Election-Themed Phishing Threats Are on the Rise
Researchers at ReliaQuest have published a report looking at cyber threats surrounding the upcoming US presidential election, warning that election-related phishing will continue to increase over the next month.
People working in the political sphere need to be wary of state-sponsored spear phishing attempts. The Trump and Harris campaigns have both already been targeted by nation-state phishing attacks, with an Iranian threat actor succeeding in stealing information from the Trump campaign.
“APTs often use phishing and spear phishing to gain unauthorized access to sensitive communications,” ReliaQuest says.
“To protect against these tactics, organizations are advised to deploy advanced email security solutions that use machine learning to detect and block phishing attempts. For enhanced protection, the security solution should also conduct threat simulations and red team exercises to identify and mitigate weaknesses. Security teams should provide contextual awareness training that incorporates real-world scenarios and recent case studies.”
Cybercriminals are also exploiting interest in the election, attempting to trick users into handing over their credentials, installing malware, or sending money.
“As the election draws near, businesses and individuals will likely see a significant increase in election-themed phishing emails,” the researchers write.
“We anticipate cybercriminals will craft emails pretending to be from legitimate political campaigns, election authorities, or news outlets. These emails typically contain urgent calls to action like donation requests or critical voting procedure updates to deceive recipients into clicking malicious links or downloading harmful attachments. We have seen election-related customer incidents involving both traditional, external phishing with malicious links and using internal spear phishing to exploit trusted relationships within organizations.”
The researchers add, “Advancements in AI will likely enable cybercriminals to create more personalized and convincing phishing emails by analyzing user behavior, preferences, and social media activity. Advanced AI algorithms can generate realistic and contextually relevant content, mimicking the writing style and tone of legitimate sources such as electoral bodies or campaigns, making it harder for recipients to detect fraud.”
KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.
ReliaQuest has the story.
Free Phishing Security Test
Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.
Here’s how it works:
- Immediately start your test for up to 100 users (no need to talk to anyone)
- Select from 20+ languages and customize the phishing test template based on your environment
- Choose the landing page your users see after they click
- Show users which red flags they missed, or a 404 page
- Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
- See how your organization compares to others in your industry
PS: Don’t like to click on redirected buttons? Cut & Paste this link in your browser: https://info.knowbe4.com/phishing-security-test-partner?partnerid=001a000001lWEoJAAW