Keystone Insights Blog

Image
Expert advice and strategies for academic success and personal growth.
Image

How to avoid email scams and phishing

Nobody wants to fall prey to a phishing scam, let alone the disruption and issues they can cause to your school or trust. There's a good reason that such scams will continue, though: They are successful enough for cybercriminals to make massive profits. Phishing scams have been around practically since the inception of the Internet, and they will not go away any time soon.

Here are some of the techniques used for phishing that you need to be aware of both whilst in and out of your workplace: 

Types of Scams

Email/Spam

Using the most common phishing technique, the same email is sent to millions of users with a request to fill in personal details. These details will be used by the phishers for their illegal activities. Most of the messages have an urgent note which requires the user to enter credentials to update account information, change details, or verify accounts. Sometimes, they may be asked to fill out a form to access a new service through a link which is provided in the email. 

Spear Phishing

While traditional phishing uses a 'spray and pray' approach, meaning mass emails are sent to as many people as possible, spear phishing is a much more targeted attack in which the hacker knows which specific individual or organisation they are after. They do research on the target in order to make the attack more personalised and increase the likelihood of the target falling into their trap.

Whale Phishing

Whaling is a type of spear phishing attack that focuses on high-level executives (e.g. the C-suite). Whaling differs from normal spear phishing as it tends to be highly researched in order to seem more credible. Hackers can either target the executive themselves or send emails pretending to be them to other members of staff. The hackers may glean information from the executives' LinkedIn profiles and news articles. They may also research industry terms to make their emails seem more credible.

Web-Based Delivery

Web-based delivery is one of the most sophisticated phishing techniques. Also known as "man-in-the-middle," the hacker is located in between the original website and the phishing system. The phisher traces details during a transaction between the legitimate website and the user. As the user continues to pass information, it is gathered by the phishers without the user knowing about it.

Link Manipulation

Link manipulation is the technique in which the phisher sends a link to a malicious website. When the user clicks on the deceptive link, it opens up the phisher's website instead of the website mentioned in the link. Hovering the mouse over the link to view the actual address stops users from falling for link manipulation. 

Keyloggers

Keyloggers refer to the malware used to identify inputs from the keyboard. The information is sent to the hackers who will decipher passwords and other types of information. To prevent key loggers from accessing personal information, secure websites provide options to use mouse clicks to make entries through the virtual keyboard. 

Trojan Horse

A Trojan horse is a type of malware designed to mislead the user with an action that looks legitimate, but actually allows unauthorized access to the user account to collect credentials through the local machine. The acquired information is then transmitted to cybercriminals. 

Malvertising

Malvertising is malicious advertising that contains active scripts designed to download malware or force unwanted content onto your computer. Exploits in Adobe PDF and Flash are the most common methods used in malvertisements. 

Session Hijacking

In session hijacking, the phisher exploits the web session control mechanism to steal information from the user. In a simple session hacking procedure known as session sniffing, the phisher can use a sniffer to intercept relevant information so that he or she can access the Web server illegally. 

Content Injection

Content injection is the technique where the phisher changes a part of the content on the page of a reliable website. This is done to mislead the user to go to a page outside the legitimate website, where the user is then asked to enter personal information. 

Phishing Through Search Engines

Some phishing scams involve search engines where the user is directed to product sites which may offer low-cost products or services. When the user tries to buy the product by entering the credit card details, it's collected by the phishing site. There are many fake bank websites offering credit cards or loans to users at a low rate, but they are actually phishing sites. 

Vishing (Voice Phishing)

In phone phishing, the phisher makes phone calls to the user and asks the user to dial a number. The purpose is to get personal information about the bank account over the phone. Phone phishing is mostly done with a fake caller ID.

Smishing (SMS Phishing)

Phishing is conducted via Short Message Service (SMS), a telephone-based text messaging service. A smishing text, for example, attempts to entice a victim into revealing personal information via a link that leads to a phishing website. Many people have experienced these around tax return time, claiming to be from the Inland Revenue. 

Malware

Phishing scams involving malware require it to be run on the user's computer. The malware is usually attached to the email sent to the user by the phishers. Once you click on the link, the malware will start functioning. Sometimes, the malware may also be attached to downloadable files. 

Ransomware

Ransomware denies access to a device or files until a ransom has been paid. Ransomware for PC's is malware that gets installed on a user's workstation using a social engineering attack where the user gets tricked into clicking on a link, opening an attachment, or clicking on malvertising. 

How to stay safe

Fortunately, there are ways to avoid becoming a victim yourself or your school.

Here are 10 basic guidelines for keeping yourself, and your school, safe: 

You don't have to live in fear of phishing scams. By keeping the preceding tips in mind, you should be able to enjoy a worry-free online experienceIf you need any help or support with your ICT support or data protection, contact us, and we can talk through how we can help.

Should you engage a school consultant?
Behind the Education Headlines in August