Red Flags for Phishing: Verizon Outlines Latest Scams to Watch Out For



Phishing Scammers Leverage GovernanceVerizon has published an article outlining various forms of social engineering attacks, including SMS/text messaging phishing (smishing), voice phishing (vishing), and spear phishing (targeted attacks, often via email).

Verizon warns users to be on the lookout for the following red flags:

  • “Scare tactics and urgent messages or subject lines. The ‘URGENT: Payment overdue’ subject line mentioned earlier is an example—bad actors want you to think that there’s some kind of problem with your account that needs immediate attention. Vishing attacks might say that they’ve identified fraud on your credit card or that you’re in trouble with the IRS."
  • “Unprompted calls from ‘customer service.’ Beware of unsolicited calls from ‘customer care agents,’ or from a ‘billing’ or ‘fraud’ department, that ask you for help to access your account or to provide them with sensitive account information. If you’re at all suspicious, hang up and then call the publicly listed customer care number of the company in question (not the number given by the caller) to report the incident. Note: Verizon will never proactively contact a customer asking for sensitive information such as a password or account PIN to perform authentication."
  • “Lookalike or misspelled web or email addresses. A lookalike URL in a link or a misspelled email address is a sure sign of trouble. Remember, you can hover your cursor over a link without clicking to see the actual URL in the link. One example given by Phishing.org: a misspelled link using ‘bankofarnerica.com’ that could look correct at a quick glance; clicking such a link could take you to a malicious site."
  • “Suspicious attachments. Any unsolicited email attachment should be viewed as a warning sign. If the email is from an unknown sender, you didn’t ask for the attachment or the attachment doesn’t make sense in the context of the message, don’t open the file.”

Verizon concludes, “Remember, phishing is common and perpetrators are hoping to catch you with your guard down. But most companies will never proactively reach out to you. And Verizon will never proactively contact a customer asking for sensitive information such as a password, account PIN or to perform authentication. So keep it simple: Trust your gut. When in doubt, hang up, delete the message, and contact the respective company directly.”

KnowBe4 enables your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

Verizon has the story.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews