Researchers at ReliaQuest have published a report looking at cyber threats surrounding the upcoming US presidential election, warning that election-related phishing will continue to increase over the next month.
People working in the political sphere need to be wary of state-sponsored spear phishing attempts. The Trump and Harris campaigns have both already been targeted by nation-state phishing attacks, with an Iranian threat actor succeeding in stealing information from the Trump campaign.
“APTs often use phishing and spear phishing to gain unauthorized access to sensitive communications,” ReliaQuest says.
“To protect against these tactics, organizations are advised to deploy advanced email security solutions that use machine learning to detect and block phishing attempts. For enhanced protection, the security solution should also conduct threat simulations and red team exercises to identify and mitigate weaknesses. Security teams should provide contextual awareness training that incorporates real-world scenarios and recent case studies.”
Cybercriminals are also exploiting interest in the election, attempting to trick users into handing over their credentials, installing malware, or sending money.
“As the election draws near, businesses and individuals will likely see a significant increase in election-themed phishing emails,” the researchers write.
“We anticipate cybercriminals will craft emails pretending to be from legitimate political campaigns, election authorities, or news outlets. These emails typically contain urgent calls to action like donation requests or critical voting procedure updates to deceive recipients into clicking malicious links or downloading harmful attachments. We have seen election-related customer incidents involving both traditional, external phishing with malicious links and using internal spear phishing to exploit trusted relationships within organizations.”
The researchers add, “Advancements in AI will likely enable cybercriminals to create more personalized and convincing phishing emails by analyzing user behavior, preferences, and social media activity. Advanced AI algorithms can generate realistic and contextually relevant content, mimicking the writing style and tone of legitimate sources such as electoral bodies or campaigns, making it harder for recipients to detect fraud.”
KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.
ReliaQuest has the story.