{"id":28644,"date":"2017-05-10T12:24:02","date_gmt":"2017-05-10T04:24:02","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=28644"},"modified":"2017-05-10T12:38:45","modified_gmt":"2017-05-10T04:38:45","slug":"phishing-scams-exploit-human-behavior-says-sophos-exec","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2017\/05\/10\/phishing-scams-exploit-human-behavior-says-sophos-exec\/","title":{"rendered":"Phishing scams continue to exploit human behavior, says Sophos exec"},"content":{"rendered":"<div id=\"attachment_28645\" style=\"width: 310px\" class=\"wp-caption alignleft\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/05\/Sumit-Bansal-Sophos-copy.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-28645\" class=\"size-medium wp-image-28645\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/05\/Sumit-Bansal-Sophos-copy-300x279.jpg\" alt=\"\" width=\"300\" height=\"279\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/05\/Sumit-Bansal-Sophos-copy-300x279.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/05\/Sumit-Bansal-Sophos-copy-768x715.jpg 768w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/05\/Sumit-Bansal-Sophos-copy.jpg 917w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><p id=\"caption-attachment-28645\" class=\"wp-caption-text\"><strong>S<em>umit Bansal, Director for ASEAN &amp; Korea, Sophos<\/em><\/strong><\/p><\/div>\n<p><strong>Phishing remains one of the most common attack vectors for hackers who exploit end-user behavior as the weakest link in a company\u2019s cyber-defenses. Traditional online security training programs are academic, blind to the current attack landscape and disconnected from the rest of IT security management, making it burdensome for IT managers to effectively integrate anti-phishing into routine risk assessments.\u00a0<\/strong><\/p>\n<p>To address this concern, Sophos launched\u00a0in February <a href=\"http:\/\/www.sophos.com\/\">Sophos Phish Threat<\/a>,\u00a0an advanced phishing attack simulator and training solution that is fully integrated with the company\u2019s cloud-based security management platform, Sophos Central. With centralized management and automated campaign analysis, Phish Threat reduces the time and resources required to affect real change in employee behavior when faced with sophisticated and rapidly evolving cybercrime techniques, according to the company.<\/p>\n<p>Sophos Phish Threat automates the entire training process and provides visual analytics to identify vulnerable users. The Sophos Phish Threat attack simulator and training platform is managed alongside other Sophos security solutions within Sophos Central to provide rapid risk detection and incident response.<\/p>\n<p>\u201cOver the years we\u2019ve seen phishing scams imitating every retailer and organization imaginable, from iTunes to Bitcoin. The phishing campaigns keep growing as it is difficult to spot fake sites and emails,\u201d said Sumit Bansal, Director for ASEAN &amp; Korea, Sophos,\u00a0in an email interview with <em><a href=\"http:\/\/UpgradeMag.com\">UpgradeMag.com<\/a>.<\/em><\/p>\n<p>Bansal said that phishing has evolved in lockstep with the \u2018Malware-as-a-Service\u2019 phenomenon. \u201cToday, we see phishing emails as a primary delivery method for ransomware payloads, which effectively latch on to organizations\u2019 files to encrypt them, holding them ransom.\u201d<\/p>\n<p>In the interview, Bansal also talked about the how users and IT security departments can keep phishing scams from spreading, and how the Philippines is doing in the fight against phishing.<\/p>\n<p><b>1.\u00a0 Despite all the education being given by security vendors and companies, why are phishing scams still a problem today?<\/b><\/p>\n<p>Globally, phishing still remains one of the most common attack vectors for hackers who exploit end-user behavior as the weakest link in a company\u2019s cyber-defenses.\u00a0 Phishing scams are also on the rise as the use of targeted phishing and &#8220;whaling&#8221; is growing. These attacks use detailed information about company executives to trick employees into paying fraudsters or compromising accounts. Phishing attackers are also increasingly targeting critical financial infrastructure, such as the attack involving SWIFT-connected institutions, which cost the Bangladesh Central Bank $81 million.<\/p>\n<p><b>2. How has phishing evolved over the last 5 to 10 years? What are the biggest differences between today\u2019s scams and the scams several years ago?<\/b><\/p>\n<p>Traditionally, users receive a \u201cspoofed\u201d email that appears to come from a legitimate website they frequently have online dealings with, like their bank, credit card company, or ISP, or in some cases even their employer. The phishing email informs the user their account is somehow at risk, and that they may need a security update, or to reset their password. The phishing email may also direct the user to a spoofed website or pop-up window which looks exactly like the real site, but has been set up for the sole purpose of stealing personal information. Unaware that the site isn\u2019t real, unsuspecting users are fooled into handing over credit card numbers, passwords, or other details.