• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • HomePage
  • About
  • Structure
  • Schedule
    • First Half of the Semester
      • Week 1: Overview of Course
      • Week 2: TCP/IP and Network Architecture
      • Week 3: Reconnaissance
      • Week 4: Vulnerability scanning
      • Week 5: System and User enumeration
      • Week 6: Sniffers
      • Week 7: NetCat, Hellcat
    • Second Half of the Semester
      • Week 8: Social Engineering, Encoding, and Encryption
      • Week 9: Malware
      • Week 10: Web application hacking, Intercepting Proxies, and URL Editing
      • Week 11: SQL injection
      • Week 12: Web Services
      • Week 13: Evasion Techniques
      • Week 14: Review of all topics and wrap up discussion
  • Assignments
    • Analysis Reports
    • Quizzes & Tests
  • Webex
  • Harvard Coursepack
  • Gradebook

ITACS 5211: Introduction to Ethical Hacking

Wade Mackay

Phishing Threat Continues To Loom Large

November 6, 2016 by Loi Van Tran 2 Comments

Although medium and large-sized organizations has taken proactive measures to train their employees on how to detect and protect themselves against phishing and spear-phishing scams, the article points out that they are still vulnerable.  It reports that 41% of organizations survey have lost sensitive information on employee’s computers, and 24% have lost sensitive data from corporate network.  It points out that the best way to mitigate phishing attacks is through employee training.  It also provided a really good example of how social media can be used for reconnaissance to craft a sophisticated spear phishing attack against a victim.

The main points of this article is to ensure that your employees are trained and aware of phishing attacks, make yourself a harder target by reducing your digital footprint, or be careful of what you post online.

Article: http://www.darkreading.com/partner-perspectives/malwarebytes/phishing-threat-continues-to-loom-large/a/d-id/1327370?

Filed Under: Uncategorized Tagged With:

Reader Interactions

Comments

  1. Ahmed A. Alkaysi says

    November 7, 2016 at 11:48 am

    My company obviously seems phishing as a huge concern, as they provide trainings on it. One of the methods they use in order to bring more awareness to the issue, is that they will test us by using phishing links. For example, the cyber team will send us an email claiming that we have just received a request for an invitation by somebody on Linkedin. There will be a link in the email supposedly to accept the request. After clicking it, it will navigate to a different page explaining the dangers of phishing attempts. Its a very interesting training method which is working.

    Log in to Reply
    • Jason A Lindsley says

      November 7, 2016 at 9:13 pm

      Our company does the same thing Ahmed and it is very effective. We have seen the click rates on these phishing simulations decline significantly over the past several rounds of these exercises. We also have effective phishing take down capabilities that help to identify fake sites impersonating our company and trying to trick our customers.

      These are strong controls but the battle continues as these phishing attacks and user errors still persist.

      Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Uncategorized (133)
  • Week 01: Overview (1)
  • Week 02: TCP/IP and Network Architecture (8)
  • Week 03: Reconnaisance (25)
  • Week 04: Vulnerability Scanning (19)
  • Week 05: System and User Enumeration (15)
  • Week 06: Sniffers (9)
  • Week 07: NetCat and HellCat (11)
  • Week 08: Social Engineering, Encoding and Encryption (12)
  • Week 09: Malware (14)
  • Week 10: Web Application Hacking (12)
  • Week 11: SQL Injection (11)
  • Week 12: Web Services (10)
  • Week 13: Evasion Techniques (7)
  • Week 14: Review of all topics (5)

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in