Pages

Protect Yourself From Spear-Phishing Scams

Humans are still our biggest cybersecurity weakness. Here's how to be smarter when it comes to avoiding scams through email and on your phone.

When dozens of celebrity Twitter accounts started promoting a Bitcoin scam one Friday in July, something was clearly going wrong down at Twitter HQ. By the end of the month, Twitter said certain employees had fallen for a scam and unwittingly helped hackers gain access to sensitive login credentials. 

The hacker, allegedly a teenager in Florida who's now charged with 30 felonies, tapped the usernames and passwords to access an internal system at Twitter and take control of high-profile accounts. The breached accounts included those of Elon Musk, Bill Gates and Joe Biden.

In your work or personal life, chances are you have access to a system or account that hackers would like to breach. The prize could be customer data that would help identity thieves do their work, your company's intellectual property or even your personal income data, which could help someone steal your tax refund or file for unemployment benefits in your name.

That access means you, too, could be the target of spear-phishing, a juiced-up hacking technique that tries to trick you into handing over login credentials or download malicious software. Twitter says the attack targeted employees on their phones, which means the hackers could have used phone calls or text messages to mislead their targets. 

Spear-phishing attacks also often take place over email. The attacks typically pair an urgent sounding message with credible-sounding information specific to you, like something that could have come from your own tax return. These scams are extra hard to avoid falling for, because they aim to override any red flags you might notice about the email with details that make the sender sound legitimate.

Despite corporate training and stern warnings to be careful who you give your password to, people do fall for these tricks. 

Another consequence of falling for a spear-phishing scam could be downloading malicious software, like ransomware. You could also be convinced to wire money to a cybercriminal's account. Still, you can avoid falling for these scams by taking these security habits to heart. Here's how to avoid a spear-phishing scam.

Know the basic signs of phishing scams

Phishing emails, texts and phone calls try to trick you into visiting a malicious website, handing over a password or downloading a file. This works in email attacks because people often spend the whole day at work clicking on links and downloading files as part of their jobs. Hackers know this and try to take advantage of your propensity to click without thinking.

So the No. 1 defense against phishing emails is to pause before clicking. First, check for signs the sender is who they claim to be:
  • Look at the "from" field. Is the person or business's name spelled correctly, and does the email address actually match the name of the sender? Or are there a bunch of random characters in the email address instead?
  •  
  • While we're at it, does the email address seem close, but a little off? Such as, Microsft.net, or Microsoft.co.
  •  
  • Hover your mouse over any links in the email to see the true URLs they will send you to. Do they look legitimate? Remember not to click!
  •  
  • Check the greeting. Does the sender address you by name? "Customer" or "Sir" would be red flags.
  •  
  • Read the email closely. Is it generally free from spelling errors or odd grammar?
  •  
  • Think about the tone of the message. Is it overly urgent or trying to get you to do something you normally wouldn't?

Don't fall for more advanced phishing emails that use these techniques
more of this post ▼
Even if an email passes the initial smell test outlined above, it could still be a trap. A spear-phishing email might include your name, use more polished language and seem specific to you. It's just plain harder to notice. Then there are targeted phone calls, in which someone calls you and tries to manipulate you into handing over information or visiting a malicious website.

Because spear-phishing scams can be so tricky, there's an extra layer of caution you should apply before acting on a request that comes over email or the phone. The most important of these extra steps: guard your password. Never follow a link from your email to a website and then enter your account password. Never give your password to anyone over the phone.

Banks, email providers and social media platforms often make it policy to never ask for your password in an email or phone call. Instead, you can go to the company's website in your browser and log in there. You can also dial back to the company's call customer service department to see if the request is legit. Most financial institutions, like your bank, will send secure messages through a separate inbox you can access only after you've logged onto the website.

Beat phishing by calling the sender

If someone sends you something "important" to download, asks you to reset your account passwords or requests that you send a money order from company accounts, call the sender of the message -- like your boss, your bank or other financial institution, or the IRS -- and make sure they really sent it to you.

