{"id":13866,"date":"2024-06-12T12:23:12","date_gmt":"2024-06-12T06:23:12","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=13866"},"modified":"2024-06-12T12:23:12","modified_gmt":"2024-06-12T06:23:12","slug":"a-tale-of-the-three-ishings-part-3-what-is-vishing","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/a-tale-of-the-three-ishings-part-3-what-is-vishing\/","title":{"rendered":"A Tale of the Three *ishings: Part 3 &#8211; What is Vishing?"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-13867 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2024\/06\/MGT_-_Blog_-_A_Tale_of_the_Three_ishings_Part_03_\u2013_What_is_Vishing_340_x_340.webp\" alt=\"\" width=\"600\" height=\"600\" \/><\/p>\n<p>Over the past two decades, the security industry has made significant strides in using technology to secure technological assets. However, the human factor in cybersecurity often remains overlooked. Consequently, cyber attackers have shifted their focus from targeting technology to targeting people. Among the various methods they employ, the three most common are phishing, smishing, and vishing. This blog series delves into these methods, the tactics and techniques used by cyber attackers, and how you can protect yourself.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>What is Vishing?<\/strong><\/p>\n<p>Vishing, short for voice phishing, involves cyber criminals making phone calls to deceive individuals. Unlike phishing, which uses emails, vishing relies on phone calls or voicemail messages to trick people into revealing sensitive information, such as passwords or credit card details.<\/p>\n<p>The rise in random voicemails and phone calls asking for passwords or payments is due to the difficulty organizations face in securing personal mobile devices. Security teams often lack the visibility and control over personal phones that they have over workstations, making mobile devices a vulnerable target.<\/p>\n<p>Vishing attacks are challenging to identify and filter. As a result, when a cyber attacker calls a potential victim, the call is more likely to reach its target. Over the phone, attackers can create a sense of urgency and trust that is harder to achieve through email or text, making these attacks more effective and profitable.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Common Vishing Attacks<\/strong><\/p>\n<p>Vishing attacks come in various forms, but here are the most prevalent types:<\/p>\n<p><strong>1. Tech Support Calls<\/strong> Cyber attackers impersonate IT support, calling individuals and requesting their passwords to &#8220;reset&#8221; accounts. These attackers sound convincing and aim to manipulate victims into divulging sensitive information.<\/p>\n<p><strong>2. Government Agency Calls<\/strong> Attackers pose as government officials, claiming that the victim owes taxes and must pay immediately to avoid jail time. Their goal is to obtain credit card details and money.<\/p>\n<p><strong>3. Tech Support Callbacks<\/strong> Instead of making the initial call, attackers trick victims into calling them. This approach bypasses phone call filters and builds inherent trust, increasing the likelihood of success. They may send texts or emails prompting the victim to call a provided number, leading to the theft of information like PayPal passwords.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/images.contentstack.io\/v3\/assets\/blt36c2e63521272fdc\/blt5b2f7890c22a037f\/65e87f624ec10753eb1a0873\/MGT_-_Blog_Graphics_-_A_Tale_of_the_Three_ishings_Part_03_%E2%80%93_What_is_Vishing(1).png\" alt=\"\" width=\"272\" height=\"337\" \/><\/p>\n<p><strong>4. Automated Calls<\/strong> Automated calls, or robocalls, deliver messages about expired warranties, approved refunds, undelivered packages, or suspicious charges. These broad attacks target millions, akin to generic phishing emails.