Spear Phishing & Whaling: What You Need to Know to Avoid Getting Caught
Edward Maurer
Director of Security
You started a company and call yourself the CEO or founder. Now what? Naturally you’ll announce your position on your company website, in corporation filings, LinkedIn, blog, Twitter, etc. Unfortunately, along with your professional and personal networks, this information is now available to malicious actors. Once they know who you are, they will use that information to their advantage, often using techniques called spear phishing or whaling. Spear phishing is a directed attack toward specific individuals to get them to reveal confidential company or personal information. Usually involving financial gain. Whaling is similar to spear phishing but targets high-level individuals within the organization such as CEOs or founders.
Spear phishing or whaling attacks begin by gathering information about a company and its organizational structure from publicly accessible websites. Attackers use this information to send convincing emails appearing to come from trusted sources such as Microsoft or LinkedIn, or people you know (co-workers or members of your board), asking for confidential company, customer or employee information they can leverage for financial gain.
What can you do to protect yourself and your company from spear phishing and whaling attacks? Here are a few tips to help guide you through the risks.
As a CEO (your company’s biggest whale) you should never click links in emails, EVER.
Email spoofing is one of the most reliable methods for an attacker to gain credentials. This happens simply by clicking on a link that looks correct, but has an embedded link that redirects to an insecure website asking for sensitive information. Below are a few best practices to follow to avoid getting caught:
Don’t post your actual location on social media when traveling
Be very careful of posting your whereabouts on social media. An attacker will use that kind of specific information to make an email seem legitimate.
Imagine a scenario where the CEO tweets they’re attending a conference in a different state. An attacker, posing as you, could use that information to send an email to the CFO or others on the finance team asking for a wire transfer to help pay for something at the conference. See how easy it is?
Understandably, you can’t always keep your whereabouts a mystery, especially if you are speaking at a public event. So if you do need to promote your company’s presence at an event or conference, a better solution is to have your marketing team post to corporate social media accounts.
Whether you’re traveling or not, it’s always good to be on the lookout for these tell tale signs of phishing emails:
Your Email may have already been compromised
Malicious actors may have gained access to your inbox months ago but are laying low, waiting for you to head out of town or for payroll information to come through so they can get the biggest bang for their buck.
If you think this has happened, what should you do about it?
No one is immune to phishing, and attackers know it. And with spear phishing and whaling, their efforts can pay off greatly. While these preventative measures seem like simple common sense, they are effective. And when things get busy, and you have hundreds of unread emails to get through, it’s easy to forget. Our best advice, whether you’re the CEO or a summer intern, think before you click, and always trust your gut. If something seems off, it probably is -- and those few extra minutes could help save your company from a real disaster.
We’re here to help! If you have any questions about cybersecurity for your business contact our free helpline: help@aadyasecurity.com
If you’d like to learn more about Marzo4, our new all-in-one cybersecurity platform for small business, request a demo today: inquiries@aadyasecurity.com