<\/p>\n<p>Over the years we\u2019ve seen phishing scams imitating every retailer and organization imaginable, from iTunes to Bitcoin. The phishing campaigns keep growing as it is difficult to spot fake sites and emails.<\/p>\n<p>Phishing has evolved in lockstep with the \u2018Malware-as-a-Service\u2019 phenomenon. Today, we see phishing emails as a primary delivery method for ransomware payloads, which effectively latch on to organizations\u2019 files to encrypt them, holding them ransom.<\/p>\n<p><b>3. Can you give a list of common things\u00a0(at least 5) to watch out for in phishing schemes?<\/b><\/p>\n<ol>\n<li>The message contains bogus links or mismatched URLs<\/li>\n<li>Poor spelling and grammar<\/li>\n<li>The message has uncommon requests<\/li>\n<li>Terrible formatting<\/li>\n<li>The sender is unknown and suspicious<\/li>\n<\/ol>\n<p><b>4. What is the biggest red flag for users and IT security departments?<\/b><\/p>\n<p>The biggest red flag is when you receive an email unexpectedly that is requesting information, money, or other actions in an unusually short period of time. It is recommended to analyze the email. By rushing or intimidating the user, email hackers are hoping that users won\u2019t take time to scrutinize the email for flaws. Hence, it is important not to fall into this trap. Be alert, aware and thorough as you look for Phishing emails.<\/p>\n<p><b>5. How is the Philippines doing in the fight against phishing? Are we lagging behind other countries?<\/b><\/p>\n<p>The National Bureau of Investigation (NBI) has warned the public of the existence of \u201cphishing\u201d syndicates that are victimiZing clients of banks and financial companies. In this vein, they are also working on tighter filtering systems for banks\u2019 internet transactions.<\/p>\n<p><b>6. How much, on average, does a business lose to phishing scams?<\/b><\/p>\n<p>It ranges according to the extent of the attack, but enterprises can lose up to millions in phishing attacks.<\/p>\n<p><b>7. How can users and IT security departments keep phishing scams from spreading?<\/b><\/p>\n<p>User education is definitely a key area to focus on, to empower employees to combat phishing. For the first time, with an aim to help organizations and staff understand phishing attacks, the Sophos Phish Threat Attack Simulator enables IT managers to create authentic phishing simulation and training sessions, and initiate course corrections for their employees. This approach exposes end users to automated attack simulations, quality security awareness training, and actionable reporting metrics; thus facilitating a positive security awareness culture.<\/p>\n<p><b>8. What are the key enabling technologies behind the Sophos Phish Threat offering?<\/b><\/p>\n<p>Sophos Phish Threat Attack Simulator provides rapid risk detection and incident response. It\u00a0 replicates the mindset of a real attacker, using the complicated methods and techniques in use today. This means assessments are modeled after potential attacks that organizations may face from real hackers.<\/p>\n<p>With Sophos Phish Threat, IT managers now have sophisticated, integrated threat intelligence that combines the strength of Sophos security technologies with a product that tests, trains and analyses human vulnerabilities. This creates a very powerful solution for businesses struggling to keep ahead of organized cybercrime and unwary end-users.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Phishing remains one of the most common attack vectors for hackers who exploit end-user behavior as the weakest link in a company\u2019s cyber-defenses. Traditional online security training programs are academic, blind to the current attack landscape and disconnected from the rest of IT security management, making it burdensome for IT managers to effectively integrate anti-phishing [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":28645,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,25],"tags":[286,657,1591,206],"class_list":["post-28644","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-software","tag-it-security","tag-phishing","tag-ransomware","tag-sophos"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/28644","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=28644"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/28644\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/28645"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=28644"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=28644"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=28644"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}