people be leveraged as a key component in your anti-phishing defense? Kurt Wescoe of Wombat shares insight

5 ways to detect a phishing email

IT Governance

Phishing has been used as a way for criminal hackers to gain sensitive information since the mid-1990s. Phishing emails can impersonate well-known brands or even people you know, such as colleagues. Phishing attacks are becoming more sophisticated, making them harder to detect.

Phishing Defense: Block OAuth Token Attacks

Data Breach Today

But OAuth Attack Defense Remains Tricky, Warns FireEye's Douglas Bienstock Just one click: That's all it takes for a victim to inadvertently grant attackers access to their email account via a third-party application. Here's how to spot signs of OAuth-related hacking and how to defend against it

Nation-State Phishing: A Country-Sized Catch

Threatpost

Sophisticated nation-state groups now integrate phishing as a core component of their statecraft. Critical Infrastructure Government Hacks InfoSec Insider Web Security andrea little limbago election interference email scame infosec insider nation state Phishing sophisticated tactics State sponsored

This Company Wants to Use the Blockchain to Stop Phishing

WIRED Threat Level

MetaCert has classified 10 billion URLs as either safe, a suspected source of phishes, or unknown. Business Security

Widespread Phishing Campaign Targets Financial Institutions

Data Breach Today

A phishing attack on Wednesday fueled by the Necurs botnet targeted at least 2,700 banking institutions of various sizes in the U.S. and around the world, explains Aaron Higbee of Cofense, which detected the attack

Last quarter saw 137M phishing attacks, up nearly 30 percent

Information Management Resources

The number of phishing attacks worldwide in the third quarter of 2018 reached more than 137 million, an increase of nearly 30 percent according to security company Kaspersky Lab. Phishing Data security Cyber security Cyber attacks

Gmail Glitch Offers Stealthy Trick for Phishing Attacks

Threatpost

Web Security Bug email glitch Gmail malicious actor PhishingThe issue comes from how Gmail automatically files messages into the "Sent" folder.

Phishing attack puts protected data at risk for 128,400

Information Management Resources

A sophisticated phishing incident at a New York oncology and hematology practice went undetected for a week, affecting 128,400 individuals. Phishing Hacking Protected health information Data security

4 reasons why phishing is so successful

IT Governance

Phishing attacks are on the rise, evolving in variety and sophistication and threatening email security. An IRONSCALES report has revealed that 90–95% of all successful cyber attacks begin with a phishing email. Widespread availability of low-cost phishing and ransomware tools.

Office 365 Phishing Campaign Hides Malicious URLs in SharePoint Files

Threatpost

Hacks Web Security Malicious URL microsoft phishing Microsoft SharePoint Office 365 Phishing phishing attack phishing campaign SharepointResearchers say the "PhishPoint" tactic has already impacted 10 percent of Office 365 users globally.

GUEST ESSAY: 5 anti-phishing training tools that can reduce employees’ susceptibility to scams

The Last Watchdog

This tool, from Cofense, proactively engages employees via simulated attacks based on real-time threats for various phishing tactics. This methodology is distributed over a period of a year giving employees time to understand various phishing strategies. This is a platform for security awareness training and simulated phishing tests focusing on the problem of social-engineering. Organizations select the phishing templates and landing page for simulation.

New Phishing Scam Reels in Netflix Users to TLS-Certified Sites

Threatpost

Researchers are warning of a new Netflix phishing scam that leads to sites with valid TLS certificates. Hacks Privacy Netflix Netflix phishing Phishing phishing scam TLS sites

Police Bust 20 Phishing Suspects in Italy, Romania

Data Breach Today

Arrests Came After a Two-Year Investigation of 'Highly Organized' Crime Group Police have charged 20 Romanian and Italian nationals with running spear-phishing attacks that stole more than $1 million from online bank customers.

Mid-sized organisations are the most vulnerable to phishing attacks

IT Governance

However, this strength turns to weakness when it comes to phishing. By training employees on using strong passwords and being more vigilant at spotting phishing attacks, businesses can significantly increase the strength of their IT security.” . How to avoid phishing attacks .

