5 Tips to Protect Yourself Against Spear-phishing Attacks | Antivirus
The word “Burisma” recently made the headlines: indeed, it is about a Ukrainian power generation company which, according to some claims, was attacked by hackers looking for data. sensitive to steal.
As you can imagine, the hackers used phishing attacks a priori.
Phishing, to summarize very briefly, is a technique used by a cybercriminal to trick you into revealing digital information that you should have kept confidential.
The good news is that most of us have learned to spot the most common phishing attacks these days.
The bad news is that you can't reliably spot phishing attacks just by paying attention to obvious mistakes that have been made or by hoping that cybercriminals will call you “ Dear Customer ” instead of using your name directly.
You should be careful with targeted phishing, often referred to as spear-phishing, where cybercriminals go to great lengths to personalize each email, such as tailoring it specifically to you and your business.
Spear-phishing, which uses fake emails really credible, is not only a problem for prominent victims such as company Burisma or other companies of the same type present in the world.
Acquiring the specific data needed to create personalized phishing emails is easier than you might think, and much of the data collection can be automated.
5 tips to protect yourself against spear phishing
So here are our 5 tips for fighting spear-phishing attacks, especially if you are dealing with a cybercriminal who is willing to put in the time and effort to earn your trust instead of just flooding you with “ Dear emails”. customer ”:
1. DON'T LOSE YOUR GUARD ONLY BECAUSE SOMEONE SEEMS TO HAVE A LOT OF INFORMATION ABOUT YOU
Someone you have never met, and certainly will never meet, can nonetheless easily pose as a loved one, a friend of a friend perhaps, or even a colleague with whom you have worked remotely at home. a time, without ever meeting you face to face.
With a mix of information collected from already public data breaches, social media profiles, and the history of emails you sent or received, even a cybercriminal with modest financial means and little technical knowledge will be able to be much more convincing than a simple “ Dear Customer ”.
2.DON'T RUSH TO SEND YOUR DATA JUST BECAUSE YOUR CONTACT IS TELLING YOU IT'S URGENT
Many email scams work because the cybercriminal in question manages to gain your trust or trick you into believing that they are very well placed at the top of your own business organization chart, while also emphasizing the urgency of the task. that he has just entrusted to you.
He will often resort to flattery as well, explaining why he is asking you and no one else. It will make you understand that the requested work is confidential and therefore should not be shared with a third party.
Never take it for granted that you are required to be completely silent; instead, treat this request as suspicious.
3.DO NOT RELY ON THE DETAILS PROVIDED BY THE SENDER EVEN AFTER CHECKING THEM
You probably think that cybercriminals will try to insistently discourage you from carrying out any checks, but sometimes, not only will they welcome your approach, but they will actively encourage you to call them back, send them a message, or even call them back. visit their website. Beware because, in reality, this strategy is precisely part of the scam.
If you call them back on the phone number they gave you or send them a message through the website they provided to you, then you are giving them a tremendous opportunity to tell you the lies they want. that you adhere.
NB: This is why financial institutions print their emergency contact numbers on the back of your bank card and display them on the home screens of their ATMs: indeed, for cybercriminals, this information is much more difficult to handle.
4.DO NOT FOLLOW THE INSTRUCTIONS TO VIEW AN EMAIL THAT APPEARS JUST IN THE EMAIL RECEIVED.
A common technique used by cybercriminals is to hide malicious content, such as data-stealing software more commonly known as macros, inside harmless-looking document-type files, and then prefix the " document ". ”Instructions on how to view it“ properly ”by changing various security settings.
Usually, the instructions seem pretty realistic, but cybercriminals are actually tricking you into disabling security features that are meant to protect you.
5. DON'T BE AFRAID TO ASK FOR A SECOND OPINION
If you've ever asked co-workers to proofread your documents or emails, they've often found mistakes you didn't think you could have missed.
This is because a second opinion is essential and precisely allows you to see beyond appearances.
In fact, this is the main reason why cybercriminals tell you not to share what you do with anyone, just to prevent you from getting a second opinion and unmasking them.
The advice also for IT teams
While we're at it, here are 3 more tips for IT teams and system administrators:
1. DEFINE A SINGLE POINT OF CONTACT TO ENABLE EMPLOYEES TO REPORT CYBERSECURITY ISSUES
Most spear phishing attempts don't work because employees are deliberately trying to be malicious, but because they want to be benevolent by being helpful and providing the best customer service possible to everyone.
No one wants to risk being that “ex-colleague who was fired for treating one of his most important clients with contempt.”
By providing a single point of contact for any reporting such as an internal address like securite-signalement@exemple.com, you make it easy for your users to get safety advice before they take risks, not after.
The worst would be to be the victim of spear-phishing by email and to find out that the person who fell in the trap was unfortunately not the first in the company to be had and that with an alert system set up upstream, you could have simply prevented this attack from happening.
2. MAKE CYBERSECURITY A SPACE FOR EXCHANGE AND SHARING: LISTEN TO YOUR USERS!
In the 1990s and 2000s, cybersecurity was often based on the idea that “equip them and IT systems were the real experts and would set all the rules to be followed, without exception”.
But this approach tends to create a culture in which anything that isn't blocked is blindly assumed to be reliable.
Even high traffic, legitimate websites get hacked sometimes, and if one of your users happens to be the first person to be tricked, you want them to be able to tell you, without shrugging their shoulders and ignoring. quite simply the problem encountered.
3. THINK ABOUT PHISHING ATTACK SIMULATIONS
Products like Sophos Phish Threat can allow you to expose your users to the same techniques used in spear-phishing attacks, but safely so that if they were to fall into the trap, no real damage was done. would be caused.
As long as you make it clear that your phishing tests are there to help and educate your users, and not to watch them and grab them when the time comes, then everyone will benefit.
After all, some of your employees are probably already receiving dozens of real phishing or spear-phishing emails every month, so even if you don't test your users, fear not because cybercriminals will most likely test them for you! Antivirus installs to safe your pc.

Comments
Post a Comment