Security

Don’t Get Poked by Spear Phishing Attacks: Learn Hacking Methods

You may have heard the term before – phishing – when a hacker attempts to trick someone into giving up personal information. It’s a scam that relies entirely on playing into our sense of trust and awareness. Phishing continues to be one of the most substantial online threats in 2018, and occurrences are growing at an alarming rate. But, what happens when attacks are so personalized they are impossible to tell real from fake?

Increased personalization is the goal of spear phishing attacks. Instead of sending out a collection of mass messages or spoofing an online campaign for stealing waves of user data, spear phishing is aimed at a specific target, which sounds unsettling. Such is the tip of a spear, sharpened and directly aimed at one fish in the pond. But how are these attacks carried out and who is at risk?

Open Season for Spear Phishing
Spear phishing attacks are launched against a targeted individual or organization. When a business has been selected as the target, the hacker is looking to obtain industry secrets or put themselves in a position of financial gain.

Read More: 5 Phishing Clues to Look for in Emails from Your Contacts

The attack itself may start with a low-level employee: the hacker takes time to learn a bit about the person and their position. After their research is complete, the hacker sends a phishing email to coax confidential information or sensitive data, such as passwords, out of the individual.

Different from a standard phishing attack, a spear phishing email will address you by name and may claim to be from an internal department you’re accustomed to dealing with. For example,  fake email may claim to be your colleague from IT asking that you confirm your information for the system. The dangerous aspect of spear attacks is how personalized they, customized for you — the hacker’s target.

Always double check the email address in the ‘from’ field. Does it truly originate from within your company or is the email address similar enough, but not quite right? The best defense in the workplace is to stay vigilant and notice where emails are actually coming from. Also, take a moment to have a discussion all the departments you work with, so you know what types of information they will never ask.

Targets Go Beyond Businesses
You don’t need to be an employee or a corporate CEO to be the target of a spear phishing attack. You may be unaware of the sensitive information stored on your personal devices and assume you aren’t a worthy target of these types of attacks. Uh, not so.

When it comes to regular people, spear phishing is more efficient than regular attacks. An attacker may obtain specific information about you such as your name, where you bank, and the contacts you trust. Are you friendly with your local banking repr? Now the hacker also knows this and can create a personalized phishing email that’s aimed at stealing your account details. What’s unsettling is it seems trustworthy – the email addresses you by name, it’s signed by your banking rep, and they even know some of your details.

One way to get started on securing your Android phone is to download a robust antivirus app such as dfndr security, which has an advanced anti-hacking feature. With the ability to alert you of phishing attempts and block potentially malicious links, an app like this can become your line of defense.

Whether you’re on personal or work devices, be sure to check the ‘from’ field of emails to ensure they are originating from an actual trusted source. Basic practices should also be followed like not giving out any personal information or passwords to anyone.

PSafe Newsroom

The dfndr blog is an informative channel that presents exclusive content on security and privacy in the mobile and business world, with tips to keep users protected. Populated by a select group of expert reporters, the channel has a partnership with dfndr lab's security team. Together they bring you, first-notice news about attacks, scams, internet vulnerabilities, malware and everything affecting cybersecurity.

Recent Posts

24 Billion Passwords Exposed? How to Check If You’re Affected.

A massive password leak has triggered a global security alert: Cybernews researchers identified an exposed…

57 years ago

That QR Code on Your Bar Table During the Game: Would You Scan It Without Thinking?

A QR code on a bar table could hide a phishing link. Learn how to…

57 years ago

Could You Spot a Fake Login Page in 5 Seconds? Take the Phishing Test

Before you keep reading, imagine this: You receive a message warning that your account is…

57 years ago

Is Mobile Data Always Safer Than Public Wi-Fi? Myth or Fact?

You’re at an airport and need to open your banking app. Which would you choose:…

57 years ago

Jury Duty Scam: Fake Arrest Warrants Are Targeting Americans

What would you do if someone claiming to be a U.S. Marshal called and said…

57 years ago

World Cup 2026 Streams: How to Tell Safe Links from Dangerous Ones

Kickoff is minutes away. You search for a 2026 World Cup stream and receive a…

57 years ago