Be Vigilant: Phishing Attacks Are Getting Trickier
The Cybersecurity and Infrastructure Security Agency has reported that 90 percent of cyberattacks start with phishing. Targeted phishing, called spearphishing, is becoming more common; today’s cyber attackers research their intended victims to create a more customized attack.
The SANS Institute warns: “Phishing attacks have traditionally been emails sent by cyber attackers to trick you into doing something you should not do, such as opening an infected email attachment, clicking on a malicious link, or sharing your password. While traditional phishing attacks continue today, many cyber attackers are creating advanced phishing emails that are more customized and harder to detect. They are also using technologies such as text messaging, social media, or even telephone calls to engage and fool you.”
To defend against phishing, think before you click. Verify attachments and requests for money, login credentials, account numbers, and confidential information through a communications channel different from the one in which the request is made. For example, if the request is in an email, verify it with a phone call using a known phone number. Use security basics like strong passwords, multifactor authentication, keeping operating systems/ software up to date, and using strong passwords.
Click here for more from the SANS Newsletter.
Click here for more from CISA.
This tip courtesy of the ACBA Legal Technology and e-Discovery Committee, and the July 6 SANS Institute “OUCH!” newsletter.