RSA Fraud Report: Newsjacking-Based Phishing on the Rise

Data Breach Today

Angel Grant Analyzes Findings, Which Also Show a Surge in Mobile App Fraud RSA's most recent Quarterly Fraud Report shows that "newsjacking" is increasingly empowering phishing attacks, says Angel Grant, RSA's director of identity fraud and risk intelligence.

Dridex Banking Trojan Phishing Campaign Ties to Necurs

Data Breach Today

Botnet Also Pushes Ransomware, Cryptocurrency, 'Virtual Kisses' The operators of the Necurs botnet continue to target victims with phishing campaigns designed to infect them with banking malware, ransomware and cryptocurrency fever, as well as to generate profits via dating website referrals

GDPR phishing scam targets Airbnb customers

IT Governance

Criminal hackers are taking advantage of the imminent General Data Protection Regulation (GDPR) with a phishing campaign targeting Airbnb customers. The phishing scam seeks to exploit this. How can I detect a phishing email? There are a number of ways to spot a phishing email.

Gmail Glitch Enables Anonymous Messages in Phishing Attacks

Threatpost

Vulnerabilities Web Security "from" header forged sender Gmail gmail bug Phishing spearphishing Spoofing uxA glitch in the UX in Gmail allows the “from” field to be forged so there is no sender listed in the email's header.

7 Most Prevalent Phishing Subject Lines

Dark Reading

The most popular subject lines crafted to trick targets into opening malicious messages, gleaned from thousands of phishing emails

TSB customers targeted by mobile phishing attacks

IT Governance

Cyber criminals are taking advantage of TSB’s recent IT problems to exploit customers using mobile phishing attacks. According to Wired , the phishing attacks encourage TSB customers to click a fraudulent URL and enter their credentials to file a complaint against the company.

Detecting Phishing Sites with Machine Learning

Schneier on Security

certificates machinelearning phishing spoofingReally interesting article : A trained eye (or even a not-so-trained one) can discern when something phishy is going on with a domain or subdomain name.

Phishing Campaign Steals Money From Industrial Companies

Threatpost

Phishing emails purported to be commercial offers - but were really installing remote administration software on victims’ systems. Hacks Malware Uncategorized Web Security data theft email scam Industrial Security malware Phishing Phishing emails remote administration software

Attackers Are Landing Email Inboxes Without the Need to Phish

IG Guru

Well now, threat actors don’t even have to exert the effort to phish to land business email accounts. The post Attackers Are Landing Email Inboxes Without the Need to Phish appeared first on IG GURU. IG News Information Governance information privacy information security Security keylogging phishing Social Engineering spoofingBy Alastair Paterson on November 23, 2018 We’ve all heard the proverb: Give a man a fish and you feed him for a day.

Innovative Phishing Tactic Makes Inroads Using Azure Blob

Threatpost

Cloud Security Web Security Azure blob campaign cloud storage Microsoft Netskope phishing techniqueA brand-new approach to harvesting credentials hinges on users' lack of cloud savvy.

False Alarm: Phishing Attack Against DNC Was Just a Test

Data Breach Today

Unannounced Exercise Stoked Voter Database Hacking Fears A website that appeared to be part of a phishing campaign designed to gain access to the Democratic National Committee's voter database has turned out to be part of an uncoordinated security exercise.

Think you’re not susceptible to phishing? Think again

IT Governance

Phishing is big business for cyber criminals. According to PhishMe’s Enterprise Phishing Resiliency and Defense Report 2017 , phishing attacks rose by 65% last year, with the average attack costing mid-sized companies $1.6 Help your staff avoid phishing attacks.

Mayfair art dealers suffer phishing attack

IT Governance

Recent reports of a phishing attack on Mayfair art dealers have revealed that “at least nine galleries or individuals were affected, including Hauser & Wirth, and London-based dealers Simon Lee, Thomas Dane, Rosenfeld Porcini and Laura Bartlett”.