INDUSTRY INSIGHT
Can the phishing epidemic be stopped?
Researchers at Germany’s Friedrich-Alexander University (FAU) recently conducted two spear-phishing studies. Before the experiment was underway, a questionnaire was sent to all participants asking them to “rate their own awareness of security.” Of the 1,700 participants, 78 percent claimed they were aware of the risks of clicking on unknown links.
Astonishingly, despite four-fifths of participants identifying themselves as security conscious, 56 percent clicked on unknown links in email messages, and 37 percent clicked on unknown links sent in Facebook messages. In speaking about these results, Zinaida Benenson, FAU’s chair of computer science and leader of the study, told Ars Technica, “the overall results surprised us.”
The results of this study are daunting for both private and public sector organizations, as the most common remedy for phishing attacks to date has centered on human intelligence, or the belief that extensive employee training can transform ordinary workers into hyper-vigilant phishing detectives.
The facts of the phishing epidemic
Phishing attacks have evolved in sophistication and frequency since they first originated in the 1990s. The first recorded mention of the term ‘phishing’ was found in AOHell, a tool released in 1995 to hack Windows America Online (AOL) users by allowing the attacker to pose as a company representative and steal passwords and credit card information. AOHell influenced many future phishing scams and, over the years, phishers transitioned from amateur to professional cyber criminals.
Phishing attacks have evolved from a matter-of-fact nuisance into an epidemic that can cost up to $4 million per event to remediate. Perpetrated by every type of criminal, from nation-state actors and hacktivists to script-kiddies and fraudsters, phishing now accounts for 95 percent of all successful cyberattacks worldwide. In the first quarter of 2016, phishing attacks surged by 250 percent — the highest since 2004, according to the Anti-Phishing Working Group. In commenting on the surge, the APWG’s co-founder and Secretary General Peter Cassidy said, “The threat space continues to expand despite the best efforts of industry, government and law enforcement.”
More effective than traditional phishing scams are spear-phishing attacks. This type of attack carefully targets employees with emails crafted to appear to be from a colleague. Spear-phishing attacks have played a role in some of the largest cyberattacks to date, including those that hit JPMorgan Chase, Target and Sony. In March 2016, someone posing as Snapchat’s CEO targeted the company’s payroll department requesting employee information and, because the email’s recipient didn’t recognize the scam, 700 employees’ payroll information was exploited. These types of attacks have also exposed millions of W-2 employee data records in large enterprises like Time Warner Cable, healthcare networks and insurance companies.
Why people click
It’s simple: people aren’t perfect. In fact, according to a recent IBM Security Officer Assessment, “95 percent of information security incidents involve human error.”
Overall, there are numerous reasons why both aware and unaware people click on suspicious links. Everyone from a CEO to a janitor can fall victim to a phishing scam by simply not paying attention, multitasking or giving in to curiosity, confusion, fear, gullibility and implausibility. A 24-year-old junior-level employee will find it hard not to click on a link within an email that looks exactly like it’s coming from a superior.
Studies show that this type of context-rich phishing attack containing a deadline and feared consequence (loss of access to an email account, for example) is also positively correlated to the click-rate. According to a 2015 study conducted at the University of Buffalo, “the more urgent the message appears, the more likely people are to fall for it.” Other analysis concludes that phishing attacks targeting social media accounts have a higher success rate.
InfoWorld’s Robert A. Grimes suggests that that professionalization of phishing attacks may also play a role:
“Today’s professional internet criminals work 9-to-5 days, pay taxes, and get weekends and holidays off. The companies they work for often have dozens to hundreds of employees, pay bribes to local law enforcement and politicians, and are often seen as the employer of choice in their region. Working for companies that break into companies in other countries is often proudly worn as a patriotic badge.”
