Spear Phishing

All it takes is one click to compromise our network. Spear phishing is a leading cause of data breaches. As the number of cyber attacks and data breaches continues to increase, it is important to be aware of the latest spear phishing threats.
What is Spear Phishing?
Spear phishing messages are targeted at small groups or individuals. Attackers personalize these messages to bypass technical controls like spam filters.
Spear phishing emails:
- Deliver file attachments that can infect your computer with malware
- Entice you to click links that take you to websites that will infect your computer
- Solicit login credentials and other sensitive information so that the attackers can gain access to our network
Spear phishing attacks are dangerous because they are often highly personalized. Attackers conduct extensive research and tailor the emails to appeal to their targets. For example, attackers frequently use information from your social media profile to make their messages more believable. Additionally, phishing emails play on emotions like fear, curiosity, recognition, opportunity, and a sense of urgency.
Quick Tips
- Think twice. Read emails thoroughly and be wary of words like “Caution”, “Act Now”, and “Warning”, which convey urgency and compel you to act quickly.
- Look at the domain name. Some attackers modify domains to catch targets off guard. For example, if the correct domain was www.example.com, the phishers may register “examp1e.com” or “example.co”.
- Keep your emotions in check. Whether it’s a surprising headline or a notification saying your account is compromised, phishers frequently use emotions like fear or curiosity to trick recipients.
- Always verify. Confirm that the email is from the real sender with a quick phone call. Report any suspicious emails.