As internet security infrastructure becomes smarter and more difficult to penetrate, hackers have made the migration toward phishing attacks as the cyber-criminal weapon of choice because they exploit the seeming weakest part of any security system – humans!
In our data-driven world, most organisations are at least partially dependent on a measure of electronic storage and networking. Perhaps out of experience, large organisations are generally aware of the need for effective cyber security frameworks including firewalls, access and awareness training, and anti-malware systems. Educational institutions, however, tend to be somewhat behind the curve, when it comes to tightly securing their data-verse. Recently, ethical hackers while testing the computer security of university networks discovered that they were able to successfully breach networks in less than 2 hours by using spear-phishing attacks to gain access to sensitive information. Well over 50 universities across the UK were a part of the test and in almost every case, testers were able to acquire domain-level administrator access used to control systems and gain complete unauthorised access to system information.
Everything has a cost, and that does not exclude free public WiFi connections.
It is true that with the onset of the holiday shopping season there is a dramatic up-tick in activity in both the eCommerce world and the cybercriminal. Black Friday and Cyber Monday have now become international shopping events and they are no longer one weekend but seem to go on for three to four weeks. So, with consumers seeing increases in offers, promotions and coupons coming out in emails or SMS messages (SMiShing is the growing threat) as well as all those order confirmations, payment requests and shipping messages there are rich pickings for the cybercriminal who wants to swim in tide of communications hoping to de-fraud some unsuspecting consumers.
Getting to know the new lure sophistication classifications, and how they can help your next campaign.
In 2017, Symantec reported that phishing rates had increased across most industries and organisation sizes. News sites consistently report on the biggest and scariest malware attacks and data breaches, and then ultimately attribute the increased susceptibility to one of many new phishing trends. But what in fact constitutes a highly-sophisticated phishing message? And how can this knowledge help you strategically plan and execute your next test campaigns.
Hurricane Harvey has hit the U.S. State of Texas hard, the most powerful storm to make landfall in the U.S. for over a decade and create what has been described as a 500 year flood. At times like this decent human beings want to help each other. However, for others in society namely "cyber-scum" they are exploiting this disaster and human goodness.
Phishing has been in the news lately, not only because it was the intrusion technique allegedly used by Russian hackers to access U.S. voter registrations, but also because it is becoming more prevalent, especially in the UK. You only have to look at the recent NHS "Wannacry" and the latest "Petrwrap" ransomware incidents both starting with curious staff opening phishing emails to understand the risks.
If the answer to any of these questions is ‘no’, then you are not alone. Employees remain the weakest link in the battle against cybercrime and are criminals number one target.
The content of this article was originally published by Mark O'Regan - Sunday Independent
The HSE could be a 'sitting duck' for a cyberattack unless it radically beefs up security to protect highly sensitive data which may be sold by criminals on the Dark Web.
A widespread cyber attack has been coming folks, and many security professionals are attempting to increase awareness for staff and companies.
Two days ago I shared an article from AIG that stated "systemic cyber attacks" were expected this year across several sectors, including healthcare.