
Phishing is a type of online attack which is used to steal personal data, including login credentials, bank details, or credit card information. Its name comes from fishing, because it ‘baits’ its’ victims by masquerading as a trusted source. The victim is tricked into clicking a malicious link, which can then instal malware, freeze hardware (as part of a ransomware attack) or access and distribute personal information. For individuals and businesses this can have huge negative effects.
However, phishing can also take place on a corporate level, in an isolated incident or as part of a larger overall cyber-attack. Here, employees are targeted in order to allow hackers to bypass security systems and gain access to business systems and secure information. Organisations that are the victims of successful phishing attacks typically suffer large financial losses, as well as experiencing decline in reputation and the trust of their clients.
Standard attacks:
These attack a large number of individuals or businesses, with the understanding that such an approach is more variable. Standard phishing attacks rely on statistics: the more emails sent, the more likely it is that a recipient will be taken in by them. However, standard attacks can be relatively easy to spot, and if employees and individuals remain vigilant, they are much more likely to spot the ‘bait’. Equally, within businesses, if a large volume of emails are sent they are likely to be discovered and prevented more quickly.
For example, an attacker sends a mass email to all employees in a business, posing as a member of the IT department. The email is about an update to their systems and includes a link to a website which will detail the steps this update will include. At the website, the employees are encouraged to enter their credentials, which are then sent directly to the hacker.
Spear phishing attacks:
Spear phishing, as the name may suggest, is a more targeted phishing attack. They require a greater amount of care and preparation from the attacker, as it targets fewer individuals using an email carefully manipulated to appear specifically relevant to them. In some cases, it can be common for the attacker to build up trust with their targets in order to more easily persuade them to click on malicious links or download malware on to their systems. A spear phishing attack is more commonly used within internal networks.
For example, an attacker becomes aware of an internal project or information at the target organisation, and then closely spoofs the original sender’s email address. They then send an otherwise innocuous email to a limited recipient list, with information relevant to them. Because of the implicit trust these details provide, it is more likely to persuade the targets to open the attachment or click the link included.
However, the most important factor at any level in preventing phishing attacks is vigilance: if you are aware what phishing emails may look like, and exercise caution when receiving emails in your inbox, then you will almost always be able to prevent an attack. Some phishing emails may contain subtle mistakes in grammar and spelling, or inconsistencies in the email address they come from. On an enterprise level, multi-factor authentication can prevent phishing attacks from being carried out if employees do click on malicious links, and strong password management policies can also prevent issues.
See the National Cyber Security Centre for more information.























