Call 310-473-4422

Alarming Phishing Attack Trends to Beware of in 2022

Grant Ackerman • May 13, 2022

Alarming Phishing Attack Trends to Beware of in 2022

Phishing remains one of the biggest dangers to your business's health and wellbeing. In 2020, 75% of companies around the world experienced a phishing attack, and mobile phishing threats skyrocketed by 161%.  In the era of web3.0 trojan's and viruses downloaded directly from the internet is far less common. Phishing emails are now the preferred method for hackers and scammers.


Just one phishing email can be responsible for a company succumbing to ransomware and having to face costly downtime. It can also lead to a user to unknowingly hand over their credentials to a company email account that the hacker can then use to send targeted attacks to customers or other vendors.


Phishing takes advantage of human error. They use sophisticated tactics to fool the recipient into divulging information or infecting their network with malware.


Your best safeguards against the continuous onslaught of phishing include:

  • Email filtering services such as IRONSCALES
  • DNS filtering
  • Next-gen antivirus/anti-malware
  • Ongoing employee cybersecurity awareness training and phishing attack simulations also available through IRONSCALES


To properly train your employees and ensure your IT security is being upgraded to meet the newest threats you need to know what new phishing dangers are headed your way and what can be done to avoid these attacks.


PHISHING IS INCREASINGLY BEING SENT VIA TEXT MESSAGE

People seem to be less suspicious of text messages than they are of unexpected email messages. Most phishing training is usually focused on phishing emails because it’s always been the most prevalent channel of attack.


However, cybercrime entities are now taking advantage of the easy availability of mobile phone numbers and using text messaging to deploy phishing attacks. This type of phishing, called “smishing” (SMS+phishing), has been growing in volume.


People are receiving more text messages now than they did in the past, due in large part to retailers and services pushing text updates to your phone what seems like every 5 minutes. This makes it even easier for phishing via SMS to fake being a shipment notice and get a user to click on a shortened URL.


BUSINESS EMAIL COMPROMISE IS ON THE RISE

Ransomware has been a growing threat over the last few years largely because it’s been a big money-maker for the criminal groups that launch cyberattacks. A new up-and-coming form of attack is beginning to be quite lucrative and is thus growing rapidly.


Business email compromise (BEC) is on the rise and being exploited by attackers to make money off things like gift card scams and fake wire transfer requests.


What makes BEC so dangerous (and lucrative) is that when a criminal gains access to a business email account, they can send very convincing phishing messages to employees, customers, and vendors of that company. The recipients will immediately trust the familiar email address, making these emails potent weapons for cybercriminals.


MAJOR TECH YOUTUBER LINUS SEBASTIAN GETS SCAMMED BY A BUSINESS EMAIL COMPROMISE ATTACK:

SMALL BUSINESSES ARE BEING TARGETED MORE FREQUENTLY WITH SPEAR PHISHING

There is no such thing as being too small to be attacked by a hacker. Small businesses are targeted frequently in cyberattacks because they tend to have less IT security than larger companies.


43% of all data breaches target small and mid-sized companies, and 40% of small businesses that become victims of an attack experience at least eight hours of downtime as a result.


Spear phishing is a more dangerous form of phishing because it’s targeted and not generic. It’s the type deployed in an attack using BEC.


It used to be that spear-phishing was used for larger companies because it takes more time to set up a targeted and tailored attack. However, as large criminal groups and state-sponsored hackers make their attacks more efficient, they’re able to more easily target anyone.


As a result small businesses are receiving more tailored phishing attacks that are harder for their users to identify as a scam.


THE USE OF INITIAL ACCESS BROKERS TO MAKE ATTACKS MORE EFFECTIVE

We just discussed the fact that large criminal groups are continually optimizing their attacks to make them more effective. They treat cyberattacks like a business and work to make them more profitable all the time.


One way they are doing this is by using outside specialists called Initial Access Brokers. This is a specific type of hacker that only focuses on getting the initial breach into a network or company account. The increasing use of these experts in their field makes phishing attacks even more dangerous and difficult for users to detect.


BUSINESS IMPERSONATION IS BEING USED MORE OFTEN

As users have gotten savvier about being careful of emails from unknown senders, phishing attackers have increasingly used business impersonation. This is where a phishing email will come in looking like a legitimate email from a company that the user may know or even do business with.


Amazon is a common target of business impersonation, but it also happens with smaller companies as well. For example, there have been instances where website hosting companies have had client lists breached and those companies sent emails impersonating the hosting company and asking the users to log in to an account to fix an urgent problem.


More business impersonation being used in phishing attacks mean users have to be suspicious of all emails, not just those from unknown senders.


