Taking Control of Your Emails | Cloud Antivirus
How well do your employees identify phishing emails? This is a question that wanted to answer in 2015 using an online quiz featuring "phishing" emails. The results announced that 97% of people globally were unable to correctly identify phishing emails. This very worrying figure, therefore, implies that attackers should still continue to target this mode of attack. Where are we today?
Phishing promises to remain a problem for the foreseeable future as it involves human decisions and judgment in the face of persistent efforts by cybercriminals to lure victims into their traps.
Phishing I've seen before, but Spear-Phishing and Account-Take-Over?
Unfortunately, phishing emails don't just deliver attachments and/or malicious links that shouldn't be executed or clicked on. Indeed, a new form of more discreet compromise is deployed through your email exchanges: remote account takes over.
It is a form of fraud based on identity theft, whereby a malicious third party manages to gain access to the user's email account credentials. By impersonating a real user, cybercriminals can alter account details, send phishing emails, steal financial information or sensitive data, or even use the stolen information to gain access to other corporate accounts. business.
The departments most at risk are IT, human resources, and management, as they have direct access to sensitive data, financial information, and security infrastructure.
Why Are Spear Phishing and Account Take Over on the Rise?
Once access to the company's e-mail is accessible from the outside, the threat of Account Takes Over is real.
Microsoft processes more than 470 billion emails per month in each month, so it is an exposed service that arouses a real target of choice for hackers.
Cybercriminals employ a number of major techniques when attempting to access a secure account.
We can retain the most discreet: Spear Phishing (harpoon fishing).
Cybercriminals will use email exchanges to trick users into revealing their personal information. The victim will then have the illusion of communicating by email with a known person.
These emails do not contain anything malicious, they are highly targeted and much more misleading. In the vast majority of cases, they are not stopped by traditional lines of defense because they are based on social engineering methods.
What Are The Risks of Taking Control of Your Email Account?
Account-taking is not inherently useful for a cybercriminal. Problems happen after the account is compromised:
Phishing campaigns: some attackers try to use the hacked email account to launch phishing campaigns that will not be detected (Example: your customers may then receive Phishing or Spear Phishing campaigns from your legitimate email).
Additional account taking, and/or resale of accounts: others use this account to perform reconnaissance operations in order to launch personalized attacks. Some attackers steal the access of other employees and resell them (Example: this will be used to prepare future more complex attacks).
Compromise of business email: Sophisticated attackers will steal a key employee's credentials and use them to launch an attack from the employee's email address, with the aim of setting up a fraudulent transaction or a transfer of funds (Example: “scam to the president”, but directly from a legitimate member of his organization).
What Are the Issues With Email Incident Response to Date?
Users do not always detect these types of threats.
Users do not always report attempted attacks.
Investigations often take a long time.
The search for malicious emails in all of the organization's mailboxes is too often manual.
The reaction time after an incident is often too long.
The Questions to Ask Yourself to Fight Effectively Against Spear-phishing and Account-take-over:
How do you identify the compromise of access to your users' email?
How long do you take to resolve a phishing attack incident?
What resources do you have to conduct a thorough analysis of the incident?
What is your process for detecting and cleaning malicious emails that have been delivered to users?
What communications do you apply when a compromised account has sent emails to external organizations (customers, partners, suppliers, etc.)
What Technical and Human Tools are Used to Detect Spear Phishing?
Do you know any internal users who would need security awareness training, more specifically on issues related to the use of messaging?
How to Fight Against this Type of Attack?
Undeniably, the implementation of a local or Cloud Antivirus protects your emails, filtering gateway must be the first stone to be laid. Then, solutions exist to make more in-depth analyzes of emails, based on the context and the communication footprints of the companies, while offering advanced solutions of remediation after incidents.

Comments
Post a Comment