Over the course of the summer I have witnessed the outcomes of three phishing attacks. It is worth reflecting on these, because the same thing could happen to you, or someone in your organisation. If it did how would you handle it?
Case 1.
A company that I have had a long relationship with, who provided a residential security service would invoice me once a year. In this case I anticipate an invoice, and from time to time contact the company to discuss account changes or servicing. Everything was fine for 24 years until June of this year.
The timing here is probably significant. On a Saturday morning I receive a message from the company that appears to have originated from the company and it carries some previous correspondence including my account, my bank details and a new invoice attached to the document.
I say the timing is significant because it is Saturday and they are closed, the office is only manned during the week.
I use an Anti-virus/ security program called ESET Smart Security. It does more than monitor for viruses. It warned me that the email with the invoice carried a virus. I had not tried to open it, the program monitors mail as it comes in and checks it.
I looked at the email more closely and found that while the message appeared to originate from the company, it was actually sent by someone else. Checking the email headers, it was clear it did not actually come from the company at all.
How did they get my personal information?
It was clear that a data breach of some form had happened at this company, and now someone was working through old email threads and trying to propagate a virus payload hidden in the invoice.
I rang the company support line and asked them to escalate this to the directors of the operation because I was concerned that other people with less adequate protection might actually download and install the virus by accident. I tried three times and even wrote a letter. Nothing happened for around 6 weeks! In the meantime I received several more invoices carrying the same virus payload.
No security breach here!
I received a very poorly worded broadcast newsletter that had not been checked by the company stating that an incident had happened which had been traced to the administrators computer. A virus had been installed on it, which had permitted a third party to read email on the computer. One can speculate that the “bad actor” copied the administrators email box and could see threads for all sorts of things, and could subsequently continue those threads by spoofing the email address. It does not take a rocket scientist to appreciate that the administrator in question probably had access to all sorts of systems through her email account, so you do not really know what happened, or how much information escaped.
The newsletter reporting the incident played it down, assured everyone there was no problem, and everything was under control. They provided an email address if you had any questions.
Naturally I asked one. The email bounced! So I called and asked to speak to a director. I was assured that there had been No Security Breach, all that had happened was an email account was compromised. I challenged this because the email in question that I had received contained my name, address, bank details and other information on. I also pointed out that possibly many of their customers now have viruses on their computers.
Conclusion
I don’t think this incident was taken seriously by the organisation, or reported to the ICO. Ironically the company in question specialism was “security”. They had little knowledge of IT security, and inadequate protection on their computer systems. The main thing I took issue with was they did not inform their client base of the potential risk of clicking on an attachment allegedly from them carrying a virus. This virus, no doubt just extends the problem to affect more people.
The company in question is no longer providing services to me. I cancelled the contract renewal and have gone elsewhere.
What would you do?
Within the policy framework of your organisation how would you handle something like this? Would you be proactive and inform your correspondents about the problem, or would you keep it all quiet and hope nobody notices?
Could you cope if this happened when your main office was closed?
Many of the organisations I work have comprehensive and online policies. Most don’t though. When I look at some of the activity in this area with one client group who seem to be adopting security measures more aligned with MI5 than a small regional charity, this type of problem is more likely to happen than a laptop being stolen.















