Phishing and Cyber Attacks Awareness

What is Phishing?

Phishing is the practice of sending communications that appear to come from a legitimate and reputable source, usually through email and text messaging. The attacker’s goal is to steal money, gain access to sensitive data and login information, or install malware on the victim’s device. Motivations for phishing attacks differ, but mainly attackers are seeking valuable user data such as personally identifiable information (PII) or login credentials that can be used to commit fraud by accessing the victim’s financial accounts. Once attackers have login information, personal data, access to online accounts, or credit card data, they can obtain permissions to modify or compromise more cloud-connected systems. In some cases, they can hijack entire computer networks until the victim pays a ransom. Phishing is often perpetrated against elderly individuals or people in targeted organizations’ finance, banking and medical departments.

Types of Phishing?

  • Email Phishing: The most common form of phishing. This type of attack uses tactics like phony hyperlinks to lure email recipients into sharing their personal information. Attackers often masquerade as a large account provider like Microsoft, Amazon, Google, or even a coworker.
  • Malware Phishing: Another prevalent phishing approach. This type of attack involves planting malware disguised as a trustworthy attachment (such as a resume or bank statement) in an email. In some cases, opening a malware attachment can paralyze entire IT systems.
  • Spear Phishing: Where most phishing attacks cast a wide net. Spear phishing targets specific individuals by exploiting information gathered through research into their jobs and social lives. These attacks are highly customized, making them particularly effective at bypassing basic cybersecurity.
  • Whaling: When bad actors target a “big fish” like a business executive or celebrity, it’s called whaling. These scammers often conduct considerable research into their targets to find an opportune moment to steal login credentials or other sensitive information. If you have a lot to lose, whaling attackers have a lot to gain.
  • Smishing: A combination of the words “SMS” and “phishing,” smishing involves sending text messages disguised as trustworthy communications from businesses like Amazon or FedEx. People are particularly vulnerable to SMS scams, as text messages are delivered in plain text and come across as more personal.
  • Vishing: In vishing campaigns, attackers in fraudulent call centers attempt to trick people into providing sensitive information over the phone. In many cases, these scams use social engineering to dupe victims into installing malware onto their devices in the form of an app.

Common Phishing Tactics

  • Cunning Communication: Attackers are skilled at manipulating their victims into giving up sensitive data by concealing malicious messages and attachments in places where people are not very discerning (for example, in their email inboxes). It’s easy to assume the messages arriving in your inbox are legitimate but be wary—phishing emails often look safe and unassuming. To avoid being fooled, slow down and examine hyperlinks and senders’ email addresses before clicking.
  • Perception of Need: People fall for phishing because they think they need to act. For example, victims may download malware disguised as a resume because they’re urgently hiring. Or they enter their bank credentials on a suspicious website to salvage an account they were told would soon expire. Creating a false perception of need is a common trick because it works. To keep your data safe, operate with intense scrutiny or install email protection technology that will do the hard work for you.
  • False Trust: Bad actors fool people by creating a false sense of trust—and even the most perceptive fall for their scams. By impersonating trustworthy sources like Google, Wells Fargo, or UPS, phishers can trick you into taking action before you realize you’ve been duped. Many phishing messages go undetected without advanced cybersecurity measures in place. Protect your private information with email security technology. Which is designed to identify suspicious content and dispose of it before it ever reaches your inbox.
  • Emotional Manipulation: Bad actors use psychological tactics to convince their targets to act before they think. After building trust by impersonating a familiar source and then creating a false sense of urgency. Attackers exploit emotions like fear and anxiety to get what they want. People tend to make snap decisions when they’re being told they will lose money, end up in legal trouble, or no longer have access to a much-needed resource. Be cautious of any message that requires you to “act now”—it may be fraudulent.

How to Avoid Phishing Attacks

  • Don’t Trust Display Names: Check the sender’s email address before opening a message—the display name might be a fake.
  • Check For Typos – Broken English: Spelling mistakes, run-on sentences and poor grammar are typical in phishing emails. If something looks off, ask someone.
  • Look Before Clicking: Hover over hyperlinks in genuine-sounding content to inspect the link address.
  • Read The Salutation: If the email is addressed to “Valued Customer”, “First Name Only” instead of to you directly, be wary. It’s likely fraudulent, again ask someone.
  • Review The Signature: Check for Contact Information, Statement of Privacy, Terms of Use, Trademarks in the email footer. Legitimate senders always include them.
  • Beware Of Threats: Fear-based phrases like “Your account has been suspended”, “Account Compromised” are prevalent in phishing emails and Text Messages.
  • New or Infrequent Senders: Anyone emailing, texting or calling you for the first time. If you are not expecting the “contact”, be suspicious.
  • Avoid Posting Contact Information Online: Some attackers collect info by scraping information from these social media and websites. They collect mobile numbers for key stakeholders from email signatures and use that information for spear phishing and smishing campaigns.
  • Keep Your Browser Updated: Always install Windows/Browser Updates each month
  • Monitor Your Online Accounts Regularly: Check your online statements for charges you did not make. Immediately call online account and lock your account/s as well as change your passwords on a regular basis.
  • Be Wary of Social, Emotion Lures: Verify anyone asking for money or account information. It is OK to hang up and call your “Online Accounts” using known numbers.
  • Never Give Out Personal Information Over Email or Social Media
  • When in Doubt – Ask Someone – Anyone

What to do if you are a Victim of Phishing Attacks

  • Do not be embarrassed and do not do nothing!
  • Write down as many details of the attack as you can recall. Note any information you may have shared, such as usernames, account numbers, or passwords.
  • Call your account’s immediately and put a hold, change or cancel your accounts.
  • Immediately change the passwords on your affected accounts and anywhere else you might use the same password.
  • Confirm that you’re using multifactor (or two-step) authentication for every account you use.
  • Notify all relevant parties that your information has been compromised.
  • If you’ve lost money or been the victim of identity theft. Report it to local law enforcement and to the Federal Trade Commission – www.IdentityTheft.gov Provide as many details as you can.
  • Keep in mind that once you’ve sent your information to an attacker it is likely to be quickly disclosed to other bad actors. Expect new phishing emails, texts, and phone calls to come your way.

Discover more from Northland Health Centers

Subscribe now to keep reading and get access to the full archive.

Continue reading