July 31, 2017 By Douglas Bonderud 2 min read

Phishing is a key part of the threat actor’s toolkit, especially to get cyberattacks off the ground. As noted by Dark Reading, some estimates suggested that 91 percent of all cyberattacks start with a phishing attack. This shouldn’t come as a surprise given the increasing sophistication of automated security tools and the reliable social pressure exerted on employees when they see emails that say “act now” or “your account has been compromised.”

But it begs the question: Are cybercriminals more advanced than the users they target? Research firm Imperva created 90 honeypot email and file-sharing accounts to find out. Here’s a look at the phishing attack playbook — and how users can shake the hook.

Not So Sophisticated

The Imperva team monitored their fake accounts over a period of nine months, using traps contained in links and documents to discover how threat actors operated and what they were doing with stolen data. The researchers found that while malicious actors have distinct preferences when it comes to exploitable data, they’re unconcerned about both attack speed and their own security.

For example, the report noted that 25 percent of phishers went after business-related data by looking at email subject lines. But over 50 percent of cybercriminals took more than a day to access accounts after they were compromised, Help Net Security said. Additionally, 74 percent of threat actors triggered bait alerts within three minutes of accessing email inboxes, indicating that they’re likely using manual techniques rather than automated tools.

Despite having access to massive amounts of personal information, less than half of all compromised credentials were exploited. This indicated that attackers may have such a wealth of data available that they can pick and choose accounts with the highest value.

Phishers were also unconcerned with avoiding security scrutiny. According to Help Net Security, 83 percent “did little to cover their tracks.” Of the 15 percent who erased new sign-in email alerts from the inbox, most neglected to clean up the trash folder, and just 39 percent made any effort to obfuscate their origin IP using Tor services or proxies.

Swimming Free From a Phishing Attack

There are some hooks users simply can’t avoid. For example, Computer Business Review reported that a Gmail phishing scam leveraged actual Google links and the company’s use of OAuth to trick users into providing third-party permissions, without the need for victims to re-enter credentials. But the laziness and sloppiness of most phishing attacks creates a small window for users: If they act quickly and decisively enough, it’s possible to wriggle free.

First, pay attention to email inboxes and file-sharing account alerts. If there’s any indication that a new user has signed in or secondary email addresses have been added for recovery, chances are a phishing attack is underway. Users need to check both the trash and sent folders to see if any suspicious messages have appeared or were sent out to other potential victims.

The Imperva team found that if users changed their password within 24 hours of the original phishing attempt, there was a 56 percent chance of preventing account takeover. By notifying email and file-sharing providers of potential attacks, along with changing all connected usernames and passwords — such as banking portals, e-commerce storefronts and any government accounts — it’s possible to frustrate most phishing efforts.

Phishing works — and continues to work — because email is ubiquitous and users don’t do enough to effectively secure accounts. But attackers are no better, leaving ample opportunity for on-the-ball observers to lock down accounts and send phish hooks back up empty.

More from

Cloud Threat Landscape Report: AI-generated attacks low for the cloud

2 min read - For the last couple of years, a lot of attention has been placed on the evolutionary state of artificial intelligence (AI) technology and its impact on cybersecurity. In many industries, the risks associated with AI-generated attacks are still present and concerning, especially with the global average of data breach costs increasing by 10% from last year.However, according to the most recent Cloud Threat Landscape Report released by IBM’s X-Force team, the near-term threat of an AI-generated attack targeting cloud computing…

Testing the limits of generative AI: How red teaming exposes vulnerabilities in AI models

4 min read - With generative artificial intelligence (gen AI) on the frontlines of information security, red teams play an essential role in identifying vulnerabilities that others can overlook.With the average cost of a data breach reaching an all-time high of $4.88 million in 2024, businesses need to know exactly where their vulnerabilities lie. Given the remarkable pace at which they’re adopting gen AI, there’s a good chance that some of those vulnerabilities lie in AI models themselves — or the data used to…

FBI, CISA issue warning for cross Apple-Android texting

3 min read - CISA and the FBI recently released a joint statement that the People's Republic of China (PRC) is targeting commercial telecommunications infrastructure as part of a significant cyber espionage campaign. As a result, the agencies released a joint guide, Enhanced Visibility and Hardening Guidance for Communications Infrastructure, with best practices organizations and agencies should adopt to protect against this espionage threat. According to the statement, PRC-affiliated actors compromised networks at multiple telecommunication companies. They stole customer call records data as well…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today