Phishing

  • Social engineering method that uses different communications methods to make you think something is real when it is not

  • Done to give up info that you wouldn’t normally

    • Username, password

  • Can check the links on the message, if a phishing message the website will be wrong

  • Usually there is something wrong with the site

    • Spelling, spacing, fonts

  • Best practice is to never click a link from an email


Business email compromise

  • Attackers take advantage of email sources we trust

  • Email address can be spoofed that uses an email from that company or one close to the company

  • Someone gaining access to an email account that can send emails or look through emails in that account

  • Sometimes attackers just use the link to make you donwload malware instead of trying to gain sensitve info


Tricks and misdiraction

  • Attackers use multiple ways of trying to get info

  • Typosquatting - a technique where attackers register domains similar to legitimate websites, often differing by only a single character

  • Pretexting - Lying to get info or impersonating someone to gain trust and coax sensitive data from victims.

  • Vishing - (Voice Phishing) over the phone

  • Smishing - (SMS Phishing) over text