Beware of Phishing

Over the past year I have become aware of many instances of phishing, it is much more prevalent than it was 2 years ago. It is also becoming increasingly sophisticated, especially if one person in a group that regularly communicate is compromised, his/ her contacts might be next.

Your regular email address is critically important

Phishing will try to target your email address, and get you to enter your password and email address into a box, believing that you can download something allegedly from a colleague. It may appear as an email in your inbox, or you may at some point be directed to a page with a form on it asking you to enter your credentials.

These attacks will frequently occur on a Friday afternoon, or just before a bank holiday weekend, just because it will be more difficult to independently check to see if something is legitimate or not.

I am aware of several cases where organisations have been caught out by this, it works in the following way:

Jane receives an email from a colleague asking her to download a document from say Sharepoint. Jane knows her colleague and while the email may have been short and to the point, she does not suspect anything. She clicks on a form in her email, and is then taken to the form on a website. She enters her email address and password anticipating this will allow her to download a document.

But nothing happens

Well, nothing obvious happened, so I will just assume it was broken……

What has actually happened is Jane’s email address and password has been passed to a 3rd party. The form was not legitimate.  The hacker can now access Jane’s email. In Jane’s email accounts are year’s of correspondence and messages that reveal whom Jane has been talking to, which other accounts she has access to, bank accounts, websites, Credit Cards etc. But Jane does not know someone is looking at her email.  The hacker could independently copy everything now and study it more carefully, and then contact one of Jane’s colleagues and do the same thing.

I received one of these messages last year, as did my wife.  In both cases our security recognised that the website we were being directed to was not legitimate.

Being Paranoid

Please be especially sensitive to anything that looks vaguely odd. These messages when they occur, are often very short, with no context, or a very limited context such as an invoice or payment has been made, or not been made. Many of them are also designed to shock you into acting quickly. They also arrive at the end of a day or just prior to a weekend.

Take a breath – is it real?

Find an independent route to check in with this person to make sure it was really sent and genuine if you are suspicious.  Don’t ever think it won’t happen to me. Complacency is one of the factors of success. Remember that if your main email address is compromised, it compromises everything that you have used your main email address for. Plus your main email address will be used for password recovery too.

In a case where I responded back to the person that was asking me to click on something, I was suspicious, but the person was known to me; I replied. I immediately got a reply back saying it was all quite innocent and not a phishing email…. So I clicked on it, and my security system immediately flagged up that it was a phishing site before I could enter anything. In this case, the hacker was also sitting on the person’s email account and answering emails. The email account owner was unaware that this was happening. This is why it is better to find a phone number and call them, or call a colleague to check first. In my case I used the same communications channel to ask if it was legitimate or not, and the hacker was waiting.

Remember if it goes wrong….

You are going to have to change all of your passwords starting with your email account, and then all of the accounts tied to your email account. It will take a long time to change everything, and you have to remember to cover everything. So it is worth being careful and more sensitive than “normal” whatever normal means these days!

It can be worse if you are using a free email account….

If you are using gmail, yahoo or hotmail, then the hacker can completely take over your account. You will find it quite challenging to regain control. There is no support desk with live people you can converse with on these free email accounts. So do take care, and make sure you have 2 Factor Authentication set up with any free accounts. That will help to protect you. 

Wingrove-Services
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

You can adjust all of your cookie settings by navigating the tabs on the left hand side.

My privacy policy can be located here: Wingrove Media Privacy Policy (opens in a new window)

My Cookies Policy can be found here: Wingrove Media Cookies Policy (opens in a new window)