Vane3alga

Business
Focused
Technology

Employees need to continue being wary of phishing scams as they begin to return to the office, according to Roger Kay at INKY. Kay describes several phishing templates that INKY has intercepted in recent months, including one that informed recipients that they needed to fill out a compliance form related to COVID-19 risks.

iStock 1216581880

“Reasonably well written, this email, apparently from the human resources department at the target company, actually came from phishers located in the United Kingdom,” Kay writes. “There are elements that might strike the recipient as strange. For example, the phrase ‘recuperating favorably’ is a bit off. Noncompliance is spelled ‘non-compliance.’ And ‘these guide and policies’ has an agreement-of-number problem. But otherwise, it’s a pretty good fake, including the legitimate SharePoint link embedded in the email. The problem with the link was that it led to a real but hijacked SharePoint site that was turned into a credential harvesting operation.”

Another phishing email purported to be sent from a company’s HR department asking all employees to take a survey regarding their interest in receiving a COVID-19 vaccine. The email contained a link to “survymonky/r/HPG23P”(spoofing the entirely legitimate and very familiar surveymonkey.com).

Kay also describes an email that appeared to come from the company’s CEO and abused an open redirect link to fool the target into thinking the link was benign.

“[E]mbedded within it was a link that used Google’s open redirect capability to send those who clicked through to a malware injection site or a credential harvesting operation,” he writes. “The cybercriminal was able to exploit a weakness that some legitimate websites like Google use that allows users to input parameters in a link that redirects to other sites. What the user sees is ‘google.com’ followed by a long URL path. Even if the recipient were to scrutinize the URL, all they’d see was a good-looking Google redirect.”

New-school security awareness training can enable your employees to recognize phishing scams and other forms of social engineering.

INKY has the story.


SOURCE: KnowBe4.com

Success Stories

President, Transportation Company

Your technical support team has always been able to handle our needs quickly, efficiently, and patiently. We appreciate your timeliness and the hours you have saved us. It is great to know that we have people at IT360 capable to provide solutions to our problems.

President, Transportation Company

Recent
Technology News

IT 360 News - Why Your Next Hardware Purchase Could Be More Expensive — and Harder to Find
Why Your Next Hardware Purchase Could Be More Expensive — and Harder to Find

A recent industry report highlights something we’re beginning to see ripple through the technology market: AI data centers are consuming massive amounts of hardware inventory. In fact, according to this article from Breitbart, Western Digital has already sold out much of its 2026 hard-drive production capacity as AI data centers purchase storage at unprecedented levels. […]

Read more
IT360 News
Why Your Old Phone System Is Holding You Back

It’s Time to Rethink How Your Business Communicates Many businesses are still relying on traditional phone systems that were designed for a very different era—when everyone worked in one building, at one desk, on one device. Today’s workforce looks nothing like that. Teams are remote or hybrid. Employees expect mobility. Companies are growing, changing, and […]

Read more