Spear-phishing: what it is and how we protect ourselves?
About the dangers of phishing and protection methods I have already written on this blog. It is a fraud technique through which cybercriminals send deceptive emails that, at first glance, appear to come from legitimate sources – such as a bank, a service provider, or a public institution.
Unfortunately, there is also a more sophisticated method, increasingly encountered: spear-phishing. To protect ourselves effectively, it is essential to understand how it works and what risks it involves, so that we can strengthen our "defense arsenal" against online fraud attempts.
What is spear-phishing?
The term spear-phishing (spear = spear, phishing = "fishing" for data) is very suggestive. Unlike classic phishing attacks, in the case of spear-phishing attackers target a single person or a specific institution, using personalized messages. Often the victim is addressed by name, and the message contains real information – such as the workplace, position, the names of colleagues or bosses – precisely to inspire trust.
The frequency of these attacks is increasing also because, through social networks and other online platforms, fraudsters have access to more and more sensitive information about us.
How can we protect ourselves?
The basic rules for protection are the same as in phishing, so it is very important to never lose sight of the recommendations below:
- Be careful with emails from unknown senders.
- Even if it seems that the message comes from someone known, check the email address and the received links.
- Be attentive to signs that may indicate a phishing attempt: an alarmist tone, grammatical errors, promises "too good to be true".
- Do not disclose personal information: identity, accounts, card number, expiration date, or PIN code.
- Do not click on links received from unverified sources or that you do not know.
- Remember that BT never sends links for downloading applications or for accessing internet banking services: applications are available for free in official application stores, and internet banking services on the bank's official website.
Given, however, that attackers who use the spear-phishing method often base their attacks on information obtained from detailed research about the target or institution, it is essential to also consider other risk factors:
- Information we share about ourselves on social media can be a true treasure for criminals. Look at your profile through the eyes of a cybercriminal and delete data that can be exploited: date of birth, phone number, email address, home address, bank details.
- Set your profile so that only friends can see your posts.
- Think twice before posting vacation or leisure photos, and avoid activating the location feature.
- And because such attacks can target companies as well: pay attention to emails that seem to come from colleagues or even superiors, especially if they request urgent payment or contain unusual requests.
Prevention remains the best weapon against online fraud. If you have doubts about a received message, better check twice than regret later. We are at your disposal with tips and support (0264.308.055 or contact@btrl.ro).