Learning More on Social Engineering Tactics are the Key to Preventing Phishing Expeditions



Understanding Social Engineering Tactics Prevent Phishing ExpeditionsUnderstanding social engineering attacks is the key to thwarting them, according to Juan Badell and Russell Petrich, content designers for Sophos’s phishing simulation service. Badell and Petrich mimic the way real cybercriminals think in order to craft convincing fake phishing emails, and they outline the four steps attackers go through when they create these emails.

First, the attackers choose their audience and design their phishing template accordingly.

“Different people fall for different tricks, so the more information you have about your target the easier it is to craft a convincing phishing lure,” Badell and Petrich write. ”The audience may be broad, for example users of a particular bank or people who need to do a tax return, or it may be very specific – such as a particular role within an organization or even a specific individual.”

Next, the criminals decide which type of emotional lure they’ll use. Fear is a common motivator, but attackers can play on other emotions as well:

  • “Curiosity. Humans are naturally inquisitive and phishers abuse this by making you want to know more. ‘Do you want to know what happened next?’ All you need to do is to click the link or open the attachment.
  • “Hope. The abuse of hope by phishers can range from general messages about unexpected prize wins and dating opportunities to specific emails referring to job offers, pay increases and more.
  • “Necessity. Phishers often use a cybersecurity lure – pretending that you’ve suffered a security breach – to make it sound as though you simply must act now.”

Third, the criminals build the phishing email, usually including links or malicious attachments. This process has become very easy with the wide availability of phishing kits for sale. Finally, the attackers send the emails, often from a spoofed domain or a hacked account.

Most phishing lures are easy to avoid once you know what to watch out for. New-school security awareness training can help your employees recognize these tactics in the real world.

Naked Security has the story.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews