phishing-attack Phishing Attack
What Is a Phishing Attack?
The term “phishing ” refers to an attempt to steal sensitive information — typically in the form of usernames, passwords, credit card numbers, bank account details, or other important data — in order to use or sell that stolen information. By disguising themselves as a reputable source with an enticing request, the attacker lures the victim into a trap, similar to the way a fisherman uses bait to catch a fish.
diagram-phishing-attack
How Does Phishing Work?
The most common phishing examples are used to support other malicious activities, such as man-in-the-middle attacks and cross-site scripting attacks. These attacks typically occur via email or instant messaging and can be broken down into a few broad categories. It is useful to recognize several of these different phishing attack vectors in order to spot them in the wild.
Advance Fee Fraud
This fraudulent attack is promoted via the so-called “Nigerian Prince” email, in which an alleged Nigerian prince in a desperate situation offers the victim a large sum of money in exchange for a small upfront fee. Unsurprisingly, once the fee is paid, no large sum of money ever arrives. The interesting history behind this is that this type of scam has been occurring for over a hundred years in various forms; it was originally known in the late 19th century as the Spanish Prisoner con, in which a con artist would contact a victim to exploit their greed and sympathy. The con artist allegedly claimed to be trying to smuggle a wealthy Spanish prisoner out of jail, who would generously reward the victim in exchange for money to bribe some of the prison guards.
This attack (in all its forms) is mitigated by not responding to requests from unknown parties that require you to provide money in order to receive something in return. If it seems too good to be true, it probably is. A simple Google search about the subject of the request or some of the text itself will often reveal details of the scam.
Account Deactivation Scam
By playing on the urgency felt by a victim who believes an important account is about to be deactivated, attackers can trick some people into handing over critical information such as login credentials. Here is an example: the attacker sends an email that appears to come from an important institution such as a bank , claiming that the victim's banking account will be deactivated unless they take immediate action. The attacker then requests the victim's banking login and password in order to prevent the deactivation. In a clever version of the attack, once the information is entered, the victim will be redirected to the legitimate bank website so that nothing appears out of the ordinary.
This type of attack can be countered by navigating directly to the service's website and checking whether the legitimate provider is notifying the user of the same urgent account situation. It is also a good idea to check the URL bar and confirm that the website is secure. Any website that requests an insecure login and password should be questioned seriously and, almost without exception, should not be used.
Website Spoofing Scam
This type of scam is usually paired with other deceptive schemes such as the account deactivation scam. In this attack, the attacker creates a website that is nearly identical to the legitimate website of a business the victim uses, such as a bank. When the user visits the page by any means — whether via a phishing email attempt, a hyperlink within a forum, or through a search engine — the victim lands on a website they believe is legitimate rather than a fraudulent copy. All information the victim enters is collected for sale or other malicious use.
In the early days of the internet, these types of duplicate pages were very easy to detect due to their poor craftsmanship. Fraudulent websites today may appear to be a perfect replica of the originals. By checking the URL in the web browser, it is usually easy to spot the scam. If the URL looks different from the usual address, it should be treated with strong suspicion. If pages are listed as insecure and HTTPS is not active, that is a red flag and virtually guarantees that the site is either broken or a phishing attack.
What Is Spear Phishing?
This type of phishing is targeted at specific individuals or companies, hence the term spear phishing . By gathering details or purchasing information about a specific target, the attacker is able to carry out a personalized scam. This is currently the most effective type of phishing attack, accounting for more than 90% of attacks.
What Is Clone Phishing?
Clone phishing involves mimicking a previously delivered legitimate email and modifying its links or attachments in order to trick the victim into opening a malicious website or file. For example, by taking an email and attaching a malicious file with the same name as the original attachment, then resending the email from a spoofed email address that appears to come from the original sender, attackers can exploit the trust of the initial communication to get the victim to take action.
What Is Whaling?
For attacks targeted specifically at senior executives or other privileged users within companies, the term whaling is commonly used. This type of attack is usually targeted with content that is likely to require the victim's attention, such as legal subpoenas or other executive-level matters.
Another common factor in this pattern of attack is whaling phishing emails that appear to come from an executive. A common example is an incoming email request from a CEO to someone in the finance department asking for their immediate assistance in transferring funds. Lower-level employees are sometimes deceived into thinking that the importance of the request and the seniority of the person it comes from overrides any need to double-check the validity of the request, resulting in the employee transferring large sums of money to an attacker.