If the request came by phone call, you can still pause and double check. For example, if someone says they're calling from your bank, you can tell the caller you're going to hang up and call back on the company's main customer service line.

A phishing message will often try to make the request seem incredibly urgent, so you might not feel inclined to add an extra step by calling the sender to double-check. For example, an email might say that your account has been compromised and you need to reset your password ASAP, or that your account will expire unless you act by the end of the day.

Don't panic. You're always in the right if you take a few extra minutes to verify a request that could cost you or your company financially, or damage your reputation.

Lock down your personal information

Someone who wants to spear-phish you has to get personal details about you to get started. Sometimes your profile and job title on a company website will be enough to tip off hackers that you're a valuable target for one reason or another.

Other times, hackers can use information they find about you in data breaches. There's not much you can do about either of those things.

But sometimes you're spilling information about yourself that can arm hackers. This is a good reason to set your social media accounts to private and not post every detail of your life on Twitter.

Finally, enable two-factor authentication (learn more HERE) on your work and personal accounts. It's a service that adds an extra step to the login process, and that means hackers need more than just your password to access sensitive accounts. That way, If you do hand over your credentials in a phishing attack, hackers won't have everything they need to log in and wreak havoc.

Follow these steps and you'll be prepared to avoid the pain of getting spear-phished. These tips are also good for avoiding coronavirus scams as well as tax scams.

Credit: cnet.com

No comments:

LABELS INDEX:

