{"id":6654,"date":"2019-08-12T11:40:00","date_gmt":"2019-08-12T11:40:00","guid":{"rendered":"http:\/\/localhost\/datcomWP\/?p=6654"},"modified":"2019-08-12T11:40:00","modified_gmt":"2019-08-12T11:40:00","slug":"think-before-you-click-spotting-a-phishing-attempt","status":"publish","type":"post","link":"https:\/\/staging.datcomllc.com\/index.php\/2019\/08\/12\/think-before-you-click-spotting-a-phishing-attempt\/","title":{"rendered":"Think Before You Click: Spotting a Phishing Attempt"},"content":{"rendered":"<p>We\u2019ve all caught the obvious spam email, like the message that is clearly bogus, or the offer that is definitely too good to be true.<\/p>\n<p>We\u2019re going to confidently assume none of our readers are getting tricked by Nigerian Princes or getting roped into order virility drugs from an unsolicited email. The real threat comes from the more clever phishing attacks. Let\u2019s take a look.<\/p>\n<p><!--more--><\/p>\n<h2>Give Me the Short Answer &#8211; What\u2019s Phishing?<\/h2>\n<p>Phishing is where you get an email that looks like an actual legit email. The goal that a cybercriminal has is to trick you into giving them a password or access to an account (like to PayPal, Facebook, or your bank) or to get you to download malware.<\/p>\n<p>The problem with phishing emails is how real they can seem. A phishing attempt for your PayPal information can look just like an everyday email from PayPal.<\/p>\n<p>Even worse, often phishing emails try to sound urgent. They make you feel like you have to take action quickly, or that a bill is overdue, or that your password has been stolen. This can lower the user\u2019s guard, and force them into a sticky situation.<\/p>\n<h2>How to Spot a Phishing Attack<\/h2>\n<p>Like I said, it\u2019s not always going to be obvious when you get phished. Even careful, security-minded, technical people can fall victim because phishing is just as much of a psychological attack as it is a technical one.<\/p>\n<p>Still, there are some practices you and your staff should use:<\/p>\n<h3>Always Use Strong, Unique Passwords<\/h3>\n<p>This can solve a lot of problems from the get-go. If your PayPal account gets hacked, and it uses the same password as your email or your bank account, then you may as well assume that your email and bank account are infiltrated too. Never use the same password across multiple sites.<\/p>\n<h3>Check the From Email Address in the Header<\/h3>\n<p>You\u2019d expect emails from Facebook to come from something@facebook.com, right? Well, if you get an email about your password or telling you to log into your account and it\u2019s from something@faecbook.com, you\u2019ll know something is up.<\/p>\n<p>Cybercriminals will try to make it subtle. Amazon emails might come from something@amazn.com or emails from PayPal might come from something@paypalsupport.com. It\u2019s going to pay off to be skeptical, especially if the email is trying to get you to go somewhere and sign in, or submit sensitive information.<\/p>\n<h3>Don\u2019t Just Open Attachments<\/h3>\n<p>This is nothing new, but most malware found on business networks still comes from email attachments, so it\u2019s still a huge problem. If you didn\u2019t request or expect an email attachment, don\u2019t click on it. Scrutinize the email, or even reach out to the recipient to confirm that it is safe. I know it sounds silly, but being security-minded might build security-mindfulness habits in others too, so you could inadvertently save them from an issue if they follow your lead!<\/p>\n<h3>Look Before You Click<\/h3>\n<p>If the email has a link in it, hover your mouse over it to see where it is leading. Don\u2019t click on it right away.<\/p>\n<p>For example, if the email is about your PayPal account, check the domain for any obvious signs of danger. Here are some examples:<\/p>\n<ul>\n<li><strong>Paypal.com<\/strong> &#8211; This is safe. That\u2019s PayPal\u2019s domain name.<\/li>\n<li><strong>Paypal.com\/activatecard<\/strong> &#8211; This is safe. It\u2019s just a subpage on PayPal\u2019s site.<\/li>\n<li><strong>Business.paypal.com<\/strong> &#8211; This is safe. A website can put letters and numbers before a dot in their domain name to lead to a specific area of their site. This is called a subdomain.<\/li>\n<li><strong>Business.paypal.com\/retail<\/strong> &#8211; This is safe. This is a subpage on PayPal\u2019s subdomain.<\/li>\n<li><strong>Paypal.com.activecard.net<\/strong> &#8211; Uh oh, this is sketchy. Notice the dot after the .com in PayPal\u2019s domain? That means this domain is actually activecard.net, and it has the subdomain paypal.com. They are trying to trick you.<\/li>\n<li><strong>Paypal.com.activecardsecure.net\/secure<\/strong> &#8211; This is still sketchy. The domain name is activecardsecure.net, and like the above example, they are trying to trick you because they made a subdomain called paypal.com. They are just driving you to a subpage that they called secure. This is pretty suspicious.<\/li>\n<li><strong>Paypal.com\/activatecard.tinyurl.com\/retail<\/strong> &#8211; This is really tricky! The hacker is using a URL shortening service called TinyURL. Notice how there is a .com later in the URL after PayPal\u2019s domain? That means it\u2019s not PayPal. Tread carefully!<\/li>\n<\/ul>\n<p>Keep in mind, everyone handles their domains a little differently, but you can use this as a general rule of thumb. Don\u2019t trust dots after the domain that you expect the link to be.<\/p>\n<h2>Training and Testing Go a Long Way!<\/h2>\n<p>Want help teaching your staff how to spot phishing emails? Be sure to reach out to the IT security experts at COMPANYNAME. We can help equip your company with solutions to mitigate and decrease phishing attempts, and help educate and test your employees to prepare them for when they are threatened by cybercriminals.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We\u2019ve all caught the obvious spam email, like the message that is clearly bogus, or the offer that is definitely too good to be true. We\u2019re going to confidently assume none of our readers are getting tricked by Nigerian Princes or getting roped into order virility drugs from an unsolicited email. The real threat comes [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":6655,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":""},"categories":[12],"tags":[67,151,169],"_links":{"self":[{"href":"https:\/\/staging.datcomllc.com\/index.php\/wp-json\/wp\/v2\/posts\/6654"}],"collection":[{"href":"https:\/\/staging.datcomllc.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/staging.datcomllc.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/staging.datcomllc.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/staging.datcomllc.com\/index.php\/wp-json\/wp\/v2\/comments?post=6654"}],"version-history":[{"count":0,"href":"https:\/\/staging.datcomllc.com\/index.php\/wp-json\/wp\/v2\/posts\/6654\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/staging.datcomllc.com\/index.php\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/staging.datcomllc.com\/index.php\/wp-json\/wp\/v2\/media?parent=6654"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/staging.datcomllc.com\/index.php\/wp-json\/wp\/v2\/categories?post=6654"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/staging.datcomllc.com\/index.php\/wp-json\/wp\/v2\/tags?post=6654"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}