Analysis of a new phishing attack highlight just how easy it can be to spot these kinds of attacks if recipients were properly educated.
Action Fraud, the U.K.’s national fraud & cyber reporting center, recently warned U.K. residents of a scam impersonating Starbucks. The email-based scam purports to be from the global coffee brand, telling the recipient they’ve won a “Starbucks Coffee Lovers Box."
Source: PBS
In reality, it’s a phishing attack designed to take victims to a fake Starbucks landing page intent on getting the victim to enter in their Starbucks customer credentials.
These credentials are then used by scammers to attempt access to other web-based services, online banking, and more – in the hopes that the credential’s owner uses the same email address and password combination.
It’s a simple enough scam to spot – the image above shows just how bogus the actual sender email address is, the email content doesn’t look remotely up to the level of what Starbucks would actually put out, and then there’s the whole “like Starbucks is just going to give me a free gift!” aspect of the scam.
But it does require a vigilant mindset when interacting with email. The need to always assume anything out of the ordinary is “guilty until proven innocent” is something taught via security awareness training that helps instill the sense of vigilance necessary to keep from falling for these scams.
KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.