“Phishing,” a type of cyberattack in which a hacker disguises themself as a trusted source online to acquire sensitive information, is a common and technologically simple scam that can put your employees and business at risk.
However, more resourceful criminals are resorting to a modified and more sophisticated technique called “spear phishing”. In spear phishing, a hacker uses personal information to pose as colleagues or other sources specific to individuals or businesses.
A spear phishing attack is often disguised as a message from a close friend or business partner and is more convincing than a normal phishing attempt. When messages contain personal information, they are much more difficult to identify as malicious.
For businesses, the potential risk of spear phishing is monumental. A report released by the Internet Crime Complaint Center (IC3) stated that there were over 800,000 cybercrime-related complaints against businesses last year, resulting in over $800 million lost. A large majority of these attacks can be attributed to spear phishing, since the messages are designed and customized to make victims feel safe and secure.
Any personal information that is posted online can potentially be used as bait in a spear phishing attack. The more a criminal learns about a potential victim, the more trustworthy he or she will seem during an attack. Once the apparent source gains the victim’s trust, and there is information within the message that supports the message’s validity, the hacker will usually make a reasonable request, such as following a URL link, supplying usernames and/or passwords, or opening an attachment.
Even if spear phishing perpetrators target just one of your employees, it can put your entire business at risk. Falling for a spear phishing attack can give a hacker access to personal and financial information across an entire network. And, successful spear phishing attacks oftentimes go unnoticed, which increases the risk of large and continued losses.
Though it is difficult to completely avoid the risk that phishing attacks pose, there are ways to prevent further damage to your business. Make sure that your employees are aware of these simple techniques:
Here are 6 additional ways to reduce cyber security risk for your business.
If you believe that your business has been the target of a spear phishing attack, it is important to act quickly to limit your potential losses. The first step should be to immediately change the passwords of any accounts connected to the personal or financial information of your business or its clients, and to obtain a list of recent and pending transactions. It may also be necessary to contact law enforcement.
Next, an internal or third-party IT expert should be consulted to pinpoint any vulnerabilities that remain in your business’ network. He or she can advise you on how to avoid future attacks.
If you have further questions about spear phishing or other types of cyberattacks, or if you would like to discuss potential insurance coverage options to further protect your business, contact RMC Group today at 239-298-8210 or rmc@rmcgp.com.
This article is not intended to be exhaustive, nor should any discussion or opinions be construed as legal advice. Readers should contact legal counsel or an insurance professional for appropriate advice. © 2015 Zywave, Inc. All rights reserved.