Article illustration

Don't make the headlines! Or everyone is the target - it's a fact!

Why nobody is outside fraudsters' reach: phishing targets money, information and workplace access, and experience alone does not make anyone immune.

4 min read

Phishing is one of the oldest and most common techniques cybercriminals use. In the U.K., phishing was the most common technique used against 83% of businesses that have identified a breach 1. Approximately 4.25 billion email users worldwide communicate through an estimated 333 billion emails daily 2. Another study estimated that over half of all emails are spam 3. A more granular breakdown of spam categories identified more than 3% of spam messages as phishing 3. Together, these numbers suggest around 5 billion phishing emails are sent daily. So, in simple terms, we can say phishing targets everyone every day. Now, also add to these figures the vishing (voice call), smishing (SMS), and the newest addition - qishing (QR codes), and it's clear that these are still conservative estimates. Phishing is undeniably a serious problem affecting all of us, individually and as a society.

Trying to validate this theory empirically on my own email account, I can "proudly" confirm that last Thursday, 9th of November, I received 3 phishing emails (the brands being imitated were Telekom, DHL, and the last one was an "I recorded you" extortion attempt). The next day, I received two more phishing emails (imitating VUB Bank and, again, DHL in Arabic).

Examples of phishing messages received by the author.
Figure 1: Examples of phishing messages received by the author.

Why would anyone attack me?

OK, you might argue that it doesn't necessarily mean everyone is in the attacker's scope, but let's move on. Many might be asking - why would anyone want to target you - a commoner, a regular dude, or a girl? Well, the truth is - if you are an average Joe - they don't necessarily target you specifically; you might just end up in their nets, which were thrown nearby (a tactic called "spray and pray").

Yet remember that, regardless of a person's socio-economic status, everyone has financial assets or information that can be exploited! There's also a revenge motive and, last but not least, access linked to one's occupation. These factors interest fraudsters, though the most common (or visible) motive is financial gain.

Especially for the last point, cybercriminals might be more interested in you than you might think. 76% of (zero-hour) phishing attacks were spear-phishing attacks aimed at stealing the target's credentials 4. If you have a certain role within your organization, like CxO or Accounting and Finance staff, you could facilitate Authorized Push Payment fraud. If you hold a more technical position, e.g., IT admin, DB admin, Architect, etc., you might enable data exfiltration through your IT access privileges. Anyone with access to valuable information, access to money, authority to move money, and the power to make decisions is a very "juicy" target, and it often depends on the attackers' maturity how wide and far they will exploit their entry point. Be aware that phishing and stolen or compromised credentials were the two most common initial attack vectors 5.

Cost and frequency of data breaches by initial attack vector, from the cited IBM report.
Figure 2: Cost and frequency of data breaches by initial attack vector, from the cited IBM report. 5

I'm well aware of the risks; It can't happen to me!

I would put the above heading into the category of "Last famous words." If you agree with the paragraph heading, pay extra attention to the below newspaper headlines:

  1. Tech Executive Falls Victim to $450K Scam on Dating Site 6
  2. IT pros: Half Of Our CEOs Fall Victim To Phishing Scams 7
  3. 1 in 4 employees who fell victim to cyberattacks lost their jobs 8
  4. Phishing Scheme Targets Professors’ Desire to Please Their Deans 9
  5. Nidhi Razdan, News Anchor, Falls Victim to Phishing Attack in The Name of Job Offer From Harvard University 10
  6. 9 Celebrity Victims of Fraud 11
  7. Nobel Laureates Get Scammed, Too 12

These headlines were supposed to make a point that no matter your knowledge, experience, or awareness, literally anyone - me, you, your spouse, your kids, best friends, family members - we all can fall victim to fraud. I have also been the victim of fraud more than once, but let's save that story for another time. So trust me on this - everyone is a target, and everyone can become a victim of fraud. Period.

As we see in almost every report, fraud is all around us, and it is practically impossible not to be targeted. It's not only more prevalent but also more sophisticated. Especially with new technologies, new scams are becoming harder to spot, even for seasoned professionals!

Therefore, please don't become the headline of the newspaper article like the ones above. Be vigilant and try to slow down and re-assess situations, especially when something feels odd. We often unconsciously feel something is off, yet because of everything on our minds at any given moment, we learn to push through. Even the most cautious person isn't vigilant 100% of the time, so when you feel tiredstressed, or exhausted and get a call from the bank, police, or IRS, slow down and think twice before taking any further steps. And, finally, after securing yourself - please help the others- those around you, your friends and family, and don't forget also your kids. Make them aware of potential risks and scams they might face.

References & Further Reading

Continue reading

All articles →

Responses (0)

Join the conversation

Responses are available to read. Reader sign-in is temporarily disabled.

Responses

Loading responses…

Article image

Loading image…