Phishing And Its Growing Threat To Your Business | Avast

Phishing And Its Growing Threat To Your Business | Avast
Katherine Little, 24 March 2021

Clever cybercriminals take advantage of busy employees to steal credentials, money, and data



It only takes a matter of minutes for cybercriminals to bait, hook, and catch a phishing victim among your employees and then leverage that success into a broader cyberattack on your business. The story goes like this: Choosing victims: A cybercriminal launches a phishing campaign to either random email recipients (often obtained from a previous data breach) or targeted to a specific company or industry. In this case, an employee of ABC Manufacturing is randomly targeted with a phishing email.
Setting the bait: The employee, Andi, opens the phishing email and sees a convincing message about a document to be downloaded from a well-known file-sharing application. It’s convincing because Andi uses the application to share documents both within the organization and externally with company suppliers. The email includes the application’s branding to make it look legitimate. Furthermore, the sender appears to be her boss, which is a technique called spear phishing, a malicious email that impersonates an individual for the purpose of tricking a recipient into completing a desired action.
Hooking the target: Andi is incredibly busy on this day and clicks on the malicious link so she can deal with this latest interruption to her already overflowing schedule. The link takes her to a fake website where she’s asked to enter her login credentials. She enters them and opens the document, which contains hidden malware.    
Taking malicious actions: The malware downloads to her device and then rapidly spreads across the ABC Manufacturing company’s network, allowing the cybercriminal to steal credentials and sensitive data along the way. At some point ..

Support the originator by clicking the read the rest link below.