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/images.contentstack.io\/v3\/assets\/blt36c2e63521272fdc\/blt4d15c02bbf7c19b2\/65e87fbb70389a2457f668a6\/MGT_-_Blog_Graphics_-_A_Tale_of_the_Three_ishings_Part_03_%E2%80%93_What_is_Vishing2(1).png\" alt=\"MGT_-_Blog_Graphics_-_A_Tale_of_the_Three_ishings_Part_03_\u2013_What_is_Vishing2(1).png\" width=\"389\" height=\"270\" \/><\/p>\n<div><\/div>\n<p>&nbsp;<\/p>\n<p><strong>Protecting Against Vishing Attacks<\/strong><\/p>\n<p>Despite the focus on phishing in many security training programs, voice-based vishing attacks require equal attention. Employees well-versed in email-based threats might overlook voice-based ones. Rather than detailing every vishing tactic, training should emphasize recognizing common indicators of vishing attacks, applicable to both vishing and other phishing methods.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Key Indicators of Vishing Attacks:<\/strong><\/p>\n<ul>\n<li><strong>Urgency:<\/strong> Calls that create a sense of urgency, pressuring victims to act quickly and make mistakes. For instance, the government will never call about overdue taxes; they send official documents by mail.<\/li>\n<li><strong>Pressure:<\/strong> Calls that pressure individuals to bypass company policies, such as someone pretending to be IT support demanding a password.<\/li>\n<li><strong>Curiosity:<\/strong> Calls that pique curiosity or sound too good to be true, like messages about undelivered packages or unexpected refunds.<\/li>\n<li><strong>Tone:<\/strong> Calls that sound off, with the caller&#8217;s words or tone not matching those of a genuine coworker or friend.<\/li>\n<\/ul>\n<p>Vishing is becoming a favored attack method due to its simplicity and effectiveness. By educating your workforce about vishing and its common indicators, you can significantly reduce the risk of falling victim to such attacks.<\/p>\n<p>&nbsp;<\/p>\n<p>Source:\u00a0<a href=\"https:\/\/www.sans.org\/blog\/a-tale-of-the-three-ishings-part-3-what-is-vishing\/\">https:\/\/www.sans.org\/blog\/a-tale-of-the-three-ishings-part-3-what-is-vishing\/<\/a><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Gi\u1edbi thi\u1ec7u v\u1ec1 DT Asia<\/strong><\/p>\n<p>DT Asia \u0111\u01b0\u1ee3c th\u00e0nh l\u1eadp v\u00e0o n\u0103m 2007 v\u1edbi s\u1ee9 m\u1ec7nh r\u00f5 r\u00e0ng l\u00e0 x\u00e2y d\u1ef1ng b\u01b0\u1edbc th\u00e2m nh\u1eadp th\u1ecb tr\u01b0\u1eddng cho c\u00e1c gi\u1ea3i ph\u00e1p b\u1ea3o m\u1eadt CNTT ti\u00ean phong kh\u00e1c nhau t\u1eeb M\u1ef9, Ch\u00e2u \u00c2u v\u00e0 Israel.<\/p>\n<p>Ng\u00e0y nay, DT Asia l\u00e0 nh\u00e0 ph\u00e2n ph\u1ed1i gi\u00e1 tr\u1ecb gia t\u0103ng khu v\u1ef1c v\u1ec1 c\u00e1c gi\u1ea3i ph\u00e1p an ninh m\u1ea1ng, cung c\u1ea5p c\u00e1c c\u00f4ng ngh\u1ec7 ti\u00ean ti\u1ebfn cho c\u00e1c c\u01a1 quan ch\u00ednh ph\u1ee7 tr\u1ecdng \u0111i\u1ec3m v\u00e0 c\u00e1c kh\u00e1ch h\u00e0ng h\u00e0ng \u0111\u1ea7u thu\u1ed9c khu v\u1ef1c t\u01b0 nh\u00e2n, bao g\u1ed3m c\u00e1c ng\u00e2n h\u00e0ng to\u00e0n c\u1ea7u v\u00e0 c\u00e1c c\u00f4ng ty thu\u1ed9c danh s\u00e1ch Fortune 500. Ch\u00fang t\u00f4i c\u00f3 c\u00e1c v\u0103n ph\u00f2ng v\u00e0 \u0111\u1ed1i t\u00e1c kh\u1eafp khu v\u1ef1c Ch\u00e2u \u00c1 - Th\u00e1i B\u00ecnh D\u01b0\u01a1ng nh\u1eb1m th\u1ea5u hi\u1ec3u r\u00f5 h\u01a1n c\u00e1c th\u1ecb tr\u01b0\u1eddng v\u00e0 cung c\u1ea5p c\u00e1c gi\u1ea3i ph\u00e1p mang t\u00ednh b\u1ea3n \u0111\u1ecba h\u00f3a.<\/p>","protected":false},"excerpt":{"rendered":"<p>Over the past two decades, the security industry has made significant strides in using technology to secure technological assets. However, the human factor in cybersecurity often remains overlooked. Consequently, cyber attackers have shifted their focus from targeting technology to targeting people. Among the various methods they employ, the three most common are phishing, smishing, and vishing. This blog series delves into these methods, the tactics and techniques used by cyber attackers, and how you can protect yourself.<\/p>","protected":false},"author":11,"featured_media":13867,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-13866","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/13866","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=13866"}],"version-history":[{"count":0,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/13866\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/13867"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=13866"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=13866"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=13866"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}