Tuesday, April 21, 2020

Social Engineering Attack - Types - Phishing Attack

What is Phishing attack?

Phishing is a type of social engineering attack often used to steal user data, including login credentials and credit card numbers. It occurs when an attacker, masquerading as a trusted entity, dupes a victim into opening an email, instant message, or text message.
  
How it Works?
An attacker will send email or sms and once you receive a malicious email/sms, it will then make you to click on a malicious link inside it, which can lead to the installation of malware, which will make your system freeze and ask for ransom  as part of attack or  reveal sensitive information which can use in future.

Types of Phishing Attacks?

Email phishing scams
An attacker sending out thousands of fraudulent messages to multiple users, it will be a spoofed message often contains delicate mistakes that expose its true identity. These can include spelling mistakes or changes to domain names etc. Users should be vigilant to analyze that why he receiving such emails and think before clicking on an embedded link inside the message.
Scammers use email or text messages to trick you into giving them your personal information. But there are several things you can do to protect yourself which are mentioned below.
Spear phishing
Spear phishing targets a specific person or enterprise, as opposed to random application users. It’s a more in-depth version of phishing that requires special knowledge about an organization, including its power structure.
How to Protect from the Attack?
Phishing attack protection requires steps be taken by both users and enterprises.
·         Do not respond to unknown or unsolicited calls/emails/messages. In case of suspicion, call your bank directly on their published number on their official website.
·         Do not provide banking information to anyone even if the caller claims to be from the bank.
·         Review your bank account and credit card statements at regular intervals for any suspicious transactions.
·         Use security filters of social media applications to safeguard your profile and ensure that no one accesses your details.
·         Do not download unknown apps and if you do so, do not allow them access to your contacts, photos, and any other access which it may ask for.
·         Confirming your whereabouts on social media can tipoff fraudsters about your location, which may be used to harm you financially while you are away.

·         Always remember that your bank NEVER asks for your personal or banking credentials through web links, SMS, email, phone calls etc.

No comments:

Post a Comment