Has Hollywood deceived us? Movies like “White House Down” portray their villains as computer geniuses capable of bringing down governments with a few deft keystrokes. But that’s not what happened last week when the so-called Syrian Electronic Army defaced a U.S. Marines recruiting website. The loosely organized group has also claimed responsibility for hijacking the websites of The New York Times, The Washington Post and others.
How did they do it? Not with fancy hacking, but with deceptive emails. The tactic is called spear phishing — using personalized information in an email to lure people into giving up sensitive data like passwords and bank account numbers or to visit a malware-laden website.
In the case of the Syrian hacking group, once they’d obtained legitimate login credentials from unsuspecting employees, they entered websites and posted their own propaganda.
How it works
Spear phishing is one of the most common tools used by cybercriminals because it’s cheap, easy and effective. Security firm TrendMicro found 91 percent of targeted attacks toward companies involve spear-phishing emails to individuals. And chances are, if you haven’t already been a target of a spear phishing campaign, you will be.
Personalization sets spear phishing apart from generic phishing scams. Cybercriminals can easily find your name, email address, the company you work for and your title on the Internet. Such criminals have been known to comb social media sites looking for personal information to use in their schemes. They may spoof the sender address to make it appear as though an email comes from your boss or a friend, which of course, increases the likelihood that you’ll carry out the directions contained in the message.
While you may be asked to click on a link, you’re more likely to encounter an attachment. In fact, 94 percent of spear phishing emails use attachments, such as Word documents, spreadsheets and PDF files, to infect computers, TrendMicro said. Open the attachment and your computer can be infected with a remote access Trojan (RAT) that allows criminals to record your keystrokes — every password, credit card number, etc. — and use them for their own purposes.
Spotting an attack
If the message doesn’t sound like the sender, it may be a fake. For instance, if your normally chatty friend sends a one-line email that reads, “Open this doc now,” you should be suspicious.
If an email contains a link, be on guard. It’s rarely wise to click on a link in an email, which could take you to a malicious site. If the link appears to be reputable, instead of clicking on it, hover over it with your mouse to see the URL in the bottom of your browser’s window. If you don’t recognize it, don’t click it.
If the email calls for immediate action, slow down. Phishers want their victims to respond right away and often use threats such as “your account will be closed unless you respond immediately.” The idea is to prevent you from checking with colleagues or trusted friends.
Don’t trust email
There is no way to really know who sent an email, so don’t take action solely based on an electronic message. The FBI recommends treating every unsolicited or unexpected email containing attachments or links with caution, even (and perhaps especially) when the email appears related to known events, people or projects.
Call the sender or speak in person to verify the message. If it turns out to be a spear phishing scam, report it to your company, or for a personal attack, the appropriate authorities.
Leslie Meredith has been writing about and reviewing personal technology for the past six years. As a mom of four, value, usefulness and online safety take priority. Have a question? Email Leslie at asklesliemeredith@gmail.com.
