Phishing Emails, Links and Websites | Complete Security Software
Recently, the number of phishing attacks on the Internet has increased again. Phishing (English phishing, from fishing - fishing, fishing) is a type of fraud on the Internet, the purpose of which is to obtain the user's login and password, the details of his bank cards and accounts. Basically, the method is used to conduct mass mailings on behalf of popular companies and organizations.
Phishing is based on the fact that users often do not know a simple fact that the services themselves do not send emails asking them to provide their credentials, password, and other personal information.
Phishing links
These are links to fraudulent Internet resources, most often to copies of websites of well-known organizations, banks, online stores, social networks, etc. By clicking on such a link, you are taken to a resource where they are trying to force you to enter your username and password by various methods.
Typically, these links are sent to you by mail or in a personal message, for example, on social networks. These are either direct links, by clicking on which you get to a site that is almost no different from the real one, or links with a redirect (redirect), by clicking on which you are redirected to other sites and ultimately get to the resource of scammers. Once on such a site, you may not immediately understand that you are in a trap, while the scammers are trying to extract the information they need from you in the form of a login and password.
There are several types of phishing links:
Direct - the link leads to the same page as its address.
With a redirect - the link takes you first to one side, then redirects to another, then to a third, etc.
Hidden - the link looks correct on the outside, but in reality, it leads to a phishing page.
fishing-site-5
An email with a phishing link
Phishing site
This is a site that is completely or partially copied from the original, but it is not. The purpose of these sites is to steal the login and password that you use on the original site. The user follows the phishing link and sees a regular portal in front of him, which he constantly uses. Unsuspectingly, he enters his username and password, which immediately become known to the attackers.
Such sites outwardly completely copy the original, but if you look closely at the address in the address bar, you will see an error in it:
Usually, a copy of the site is first created, then an informational letter is sent to users that there was some kind of failure on the site or another good reason is given in connection with which you must log into your account. You follow the link, enter your username and password ... and you are in the clutches of intruders.
Phishing protection
All modern browsers have the ability to inform users about a suspicious site. This function is called "Antiphishing". Therefore, always keep your browser version up to date by constantly installing the latest updates. Also, browsers already have an additional anti-phishing mechanism built-in.
Any modern antivirus has the function of warning and blocking the transition to a dubious portal. Use the latest antivirus complete security software solutions.
Fighting email services with special spam filters that process email before reaching the user.
There are many different technical ways to protect against phishing, but the “weak link” in this chain is the user himself, his curiosity and inattention allow fraudsters to effectively use social engineering methods.
You need to be careful about where and what you enter.
Do not click on links that you have not verified or that you have not verified.
Be sure to pay attention to the address in the address bar of the page you are currently on because the address http://facebook.sait.com is actually a phishing component of the sait.com website.
If you accidentally entered your username and password on the cybercriminals' resource and only then noticed that this is a deception, then immediately go to the real site and change the data that you entered - the password, if possible, the login, secret questions for data recovery. Also, be sure to report what happened to the resource support service.
Typically, portals send mailings about an attempt to hack user accounts and that users may receive an email with a fraudulent link.

Comments
Post a Comment