How to Protect Yourself From Phishing
Phishing is a cyber threat that takes many forms and can lead to a variety of damaging outcomes. For individuals, the effects may include stolen money, fraudulent charges on credit cards or lost access to photos and videos. For organizations, the risks could include a financial loss or a loss of trust with customers and colleagues.
The goal of phishing is to trick victims into revealing sensitive information, such as passwords, account numbers or other personal details. Attackers use a variety of techniques to achieve their goals, including impersonating legitimate sources, creating a sense of urgency and exploiting emotions such as fear. Signs of a phishing email or message include a request for personal details, an urgent call to action or threats such as “account termination” or a warning that a 2FA code will expire.
Scammers will often target well-known brands and businesses, such as banks, online retailers or the makers of popular apps. This tactic increases the likelihood that an attacker will succeed by luring victims with a brand they recognize and trust.
Attackers may also send emails, texts or voicemails containing malicious links that take the victim to a counterfeit website. These sites can be used to harvest data, install malware or deliver a payload such as ransomware.
Often, the malicious payload in these campaigns is delivered via an attachment. Attackers employ a range of tactics to lure unsuspecting recipients into opening these files, including using emotive language to instil a sense of fear or curiosity. A good rule of thumb is to be suspicious of emails that contain attachments and never click on a hyperlink without a full display of its contents (including the hidden URL, which can be revealed by hovering over the link).