New UK Phishing Campaigns Lure Industry Targets With Compromised Email Contacts

Stu Sjouwerman | Aug 2, 2018
phishing-macboat

A new batch of U.K. phishing campaigns is using compromised email contacts to lure targets from the engineering, transport and defense sectors.

According to a recent advisory from the U.K.’s National Cyber Security Centre (NCSC), a “widespread phishing campaign” is now affecting multiple industries. All the phishing samples the researchers observed were similarly themed, indicating that the attacks are likely part of a larger, connected effort to compromise the engineering, transport and defense industries.

While the NCSC has yet to identify the source of this campaign, it noted that “the tools and techniques used suggest criminal involvement.”

According to the advisory, potential victims receive an email from one of their supply chain contacts whose account has been compromised. The message asks the recipient to visit a URL contained in the email or open an attached PDF that leads to a URL. In both cases, users are directed to cloned login pages for popular services such as Office365, OneDrive and Apple. The cybercriminals then attempt to capture and exploit this login data. Continued:

https://securityintelligence.com/news/new-uk-phishing-campaigns-lure-industry-targets-with-compromised-email-contacts/

Topics: Phishing

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the human and AI workforce to make safer security decisions every day. Trusted by over 70,000 organizations worldwide, we help strengthen security culture and manage risk. Our comprehensive AI-driven platform includes awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, agent security and more. As the only global security platform of its kind, KnowBe4 provides personalized content, tools, and techniques to keep the modern workforce safe from phishing, vishing, deepfakes, and emerging threats.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.