Don’t open unfamiliar attachments. Don’t click on unsolicited links. Don’t reply to spam. Most security practices are so ingrained, they’re like second nature. Or are they?
According to a study conducted by O+K Research on behalf of security firm Kaspersky Lab ZAO, a whopping 50 percent of users say they are unable to recognize a phishing message or a spoofed Web site – underscoring to the channel that there is still a lot of room for back-to-basics security education and training.
Phishing and its derivative, spear-phishing, are attacks that impersonate a legitimate site or organization to trick users into opening malicious files or handing over login credentials and personally identifying information.
While phishing attacks have been around for some time, there’s still a critical mass of users that will fall prey. Altogether, 26 percent of users say their computers have been infected as a result of opening an attachment to a letter, while 13 percent of respondents admitted to entering personal or financial data on suspicious applications.
These stats are not new nor incredibly surprising. It’s well known that social engineering has long since become the tool du jour for cybercriminals to reach intended victims. Such methods are usually on the front lines in targeted and advanced persistent threat attacks. That said, as more users catch on to these tactics and react accordingly, cybercriminals will continue to make them more challenging to identify.
These days, users are regularly targeted with authentic-looking e-mails that appear to come from someone they know, or with spoofed pages that are practically identical to the actual sites. Not surprisingly, phishing e-mails with malicious attachments appear to be on the rise.
One of the most notorious examples in recent years is the massive APT attack against RSA, the security division of EMC. During the attack, cybercriminals reportedly from China compromised the company’s flagship two-factor authentication SecureID tokens by cracking its seed code. The compromised tokens were then leveraged in serial attacks against RSA’s high profile customers, which included U.S. defense contractors Lockheed Martin, Northrop Grumann and L3 Communications, among others.
While most phishing attacks aren’t quite as high profile in nature, the majority are used to gain unauthorized access to a network and commit data theft, primarily from social network accounts, online banking and payments system and e-commerce sites. In June, 68 percent of phishing messages were related to such services, according to Moscow-based Kaspersky Lab.
Meanwhile, one relatively new development–and one that is expected to grow– is that cybercriminals are increasingly leveraging attacks against mobile devices as mobility and Bring Your Own Device trends gain traction. According to the study, 24 percent of tablet users and 18 percent of smartphone owners said they received communications with suspicious links and attachments, with 14 percent and 11 percent respectively contending that they received letters that claimed to be sourced to a bank or social network.
But what the study suggests are two-fold:
- One, we can’t assume that everyone adheres to security best practices. In fact, even those with extensive security acumen have been known to fall victim to threats by unwittingly clicking on an embedded link, downloading an unsolicited program or entering passwords to a suspicious login site. As as such, there’s still a lot of room for user education. That holds especially true as new technologies, such as cloud collaboration tools and mobility become more ubiquitous in the work environment and thus present a new crop of unexpected security risks and challenges. While its never foolproof, raising awareness via regular best-practices training provided by the channel could go a long way in reducing the number of phishing attack victims.
- And two: no matter how much education users receive, there will always be those that ignore the warnings and click the links. That means there will always be a wide open market for security solutions such as application control, Web filters and DLP, designed to save users from themselves. Disruptive new technology trends will create new vectors for attacks. But partners can likewise find ways to apply new and dedicated security solutions to mobile, virtualization and cloud platforms that will serve to build out their security practices, and give their businesses a few new directions in which to grow.
