Phishing


Contact us by filling out this form - Contact Us



Interested in Cybersecurity Awareness Training? Start your free Risk Assessment.



Purchase our Anti-Phishing Bundle


How many of your users, do you think, truly understand phishing? Do you run exercises? Do you track metrics around phishing and training around phishing awareness?

If you answered "unsure" or "no" to any of the above questions, then you are definitely at risk!

First, do your users understand what phishing is? If the answer is "no", you should start at the ground level and create a comprehensive phishing awareness program, and add detailed phishing awareness training to your annual computer security awareness training.

Normally, we would have a link for you to click to finish reading this article... but then again, that is phishing, isn't it? Phishing can take many forms. The actual act of phishing doesn't change, but the different types of phishing relate directly to who the targets are. For example, you can phish DNS (called pharming), but for this article, we are only going to discuss the different types of human phishing. This is simply because there is a much greater risk of a human being phished than of anything else.

The concept behind phishing is to obtain sensitive information. Generally, phishing involves impersonating a legitimate sender (email, PDF, document, etc.) to create an opportunity for the target to provide sensitive information. Some controls can prevent senders of phishing campaigns from sending phishing emails, and others can prevent suspicious outbound connections to potential phishing destinations. But does your organization have those controls? Even if you do have those controls, the first line of defense is user awareness.

Human-based phishing is generally categorized as follows.

- General phishing - "General" phishing can be equated to a shotgun blast. You don't really have to aim very well, and you will still likely hit your target with the pellets. In this case, a company is specifically targeted, and a large number of emails are sent to as many people as possible within the company in hopes that someone will provide information. Generally, far more than just one person provides information.

- Spear phishing - Spear phishing is the same as general phishing; however, in this case, the targets have been narrowed down to a specific set of people. Generally, a spear-phishing campaign also indicates strong reconnaissance of the target company to determine exactly who to target.

- Whaling - Whaling is a subset of spear phishing in that the phishing targets are generally high-level people within the target company. Persons such as the "C suite", VPs, EVPs, etc, that can influence the company in some way or another. Examples include a CEO being compromised and then sending an email to the CFO to issue a cashier's check for a large sum of money. Generally, CEOs aren't questioned on their actions, which makes this a very dangerous situation for the company.

- Phone phishing - Phone phishing is the same thing as electronic phishing (including the type of targets); however, all activity is performed over the phone.

So what makes a phishing email successful? First, the subject needs to be enticing. The person has to want to read the email and click the link. So, what makes an email enticing? Well, that goes into the research into the company to help determine that. If the target is an automobile company, they are likely interested in automobile-related subjects (e.g., recall notices). Second, it needs to be personal in some way... use of the first name, for example, or content that suggests a relationship, such as pictures from the New Year's company party..."Bob looks like he had a little too much fun". What company doesn't have a Bob or a John? Third, the phishing campaign needs to be random and sporadic. For example, if 100 phishing emails were sent at the same time. Everyone asked "did you just get this email?" then someone is likely to press the "I just got phished" button and alert security. A successful phishing campaign will have those 100 emails spread out over time, during periods that make sense. Another successful tactic is to run an obvious phishing campaign simultaneously with a well-planned one, to help camouflage the well-planned one. After all, who would do two phishing campaigns at the same time and to the same place?

Any amount of phishing is going to require advanced work by the phishers. This will mean that they are going to try and figure out what makes the company tick, what affects the company and employees, what the employees will likely want to open, what the employees will likely immediately view as phishing, etc... Once they have done this then they will build a phishing strategy or what they think is the best option to phish a target successfully.

So you are probably wondering what success looks like in combating phishing, as well as what a successful phish looks like. For the phishing exercises we have conducted, we find an average phishing rate of 10% across all targets. Thus, we estimate generalized phishing at around 10%. Spear-phishing has a phish rate of about 5%, depending on the target. A low-level employee being spear-phished is less likely to be compromised than a high-level target. An intern can be phished just as easily as anyone in a role that revolves around customer satisfaction. A brand-new employee is less likely to be phished because they have recently completed the company's computer security awareness training. Whaling success rate varies based on the age of the target. Older targets are more likely to be phished than younger targets, who are more computer-savvy. However, phone phishing has a much higher success rate than all other forms of phishing... we estimate phone phishing rates at around 30%. This includes having the target provide numerous amounts of sensitive or personal information, or even running commands on their own workstation. Phone phishing is a little more difficult, as the phisher must then convey a specific tone of voice, appear to speak English as a first language, and be confident in their answers when questioned by the target. However, we also find that once the target is convinced that the phisher can be trusted, then more information is released.

What can you do to improve your company? First, conduct a comprehensive evaluation of your computer security awareness training to ensure that phishing is adequately covered. Hire a 3rd party, such as Arrakis, to conduct 3rd-party phishing against your company to establish a baseline. Create reportable metrics that clearly show the number of persons trained, user reports related to phishing, and how many actual hostile phishing attempts were made against your company. An additional suggestion would be to read our article about scams


Interested in Cybersecurity Awareness Training? Start your free Risk Assessment.


We are masters at these frameworks and many more.

Our membership in professional organizations

Contact Us