Connecting to LinkedIn...

W1siziisijiwmtuvmdqvmtuvmdgvntqvmzgvnzi1l01ptlrbu0hfqkxpr19vtljftkrfukvex0lnqudfx3jlc2l6zwrfyw5kx3jlbmrlcmvklmpwzyjdlfsiccisinrodw1iiiwimtkymhgxmjuwiyjdxq

Blog

The weak link in the enterprise security chain: Falling for phishing

4/09/2014 by

W1siziisijiwmtqvmtavmjgvmtuvmtyvmzyvmjk0l2zpbguixsxbinailcj0ahvtyiisijywmhg0mdbcdtawm2uixv0

New research suggests that human error and a lack of knowledge concerning online scams remain a risk to enterprise security.

The report, McAfee Labs Threats Report: August 2014, claims that phishing campaigns remain a prime way to access enterprise networks.

Phishing campaigns come in many forms and guises. These days, phishing goes far beyond crude emails telling you you've won the Spanish Lottery or have a rich uncle in Nigeria who wants to transfer millions of dollars to your account. Instead, cyberattacks hijack news events -- such as high-profile security breaches -- in order to steal your information. A phishing email may claim your account has been compromised in a breach and you must change your password, PayPal has suspended your account until you verify particular details, a student loan has been delayed until you log in, or your bank has a transaction in question.

Many of these campaigns will lead their victims to genuine-looking but malicious websites that mirror legitimate firms, and once you input your data, the information wings its way to cybercriminals. What makes many phishing emails seem genuine is not only short-term campaigns that exploit news events, but tapping in to the irrational human emotion of panic -- what's going on at the bank, or how will I get my student loan? -- preventing users from taking a step back and thinking before clicking on a link.

s so many businesses now rely on technology to run successfully, and cybercrime continues to evolve and become more sophisticated, it is unsurprising that social engineering is now such an important facet of cyberattacks.

Both mass and spear phishing are rampant in today's cyber space. When McAfee presented 10 email messages which were a mixture of genuine messages and phishing campaigns in a quiz designed to test business users' ability to detect online scams, 80 percent of its participants failed to detect at least one of seven phishing emails.

Furthermore, employees in finance and human resource departments proved to be the worst at detecting phishing campaigns.

The most successful tactic was the use of spoofed email addresses, and test takers missed them 63 percent and 47 percent of the time, respectively. The sample phishing email most likely to fool users appears to be sent from UPS, complete with a sender address spoofed to appear from the UPS.com domain. The email itself contained a link to the genuine UPS shipment tracking page, but a second, malicious link prompted an "invoice" download. This link delivered a payload of malware disguised in a .zip archive.

This article has been extracted from http://www.zdnet.com/, please click on this link to read the article in full http://www.zdnet.com/the-weak-link-in-the-enterprise-security-chain-falling-for-phishing-7000033289/

Montash is a multi-award winning, global technology recruitment firm. Specialising in permanent and contract positions across mid-senior appointments which cover a wide range of industry sectors and IT functions, including:

ERP, BI & Data, Information Security, IT Architecture & Strategy, Energy Technologies, Demand IT and Business Engagement, Digital and E-commerce, Infrastructure and Service Delivery, Project and Programme Delivery.

With offices based in London, Montash has completed assignments in over 30 countries and has appointed technical professionals from board level to senior and mid-management in permanent and contract roles.

comments powered by Disqus

Social Stream

Latest News

W1siziisijiwmtcvmdgvmtqvmtmvmjcvmjgvnja2l2nsb3rozxmuanbnil0swyjwiiwidgh1bwiilcizodb4mtawiyjdxq

In Her Shoes... From Market Stall to Recruitment

2017-08-14 14:00:00 +0100

From the melee of the market stall to placing candidates in high-flying IT roles, life's always on the up from market-trader-turned-recruiter, Lois Hinken (22). She took the time to talk to us about how her experience in the cut throat world of the market has helped her in the world of global talent acquisition. As a 360 recruitment consultant for Montash, her negotiation skills and "go get it" attitude have helped her thrive. "I started working on the ...

W1siziisijiwmtcvmdgvmdcvmtmvmtcvntqvnze3l1vudgl0bgvkigrlc2lnbiaomikuanbnil0swyjwiiwidgh1bwiilcizodb4mtawiyjdxq

Will AI Cost Us Our Humanity?

2017-08-07 15:00:00 +0100

As technology evolves, artificial intelligence is becoming increasingly mainstream, and it will inevitably start to impact the way we interact. On the one hand, AI has the potential to solve a variety of problems and streamline our lives and our work. But will this come at the cost of the all-important human touch? A foreshadowing statistic claims that by 2020, 85% of client interactions will be managed without a human[1]. But can there really be an alg...