IS YOUR COMPANY ADEQUATELY PROTECTED FROM PHISHING ATTACKS?

It’s important to use a multi-layered strategy when it comes to defending against one of the biggest dangers to your business's wellbeing.


Give us a call at 626-405-8987 or fill out the form below to get started with a cybersecurity audit to review your current security posture and identify ways to improve.

Contact Us

By Eduardo Velandia 19 Mar, 2024
STOP
28 Dec, 2023
Your Shield Against Insider Attacks
06 Dec, 2023
Password Managers
By Varant Tchalikian 30 Oct, 2023
Cyber Insurance
By Eduardo Velandia 28 Jun, 2023
In today's day in age, the use of AI-generated platforms has become increasingly popular across the internet. These platforms allow for a fast and facilitated way to complete tasks such as professional work, education, or expanding one's personal knowledge. Anyone has the ability to discover new or pre-existing information regarding a multitude of topics by simply imputing their inquiries on platforms such as Chat GPT. Chat GPT has had a striking impact on society because of how easy it is for people to gather information on any topic. The platform provides information on anything asked through its online chat and it does so with a fast response. However, Chat GPT and AI-generated platforms can have potential risks such as... Data Breaches Data breaches can happen when using any type of online platform, especially those generated by AI. Chat GPT must be accessed through a web browser since it cannot be downloaded. Because of that, data breaches can occur if an unauthorized party gets a hold of your online chat logs, personal information, or any other sensitive data. A few consequences are: Privacy compromises : If an unknown person or group gains access to your personal information through the platform, your privacy has been compromised and you identity could be exposed. Identity theft : Cybercriminals could use your personal information to act under your name rather than their own. They would steal your identity by using it against you in order to perform fraudulent actions. Misuse of data : User data could be subject to misuse when a data breach occurs on an AI platform. With that, your information could be used without your consent for suspicious activity online. Open AI appears to be taking accurate cyber security measures in order to make it less likely for data breaches to take place. However, not all systems are free from errors or breaches in security, and Chat GPT is a good example of this. Access to Confidential Information Chat GPT has the ability to use personal information entered into the online chat by its users. In order to ensure the user's safety and continual privacy while using the platform, it's best to not exploit one's own information when using the AI chat. Gaining access to user information isn't easy for an AI-generated platform to achieve, but if the user provides the data themselves, it can have some consequences. Biased or Inconsistent Information An additional risk in using Chat GPT is that it could potentially provide biased or inconsistent information to its users Because of the wide range of information the platform contains, it could possibly generate false data that could be confused for something else. This can definitely affect industries or companies that use AI-generated content for their line of work These businesses could provide faulty service to their customers all due to the misleading data given by an AI platform. This has the potential to hinder the company’s advances and overall performance as a result. In the end, it's up to the user and the user alone how they interpret the information given by the AI chat bots; it could be completely right or completely false. Question: Is it safe to use? In certain aspects, Chat GPT contains multiple potential threats to one’s online experience. A platform such as this one can provide misinformation and exploit your personal information. However, it can still be used without problems if certain measures are taken accordingly. Safety Measures You Can Take: Browse on and interacting with AI platforms through anonymous accounts Keep personal or sensitive information private Review the platform’s privacy policy and be well-informed about its activity To conclude, yes, Chat GPT is safe to use as long as it is used responsibly and accordingly to reap the benefits. These types of platforms will continue to be prevalent in the world for years to come and it’s important to know how to ensure we have the best experience with AI. Where can I learn more about the effects of AI for my business? At EV-Consultech, we can answer any questions or concerns you may have regarding the influence of AI. Learn more by contacting us below.
AI Chatbots
By Briana Alvarado 12 May, 2023
Why Using A.I. Chatbots Will Impact The Way You Conduct Business
By Andrea Velandia 04 Jan, 2023
Pandemic Impact
checklist
By Grant Ackerman 29 Nov, 2022
When an employee decides to leave a company, there is an offboarding process that needs to happen. This process “decouples” the employee from the company’s technological assets and is vital to cybersecurity.
By Grant Ackerman 13 Oct, 2022
The pandemic has been a reality check that companies all around have shared. It required major changes in how they operate. No longer, did the status quo of having everyone work in the office make sense for everyone. Many organizations had to quickly evolve to working through remote means.
6 Discontinued Technologies That Could Be Putting You At Risk
By Grant Ackerman 02 Sep, 2022
The one constant about technology is that it changes rapidly. Tools that were once industry standard, like Internet Explorer and Adobe Flash, age out, replaced by faster and more secure alternatives.
More Posts
Share by: