Vane3alga

Business
Focused
Technology

Employees need to continue being wary of phishing scams as they begin to return to the office, according to Roger Kay at INKY. Kay describes several phishing templates that INKY has intercepted in recent months, including one that informed recipients that they needed to fill out a compliance form related to COVID-19 risks.

iStock 1216581880

“Reasonably well written, this email, apparently from the human resources department at the target company, actually came from phishers located in the United Kingdom,” Kay writes. “There are elements that might strike the recipient as strange. For example, the phrase ‘recuperating favorably’ is a bit off. Noncompliance is spelled ‘non-compliance.’ And ‘these guide and policies’ has an agreement-of-number problem. But otherwise, it’s a pretty good fake, including the legitimate SharePoint link embedded in the email. The problem with the link was that it led to a real but hijacked SharePoint site that was turned into a credential harvesting operation.”

Another phishing email purported to be sent from a company’s HR department asking all employees to take a survey regarding their interest in receiving a COVID-19 vaccine. The email contained a link to “survymonky/r/HPG23P”(spoofing the entirely legitimate and very familiar surveymonkey.com).

Kay also describes an email that appeared to come from the company’s CEO and abused an open redirect link to fool the target into thinking the link was benign.

“[E]mbedded within it was a link that used Google’s open redirect capability to send those who clicked through to a malware injection site or a credential harvesting operation,” he writes. “The cybercriminal was able to exploit a weakness that some legitimate websites like Google use that allows users to input parameters in a link that redirects to other sites. What the user sees is ‘google.com’ followed by a long URL path. Even if the recipient were to scrutinize the URL, all they’d see was a good-looking Google redirect.”

New-school security awareness training can enable your employees to recognize phishing scams and other forms of social engineering.

INKY has the story.


SOURCE: KnowBe4.com

Success Stories

Principal Owner, Marketing Firm

Bringing IT360 on as our technology services “department” was one of the smartest business decisions we’ve made. Over the years, we’ve tried various similar services and have also hired internal IT staff, and we’ve never felt confident that we were adequately supported. IT360 has changed all that. They not only provide proactive, comprehensive technical support and consulting, they engage with us in a way that feels like they are part of our company…a true business partner.

Principal Owner, Marketing Firm

Recent
Technology News

IT360 News
AI in IT: What You’re Missing Out On

AI in it: What you’re missing out on Artificial Intelligence (AI) is no longer a distant concept—it’s actively transforming the way businesses operate, particularly in IT. If your organization isn’t yet leveraging AI-driven tools, you could be missing out on major opportunities to optimize workflows, detect system vulnerabilities faster, and enhance data-driven decision-making. AI tools […]

Read more
IT360 News
How AI Can help Accountants During Tax Season By Streamlining Processes and Enhancing Efficiency

What season is it? If your Bugs Bunny, it’s “wabbit” season…for the rest of us, well, it’s TAX SEASON! Tax season brings a wave of stress and pressure for accountants as they navigate numerous financial documents, compliance regulations, and client consultations. The advent of Artificial Intelligence (AI) is revolutionizing the accounting profession by offering innovative […]

Read more