The use of impersonating a person or brand as part of an attack in on the rise, giving attackers the upper hand, establishing instant credibility and lowering the defenses of the potential victim.
The first goal of any phishing attack is to establish context around who is sending the email. And according to email security vendor Agari, the bad guys are laser-focused on using both brand and personal identity deception to accomplish this. According to their recent Q4 2019: Email Fraud & Identity Deception Trends report, attacks impersonating individuals nearly doubled in Q3, rising from 12% of all impersonation attacks to 22%.
Of all advanced email attacks in Q3 of this year, nearly two-thirds of them (62%) used some form of identity deception. Brands continue to dominate – representing 42% of all impersonation attacks – where something as simple as a display name of “UPS Shipping Notification” may be all that’s needed. Look-alike domains (think chaase.com) also remain an issue, also representing 22% of attacks.
With the goal being to trick users into diverting payroll, initiating a fraudulent bank transfer, or obtaining gift cards, the use of identity deception – particularly in the case of impersonating an individual – is rather compelling. An email to payroll about modifying banking details from what appears to be an employee’s external email address is somewhat believable.
Organisations need to elevate their user’s understanding of how these tactics are used and the scams that exist via Security Awareness Training. By educating them, users can spot potential phishing scams that may be designed to trick users through the use of identity deception.
Will your users respond to phishing emails?
KnowBe4’s new Phishing Reply Test (PRT) is a complimentary IT security tool that makes it easy for you to check to see if key users in your organisation will reply to a highly targeted phishing attack without clicking on a link. PRT will give you quick insights into how many users will take the bait so you can take action to train your users and better protect your organisation from these fraudulent attacks!
Here’s how it works:
Immediately start your test with your choice of three phishing email reply scenarios
Spoof a Sender’s name and email address your users know and trust
Phishes for user replies and returns the results to you within minutes
Get a PDF emailed to you within 24 hours with the percentage of users that replied
PS: Don’t like to click on redirected buttons? Cut & Paste this link in your browser: https://info.knowbe4.com/one-on-one-demo-partners?partnerid=001a000001lWEoJAAW