{"id":141872,"date":"2021-10-22T08:51:56","date_gmt":"2021-10-22T08:51:56","guid":{"rendered":"https:\/\/www.regenesys.net\/reginsights\/?p=141872"},"modified":"2022-09-17T20:01:07","modified_gmt":"2022-09-17T14:31:07","slug":"phishing-attack-implications-for-the-organisation-you-work-for","status":"publish","type":"post","link":"https:\/\/www.regenesys.net\/reginsights\/phishing-attack-implications-for-the-organisation-you-work-for","title":{"rendered":"Tips to Fight Phishing Attacks"},"content":{"rendered":"

“Me? Fall for a phishing scam? Never!\u201d<\/p>\r\n\r\n

You may believe you\u2019re somewhat cybersmart \u2013 enough not to fall for a phishing scam… That is until you get hooked and fooled in a fateful oversight. It happens to the best of people; just pray that you don\u2019t become prey to phishing attacks also.<\/p>\r\n

Statistically, it’s safe to say many South Africans are unsecure and may not be well-versed about cyber threats such as phishing. As many as 1,031, 006 people fell victim to phishing attacks<\/a> in only the first half of this year. Yes \u2013 a whopping million people and more, in under a year!<\/p>\r\n\r\n

Over the past year, email security provider Mimecast saw a rise in email threats by 64%. The reality is your inbox may be the next target for phishers whose modus operandi is email scams. \u00a0<\/p>\r\n

The whole world uses email regularly, to share information formally, and to sign up for online services, from online banking to subscription-based services. In a day, 78 billion emails are exchanged, the majority of which are spam, according to Mimecast.<\/p>\r\n\r\n

\"Phishing\"<\/a>What is phishing and how does it work?<\/strong><\/h2>\r\n\r\n

Whether for personal use or organisational use in the workplace, emails are a key source to highly sensitive data, and that\u2019s why hackers continue to make multi-million dollars through phishing attacks. But what is phishing exactly?<\/p>\r\n

It\u2019s when a hacker simulates the image of a company that you\u2019re likely familiar with and trust, and baits you with a carefully crafted, authentic-seeming message which gives a directive on an action to perform with urgency. The end goal is to collect sensitive data such as bank account credentials \u2013 you can figure out the rest.<\/p>\r\n\r\n

A phishing attack doesn\u2019t just have a bearing on you as an individual, leaving you compromised personally \u2013 it could have a very detrimental impact on the organisation you work for \u2013 and you don\u2019t want that on your head.<\/p>\r\n

This kind of cyberattack is the leading cause of data breaches, accounting for 90% of them. Imagine a data breach that could cost a company somewhere in the millions, all resulting from your rookie error\u2026<\/p>\r\n\r\n

One thing is for sure, hackers are hungrier than ever, constantly fishing for user credentials and devising phishing attacks to take advantage of unsuspecting, probably inexperienced people.<\/p>\r\n

As an employee, you could solely be that weak point in an organisation\u2019s cybersecurity efforts. 86% of organisations have had at least one user try to connect to a phishing site. One phishing email landing in your inbox and next thing, you\u2019ve put the entire business at risk!<\/p>\r\n\r\n

How phishing can affect your organisation<\/strong><\/h2>\r\n\r\n

The State of Email Security Report 2021<\/a> by Mimecast, suggests that email remains the most popular way to try to sidestep a business\u2019 defences. Hackers hence use phishing to achieve their goal to obtain sensitive data.<\/p>\r\n

A simple oversight and you could compromise your organisation big time. With phishing emails not so obvious at first glance sometimes, even people who should know better end up falling for the scam.<\/p>\r\n\r\n

Recall the infamous case of former White House Chief of Staff and Hillary Clinton\u2019s presidential campaign chair, John Podesta in 2016. For someone of such a high profile, and in a high office, one would think a phishing attack couldn\u2019t happen to them. Podesta fell for a phishing scam which resulted in a data breach involving tens of thousands of emails being exposed, including those about the presidential campaign.<\/p>\r\n\r\n

Good ol\u2019 Podesta had received a very well-designed email from \u2018Google\u2019 which claimed that someone had attempted to log into his account and had his password. Naturally, the first thing you want to do is secure your email immediately in that instance.<\/p>\r\n

Podesta clicked on the link to change his password, which was a wrong move! But to be fair, he had first sought the advice of IT staff who were also duped by the email, so he went ahead and reset the password, only to get hacked. Podesta took the bait unfortunately and was caught.<\/p>\r\n\r\n

Why \u2018phishing\u2019 anyway?<\/strong><\/h2>\r\n\r\n

And why is it called ‘phishing’? Well, it\u2019s analogous to angling, so it draws from the idea of a fishing line with a baited hook being thrown into a sea of oblivious internet surfers, anticipating that a victim will bite. The bait being a message of trickery.<\/p>\r\n\r\n

There are two elements to a phishing email; a link or an attachment. The link redirects you to a fake webpage asking for personal information being sought such as your passwords (which is what happened to Podesta). Alternatively, downloading the attachment may spread malware on your computer.<\/p>\r\n\r\n

While email has been the predominantly used method, phishing has evolved to include other communication methods such as telephone or text messages. But emails remain the primary method for phishers.<\/p>\r\n\r\n

Tips to fight phishing attacks<\/strong><\/h2>\r\n\r\n

You mustn\u2019t take the bait to avoid a catastrophe resulting from a phishing attack.<\/p>\r\n\r\n\r\n\r\n