Phishing
Social engineering method that uses different communications methods to make you think something is real when it is not
Done to give up info that you wouldn’t normally
Username, password
Can check the links on the message, if a phishing message the website will be wrong
Usually there is something wrong with the site
Spelling, spacing, fonts
Best practice is to never click a link from an email
Business email compromise
Attackers take advantage of email sources we trust
Email address can be spoofed that uses an email from that company or one close to the company
Someone gaining access to an email account that can send emails or look through emails in that account
Sometimes attackers just use the link to make you donwload malware instead of trying to gain sensitve info
Tricks and misdiraction
Attackers use multiple ways of trying to get info
Typosquatting - a technique where attackers register domains similar to legitimate websites, often differing by only a single character
Pretexting - Lying to get info or impersonating someone to gain trust and coax sensitive data from victims.
Vishing - (Voice Phishing) over the phone
Smishing - (SMS Phishing) over text