Phishing is a trap to get your sensitive data through email which seems, it is from a trusted and well-known sender. This fraudulent attempt is done by online scammers (cybercriminal) to steal your identity and passwords to do crimes. The term “Phishing” was first used in 1996 that occurred in Usenet newsgroup called AOHell. Since the earlier hackers are called “Phreaks”, the ‘f’ in fishing replaced by ‘ph’. Even phishing attacks start to propagate through email, now it held by phone calls too.
Mostly the attackers target a certain group or individual, Instead of sending emails to a large number of people. And those email seems like it is from reputed organization. Phishing emails make recipient panic by saying that your account has been hacked or there is an unrecognized activity occurred in your account and forced them to change their credentials using a given link. On the other hand, victims encourage to click on the link by saying that they have won a reward. When the receiver clicks on the malicious link, it will be redirected to the fake website with trustworthy features. Otherwise, it will download malicious software to your device.
With the details you entered using the link, the scammers are allowed to do any kind of crimes.
- Invade into your mail inbox.
- Steal money from your bank account.
- Extort the victims by saying that they have your confidential details and photos.
- Demanding ransom to recover your device.
- Compromise the targeted device and take administrative control.
- Used for political campaign and more…
Therefore initially you have to have a cautious look at the emails you received even if it says office document.
- Analyze the URL. If you hover the mouse over URL, it will display where you will be redirected to. There is some web source to check whether it redirects to a legitimate site. Look whether it starts from HTTPS instead of HTTP and concern on the spelling of the URL too.
- Check the structure. There can be misspelled words and grammar error in the email and places somewhere look informal.
- Never click on the link which cannot be differentiated.
- Contact the organization and verify whether they have sent such emails via the correct contact number. Not through mentioned in those emails.
- Keep update your operating system and web browsers.
- Use antivirus software.
- Use two factor authentication and other security mechanism for online and social media accounts.
- Frequently change your passwords.
According to the recent analysis by security provider Mimecast, there is one in 61 emails in our mail inbox now contains a malicious link. Between August to November and December to February, the number of emails that contains malicious link has increased by 126 percent. Consequently there is a necessity to protect ourselves from phishing to prevent data breach.
"Fishing is relief. Phishing is not!"
Very useful information
ReplyDeleteThank you
Delete