How to Prevent Phishing at Work
Phishing is a type of social engineering attack that tries to trick people into giving away money or personal information. Its hallmarks include requests that are out of the ordinary or appear to be too good to be true, requests for sensitive data and a sense of urgency.
Scammers typically impersonate companies that are familiar to their targets, like banks, online retailers and the makers of popular apps. They also spoof email addresses to make the messages look genuine. In a recent study, Kavvadias and Kotsilieris found that demographic factors like age, education and technical skills are related to vulnerability to phishing attacks. But psychological traits such as impulsivity, trust and emotions also play a role.
Some phishing scams involve impersonating company employees to gain access to sensitive information. In one example, attackers used a spearphishing email to gain access to the CEO’s company email account and then used SecurID two-factor authentication to steal confidential data from employees across the organization.
The best way to prevent phishing is to educate everyone in the workplace about the dangers and how to identify phishing attempts. Regular training sessions can help employees spot suspicious emails and flag them through designated reporting tools in Microsoft Edge and Windows 10. Additionally, deploy software that detects and blocks phishing attempts. And finally, require multifactor authentication (MFA) on all accounts to increase the difficulty of compromising a user’s identity or stealing company data.
If you suspect a phishing attack, immediately change all passwords associated with the affected site and use MFA on any accounts that contain financial information or personal data. Additionally, monitor your credit report for new lines of credit you don’t recognize.