New Potential Phishing Scam Begins with A Phone Call

Stu Sjouwerman | Mar 31, 2020

Closeup of hands of young man in checkered shirt using mobile phone while his partners arguing-1A recent suspicious phone call was brought to our attention. It looks to be the beginning of a phishing campaign and demonstrates the lengths cybercriminals will go to in order to ensure success.

One of our threat analysts reached out to me today and shared an email they received from a customer who wanted to bring to our attention a vishing call he had taken that felt far more like social engineering than it did a legitimate call.

Take a read:

3-30-20 Image

Now, it’s completely possible that this was a business development rep from Ctirix. But, from the tone conveyed and the inferred bit about the email being incorrect, it doesn’t sound like they ever got anything legitimate from Citrix.

Assuming this to be a vishing email designed to bring the victim’s defenses down when they are sent a phishing email, it means there was some diligence done using online tools like LinkedIn and other business contact data mining services to pull together a profile of the potential victim before calling. They, then identified a brand and to impersonate and “story” to use that would yield the highest engagement rate.

The idea of vishing before phishing isn’t out of the realm of possibility; the use of social engineering takes all forms. And a layered attack strategy likely has a better chance of succeeding than simply sending, in this case, an unsolicited email from a known vendor, which - in the case of IT pros specifically – would probably have a very low success rate.

Educate your users with Security Awareness Training about attacks like this, along with the use of vishing, phishing and social engineering as separate tactics. Attacks are getting more sophisticated to increase their chances of success. Without training, you users may fall more easily for these types of attacks.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.