A study by nonprofit research company Jisc and the UK’s Higher Education Policy Institute (HEPI) found that 100 percent of spear phishing tests against universities were able to gain access to sensitive data within two hours. The tests targeted students and staff members at 173 institutions.
White-hat hackers from Jisc used publicly-available information about the universities and their staff members to construct tailored phishing emails, and successfully gained access to research databases, financial systems, or personal information at every participating university. In some cases, this took them less than an hour.
Douglas Bonderud, writing for IBM’s SecurityIntelligence blog, says the lesson here is that “well-written phishing emails are corporate compromise kryptonite.” He recommends that organizations focus on the way employees interact with emails to combat this threat.
“Avoiding the spear phishing hook starts with recognizing the critical link between employees and email,” Bonderud writes. “Most users believe they’re above average when it comes to recognizing the danger signs of phishing, but this doesn’t pan out in practice. By implementing low-key warning processes that recognize key phishing tactics, companies can ensure staff are notified without fighting the ‘it won’t happen to me’ battle.”
Email filters and anti-phishing technologies are essential tools to defend against these attacks, but spear phishing emails are particularly difficult to block, since attackers put in extra effort to ensure that their emails bypass these measures. New-school security awareness training can help your employees identify these emails by teaching them how to confirm that requests for information, access, or money are legitimate before following through.
SecurityIntelligence has the story: https://securityintelligence.com/news/spear-phishing-report-card-perfect-scores-in-school-security-pen-testing/
Free Phishing Security Test
Find out what percentage of your employees are Phish-prone™
Would your users fall for targeted phishing attacks? Take the first step now and find out before the bad guys do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.
Here's how it works:
- Immediately start your test for up to 100 users (no need to talk to anyone)
- Customize the phishing test template based on your environment
- Choose the landing page your users see after they click
- Show users which red flags they missed, or a 404 page
- Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
- See how your organization compares to others in your industry
PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser: