{"id":13730,"date":"2024-04-11T13:02:10","date_gmt":"2024-04-11T07:02:10","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=13730"},"modified":"2024-06-19T13:34:04","modified_gmt":"2024-06-19T07:34:04","slug":"a-tale-of-the-three-ishings-part-1-what-is-phishing","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/a-tale-of-the-three-ishings-part-1-what-is-phishing\/","title":{"rendered":"A Tale of the Three *ishings: Part 1 \u2013 What is Phishing?"},"content":{"rendered":"<div class=\"container\" data-v-2e266d28=\"\">\n<p class=\"description whitespace-break-spaces\" data-v-2e266d28=\"\">Phishing remains and will remain one of the foremost methods used by cyber attackers today.<\/p>\n<p data-v-2e266d28=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-13731 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2024\/04\/SSA_-_CAM_-_Blog_Thumb_-_Tis_the_season_SMeaSon__for_Smishing_-_-1.webp\" alt=\"\" width=\"600\" height=\"600\" \/><\/p>\n<p>Over the past two decades, the cybersecurity industry has focused extensively on using technology to secure itself, achieving significant advancements in this regard. Unfortunately, organizations have often overlooked the human factor, which cyber attackers have exploited. These attackers have shifted their focus to targeting humans directly, utilizing what many refer to as the &#8220;three *ishings&#8221;: phishing, smishing, and vishing. In this series of blog posts, we will delve into these methods, explore how attackers are adapting their strategies, and discuss effective countermeasures.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Let&#8217;s begin by defining phishing:<\/strong><\/p>\n<p>Phishing is a form of social engineering attack where cyber attackers deceive victims into performing actions that compromise security, such as sharing passwords or granting access to sensitive information. It primarily operates via email, though smishing (messaging-based) and vishing (voice\/phone-based) variants exist and will be covered in subsequent posts. What makes phishing so effective is its widespread use of email, a ubiquitous communication tool in every organization. Attackers exploit this by crafting deceptive emails that manipulate recipients into unwittingly complying with their demands. Moreover, email provides a cost-effective means to reach a global audience swiftly.<\/p>\n<p>The evolution of phishing tactics includes traditional methods like malicious links and attachments, which aim to either infect devices with malware or harvest login credentials. However, cyber attackers are now employing more sophisticated approaches:<\/p>\n<p>1. <strong>Business Email Compromise (BEC)<\/strong>: These targeted attacks, also known as CEO fraud, do not include links or attachments. Instead, they rely on convincing language to deceive finance personnel into authorizing fraudulent transactions, often posing as trusted executives or vendors.<\/p>\n<p>2. <strong>Call Back<\/strong>: This method prompts victims to call a provided phone number, where attackers use persuasive tactics to extract sensitive information or initiate unauthorized transactions under false pretenses.<\/p>\n<p>3. <strong>QR Codes<\/strong>: Instead of traditional links, attackers include QR codes in emails. These codes redirect users to malicious websites, exploiting vulnerabilities that traditional phishing filters may overlook, particularly on mobile devices.<\/p>\n<p>Furthermore, phishing attacks can be highly tailored through techniques like spear phishing (targeted at specific individuals) and whaling (targeted at high-profile individuals or executives). Moreover, cybercriminals are increasingly outsourcing their phishing operations through Phishing-as-a-Service (PaaS) platforms, which offer sophisticated attack templates and infrastructure for a subscription fee.<\/p>\n<p>To combat phishing effectively, organizations employ a dual approach of enhancing technical controls and providing comprehensive workforce training. While technological defenses continue to evolve, some phishing attempts evade detection due to attackers&#8217; evolving tactics. Therefore, training programs should focus on recognizing common phishing indicators rather than attempting to cover every possible lure. These indicators include urgency, pressure to bypass protocols, curiosity-inducing messages, discrepancies in tone or salutation, and emails from personal addresses disguised as legitimate contacts.<\/p>\n<p>It&#8217;s crucial to adapt phishing prevention strategies continually as attackers refine their methods. For more insights into protecting your workforce against evolving cyber threats, consider joining SANS Institute&#8217;s LDR433 Managing Human Risk course.<\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<p>Source:\u00a0<a href=\"https:\/\/www.sans.org\/blog\/a-tale-of-the-three-ishings-part-1-what-is-phishing\/\">https:\/\/www.sans.org\/blog\/a-tale-of-the-three-ishings-part-1-what-is-phishing\/<\/a><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Gi\u1edbi thi\u1ec7u v\u1ec1 DT Asia<\/strong><\/p>\n<p>DT Asia \u0111\u01b0\u1ee3c th\u00e0nh l\u1eadp v\u00e0o n\u0103m 2007 v\u1edbi s\u1ee9 m\u1ec7nh r\u00f5 r\u00e0ng l\u00e0 x\u00e2y d\u1ef1ng b\u01b0\u1edbc th\u00e2m nh\u1eadp th\u1ecb tr\u01b0\u1eddng cho c\u00e1c gi\u1ea3i ph\u00e1p b\u1ea3o m\u1eadt CNTT ti\u00ean phong kh\u00e1c nhau t\u1eeb M\u1ef9, Ch\u00e2u \u00c2u v\u00e0 Israel.<\/p>\n<p>Ng\u00e0y nay, DT Asia l\u00e0 nh\u00e0 ph\u00e2n ph\u1ed1i gi\u00e1 tr\u1ecb gia t\u0103ng khu v\u1ef1c v\u1ec1 c\u00e1c gi\u1ea3i ph\u00e1p an ninh m\u1ea1ng, cung c\u1ea5p c\u00e1c c\u00f4ng ngh\u1ec7 ti\u00ean ti\u1ebfn cho c\u00e1c c\u01a1 quan ch\u00ednh ph\u1ee7 tr\u1ecdng \u0111i\u1ec3m v\u00e0 c\u00e1c kh\u00e1ch h\u00e0ng h\u00e0ng \u0111\u1ea7u thu\u1ed9c khu v\u1ef1c t\u01b0 nh\u00e2n, bao g\u1ed3m c\u00e1c ng\u00e2n h\u00e0ng to\u00e0n c\u1ea7u v\u00e0 c\u00e1c c\u00f4ng ty thu\u1ed9c danh s\u00e1ch Fortune 500. Ch\u00fang t\u00f4i c\u00f3 c\u00e1c v\u0103n ph\u00f2ng v\u00e0 \u0111\u1ed1i t\u00e1c kh\u1eafp khu v\u1ef1c Ch\u00e2u \u00c1 - Th\u00e1i B\u00ecnh D\u01b0\u01a1ng nh\u1eb1m th\u1ea5u hi\u1ec3u r\u00f5 h\u01a1n c\u00e1c th\u1ecb tr\u01b0\u1eddng v\u00e0 cung c\u1ea5p c\u00e1c gi\u1ea3i ph\u00e1p mang t\u00ednh b\u1ea3n \u0111\u1ecba h\u00f3a.<\/p>\n<p>&nbsp;<\/p>","protected":false},"excerpt":{"rendered":"<p>Phishing remains and will remain one of the foremost methods used by cyber attackers today.<\/p>","protected":false},"author":11,"featured_media":13731,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-13730","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/13730","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=13730"}],"version-history":[{"count":0,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/13730\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/13731"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=13730"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=13730"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=13730"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}