* (5) 2038 Problem (1) 3G - Goodbye (1) 5G (2) Abine Blur (1) Activation Lock (1) ADAS (1) Add sound to Impress (2) Address Book (1) AirTags (3) Amazon (3) Android (2) Android phone (2) Annoying Ads (1) Anti-Virus (1) App Store (1) Apple Bytes-2019 (12) Apple Bytes-2020 (19) Apple Bytes-2021 (13) Apple Bytes-2022 (10) Apple Bytes-2023 (11) Apple Glass (1) Apple Maps (1) Apple Repair (2) Apple Support (2) Apple TV (1) Apple Watch (6) Archives of CTC (7) ARM M1 Processor (1) Attachments (1) Audio Files (1) Autonomous (1) Avast (1) Backups (3) Bank-fraud (1) Battery Icon (1) Battery life (4) Battery Replacement (1) BCC (1) Best Buy (1) Big Data Mining (1) Big Sur (1) Bloatware (1) Board Minutes 2019 (12) Board Minutes 2020 (12) Board Minutes 2021 (12) Board Minutes 2022 (12) Board Minutes 2023 (12) Board Minutes 2024 (2) Boom Supersonic (1) Browser Attack (1) Browser Settings (1) Browser Tabs (1) browsers (1) Cache (1) Camera App (1) Caps Lock Indicator (1) Car charging (1) Car Door Lock (1) Cell phone strength (1) Cell Phones (1) Charge Cycles (1) Chevy Bolt (2) Chrome browser (2) Chromecast (1) Clone vs Image (1) Cloud Computing (1) Colorado (1) Construction (1) Contact Removal (1) Converting CDs (1) coronavirus (1) Coupons (1) COVID-19 (1) Covid-19 Detection (1) CPAP Recall (1) CTC 2023 ISP Survey (1) Customer Support (1) Dash Cams (1) Default browser (1) Delete Apps (2) Digital Estate Planning (1) Disable Thumbnails (1) Disk image (2) DogWalk malware (1) Domino's (1) Download Videos (1) Drive Partition (1) Driver Assistance (1) Drones (3) Drywall (1) DuckDuckGo (4) E-bikes (1) E.A.S.Y Pay (1) ebooks (1) Edge (1) Edge Browser (4) EdgeDeflector (1) Electric Bicycles (2) Electric car batteries (1) Electric Cars (6) Electric Trucks (1) email (1) Email Aliases (1) EV (13) EV Charging (1) External Storage (1) Facebook (4) FaceTime (3) Fake Reviews (1) Fast Charging (1) FBI Warning (1) Fiber Optic Cable (1) FIDO (1) File & Folder Icons (1) Firefox (2) Firefox Relay (1) Fitbit (1) Force Quit (1) Future Tech (1) Gmail (2) Gmail Contact (1) Googerteller App (1) Google (1) Google Maps (1) Google Music (1) Google Play Store (1) Google Search (1) Google TV (1) Group Text (1) Hacking (3) Harley-Davidson (1) Headlights (1) Healthcare (1) ID.4 (1) Identify Music (1) Image vs Clone (1) iMessage (2) Incognito Mode (1) Instagram (1) Intel Drivers (1) Internet Explorer (1) Internet of Things (1) Internet speed (1) iOS 13 (1) iOS 14 (2) iOS 15 (2) iPad (5) iPad Air (1) iPadOS 15 (2) iPhone (16) iPhone 12 (1) iPhone Battery (2) iPhone SE (1) iPod Touch (1) ISO Files (1) ISP Down? (1) Karen's Replicator (1) Keyboard (1) keyboard shortcuts (2) LibreOffice (1) LibreOffice Impress (1) Linux Mint 19.2 (1) Lithium-Iron Phosphate (1) M2 Processor (1) Mac (1) Mac Tips (10) MacBook Air (2) macOS (4) Magnifier (1) Mail App (1) Malware (4) Mars (1) Masked Email (1) meetings (6) Microcomb (1) Microsoft (1) Mirroring Tips (1) Mobile Wi-Fi Hotspot (1) Mouse Speed (1) MyHealtheVet (1) NASA (1) Norton (1) old computers (1) OneDrive (1) Ookla (1) Oregon (1) Oura Rings (1) Outlook (1) Parallels 18 (1) passwords (1) PDF (1) PDF Editing (1) Phishing Scams (1) Phone Data Swap (1) Phone Scams (1) Plug & Charge (1) Pop-Up Blocker (1) Portable EV Chargers (1) print spooler (1) Printer problem (1) printers (2) Privacy (5) Privacy Settings (1) Private Browsing (1) Pro Pilot (1) RAM (1) RAM 1500 REV Pickup (1) Range anxiety (2) Range Extended Vehicle (1) Ransomware (3) Rebooting (1) Recharge Cycles (1) Remote control (1) Robots (1) Roomba robots (1) Router (3) Samsung Drive Storage (1) Samsung Gallery Sync (1) Scams (1) SD Cards (1) Search Engines (3) Search Tips (1) Secret Button (1) Security Flaw (1) Security Key (1) Security Warning (1) Sharing From Phone (1) Short Codes (1) Show Wi-Fi Password (1) Signal Strength (1) Sion (1) Siri (1) SkyDrive (1) Slide Over (1) Slow Internet (1) Smart Glasses (1) Smart Home (1) Smart Toys (1) Smartwatch (1) Solar-powered EV (1) Sono Motors (1) Speed Wars (1) Split Screen (1) Split View (1) Spreadsheets (1) Spy Pixel (1) Start Up (1) Startpage (1) Streaming (1) Streaming Services (1) Street View (1) Surface Duo (1) Surface Earbuds (1) System Tray (1) Tab Syncing (1) Tbps (1) Teams (1) Technology Channels (1) Telegram app (1) Tesla (6) Tesla Adapter (1) Tesla Model 3 (1) Texting (1) Tracking (1) Tracking Pixel (1) Two-Factor Authentication (2) Undo Send (1) Unlock Phone (1) Update problems (1) USB drive (1) USPS Informed Delivery (1) VA access (1) Verizon (1) Vertical TV (1) Video Conferencing (1) Videos (3) Voice Assistant (1) Vultur (1) VW (1) Web Beacon (1) WhatsApp (1) wi-fi (2) Wi-Fi Hotspot (1) Widgets (1) Win 10 Performance (5) Windows (1) Windows 10 (9) Windows 10 Tips & Tricks (1) Windows 11 (8) Windows 7 (1) Windows S Mode (1) Windows Update (1) Windows update problem (1) Wink (1) Winstall (1) Yahoo mail (1) Yippy (1) You've Been Hacked (1) YouTube (1) Zero Emissions (1) Zoom (2)