The latest warning from Financial Industry Regulatory Authority (FINRA) puts firms on notice of yet another tailored attack seeking to gain access to firms networks.
It’s no surprise that brokerage firms are under attack by cybercriminal organizations; they, by definition, are where the money is. But in most cases, attacks are not widespread enough to warrant a warning from an industry’s governing body.
According to FINRA, the phishing email “appears to be from a legitimate credit union attempting to notify the firm about potential money laundering involving a purported client of the firm” and contains a potentially malicious attachment.
Highly targeted phishing campaigns are the new norm, with cybercriminals doing reconnaissance and diligence about their targets in an effort to leverage as much context as possible to establish credibility and improve their chances of success.
Whether your organization is in the world of finance or not, this phishing warning to every industry that cybercriminals are continuing to use targeted campaigns to carry out their evil plans.
Organizations looking to spot suspicious (and potentially malicious) email and web content should be looking to Security Awareness Training to educate users on how attacks take place, what methods are used, what to look for, and how to maintain a constant state of vigilance.
The targeted attack FINRA is warning firms about can likely be spotted a mile away by a trained eye. Security Awareness Training empowers users with the knowledge to become part of your defense against cyberattacks, reducing the threat surface and lowering the risk of successful attack.
Free Phishing Security Test
Find out what percentage of your employees are Phish-prone™
Would your users fall for targeted phishing attacks? Take the first step now and find out before the bad guys do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.
Here's how it works:
- Immediately start your test for up to 100 users (no need to talk to anyone)
- Customize the phishing test template based on your environment
- Choose the landing page your users see after they click
- Show users which red flags they missed, or a 404 page
- Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
- See how your organization compares to others in your industry
PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser: