Business bosses are trying to find out which employees could leave an opening for their firm to be hacked – by sending spoof phishing emails to see who bites.
High-profile hacks have put companies on the defensive, as they try to avoid becoming the next Sony Pictures.
Data shows phishing emails are more and more common as entry points for hackers. Unwittingly clicking on a link in a scam email could unleash malware into a network or provide other access to cyberthieves.
So a growing number of companies, including Twitter, are giving their workers a pop quiz, testing security by sending fake phishing emails to see who takes the bait.
“New employees fall for it all the time,” said Josh Aberant, postmaster at Twitter, during a data privacy town hall meeting recently in New York City.
Falling for the fake scam offers a teachable moment that businesses hope will ensure employees will not succumb to a real threat. It is even a niche industry, with companies such as Wombat Security and PhishMe offering the service for a fee.
Phishing is very effective, according to Verizon’s 2014 data breach investigations report, one of the most comprehensive in the industry. Some 18% of users will visit a link in a phishing email that could compromise their data, the report found.
Not only is phishing on the rise, the people behind it are getting smarter. Criminals are “getting clever about social engineering”, said Patrick Peterson, chief executive of email security company Agari.
As more people wise up to age-old PayPal and bank scams, for example, phishing emails are evolving. You might see a gift card offer or a notice claiming to be an Ebola warning.
The phishing tests recognise that many security breaches are the result of human error. A recent study by the non-profit Online Trust Alliance found that of more than 1,000 breaches in the first half of 2014, 90% were preventable and more than one in four were caused by employees, many by accident.
Fake phishing emails are indistinguishable from the real ones. In one sent out by Wombat, the subject reads “Email Account Security Report – Unusual Activity”.
It informs the recipient that his or her account will be locked because of unusual activity such as sending a large number of undeliverable messages. At the bottom there’s a link that, were it a real phishing email, would infect the recipient’s computer with malicious software or steal password and login information.
If you click, u p pops a web page: “Oops! The email you just responded to was a fake phishing email. Don’t worry! It was sent to you to help you learn how to avoid real attacks. Please do not share your experience with colleagues, so they can learn too.” It also offers tips on recognising suspicious messages.
In the 14 years since PhishMe CEO and co-founder Rohyt Belani has been in the information security field, he says it has changed from something a “geek in the back room” was supposed to take care of to something companies now handle at the highest level of management.
The nature of the intruder has also changed, he said, from pranksters to criminal organisations and nation-states.
As the security industry developed, he said, so did the idea of the user as “stupid” and the “weakest link”, destined to continue to fall for phishing attempts and other scams. Mr Belani disagrees with that, faulting the security industry for not training workers better.
“We posted posters in hallways, gave out squishy balls, (made) screen savers,” he said. “When was the last time you changed your password because of a squishy ball?”
While phishing training emails are a “good cautionary measure”, they are not “actually going to strike at the core of the issue”, said Mr Peterson.
He, along with large internet companies such as Facebook, Google and Microsoft support establishing a standard that makes it impossible for scammers to impersonate your bank, social network or other business in an email.
Think of it as a verification system for emails. For now, though, this seems a long way off.
So, at firms such as Pinnacle Financial Partners in Nashville, Tennessee, employees will continue to receive fake phishing emails.
The results are reported to the company’s audit committee and board of directors, said chief information officer Randy Withrow.
Since the 800-employee company started the Wombat program Mr Withrow said it has seen a 25% drop in successful phishing attempts.
Workers “take it very personally” when they fall for it, he said. “They become apologetic and wonder ‘how did I miss it’?”
