Yes, you’re right: there’s an element of truth to that last comment. But
before you get too high on your horses, hear me out. I know that phishing
scams aimed at stealing your personal data and passwords have been around
since the mid-1990s. I know that cyber
phishermen attack approximately 3,000 Britons per day. And I know
that you should never enter any personal details when you receive electronic
correspondence from your ‘bank’, a ‘Nigerian businessman’ or a ‘friend
stranded in South America’. But I did not know that you should not attempt
to sign into a Google Drive homepage when you are taken there by an
attachment on an email titled ‘document’ that has been sent to you by your
accountant on a day when you are expecting a secure document from your
accountant.
The ‘document’ scam has been doing the rounds since March and is an example of
a relatively new variant of email deception called ‘spear phishing’.
“Spear phishing is a more targeted version of phishing where an adversary
conducts online reconnaissance on an individual or organisation in order to
construct an email which appears to be of significant interest to those
targeted,” reveals the Centre for
the Protection of National Infrastructure. “The IT security
community has assessed that it is a remarkably effective cyber-attack
technique.”
The secret to spear phishing’s success is its delivery. Instead of the email
being sent by a suspicious source, it comes from someone you’ve contacted
before and have no reason to distrust. Someone like your accountant. Hence
why I merrily typed in my email address and password. Once this happened, I
was taken to a fake page and the cyber attacker was in control. First, he or
she altered one digit on the phone number on the bottom of my email
signature (so people called or texted a premium phone line). Then, he or she
used my address to launch the ‘document’ scam on every single one of my
contacts.
By my reckoning, the cyber attackers speared somewhere between 2,000 and 5,000
people through me. Did any of them fall for the scam? Hopefully not, but I
don’t know for sure. All I know is it took me a day to change my passwords,
send my apologies and mop up the mess. Still, it could have been far worse.
The attackers could have had a party on my credit card or emptied my bank
account.
So do yourself a favour and learn from my mistake. No matter how realistic it
looks or how much you trust the sender, never sign into a link that
emerges from an email attachment.
