Phishing is a key part of the threat actor’s toolkit, especially to get cyberattacks off the ground. As noted by Dark Reading, some estimates suggested that 91 percent of all cyberattacks start with a phishing attack. This shouldn’t come as a surprise given the increasing sophistication of automated security tools and the reliable social pressure exerted on employees when they see emails that say “act now” or “your account has been compromised.”

But it begs the question: Are cybercriminals more advanced than the users they target? Research firm Imperva created 90 honeypot email and file-sharing accounts to find out. Here’s a look at the phishing attack playbook — and how users can shake the hook.

Not So Sophisticated

The Imperva team monitored their fake accounts over a period of nine months, using traps contained in links and documents to discover how threat actors operated and what they were doing with stolen data. The researchers found that while malicious actors have distinct preferences when it comes to exploitable data, they’re unconcerned about both attack speed and their own security.

For example, the report noted that 25 percent of phishers went after business-related data by looking at email subject lines. But over 50 percent of cybercriminals took more than a day to access accounts after they were compromised, Help Net Security said. Additionally, 74 percent of threat actors triggered bait alerts within three minutes of accessing email inboxes, indicating that they’re likely using manual techniques rather than automated tools.

Despite having access to massive amounts of personal information, less than half of all compromised credentials were exploited. This indicated that attackers may have such a wealth of data available that they can pick and choose accounts with the highest value.

Phishers were also unconcerned with avoiding security scrutiny. According to Help Net Security, 83 percent “did little to cover their tracks.” Of the 15 percent who erased new sign-in email alerts from the inbox, most neglected to clean up the trash folder, and just 39 percent made any effort to obfuscate their origin IP using Tor services or proxies.

Swimming Free From a Phishing Attack

There are some hooks users simply can’t avoid. For example, Computer Business Review reported that a Gmail phishing scam leveraged actual Google links and the company’s use of OAuth to trick users into providing third-party permissions, without the need for victims to re-enter credentials. But the laziness and sloppiness of most phishing attacks creates a small window for users: If they act quickly and decisively enough, it’s possible to wriggle free.

First, pay attention to email inboxes and file-sharing account alerts. If there’s any indication that a new user has signed in or secondary email addresses have been added for recovery, chances are a phishing attack is underway. Users need to check both the trash and sent folders to see if any suspicious messages have appeared or were sent out to other potential victims.

The Imperva team found that if users changed their password within 24 hours of the original phishing attempt, there was a 56 percent chance of preventing account takeover. By notifying email and file-sharing providers of potential attacks, along with changing all connected usernames and passwords — such as banking portals, e-commerce storefronts and any government accounts — it’s possible to frustrate most phishing efforts.

Phishing works — and continues to work — because email is ubiquitous and users don’t do enough to effectively secure accounts. But attackers are no better, leaving ample opportunity for on-the-ball observers to lock down accounts and send phish hooks back up empty.

More from

Most organizations want security vendor consolidation

4 min read - Cybersecurity is complicated, to say the least. Maintaining a strong security posture goes far beyond knowing about attack groups and their devious TTPs. Merely understanding, coordinating and unifying security tools can be challenging.We quickly passed through the “not if, but when” stage of cyberattacks. Now, it’s commonplace for companies to have experienced multiple breaches. Today, cybersecurity has taken a seat in core business strategy discussions as the risks and costs have risen dramatically.For this reason, 75% of organizations seek to…

How IBM secures the U.S. Open

2 min read - More than 15 million tennis fans around the world visited the US Open app and website this year, checking scores, poring over statistics and watching highlights from hundreds of matches over the two weeks of the tournament. To help develop this world-class digital experience, IBM Consulting worked closely with the USTA, developing powerful generative AI models that transform tennis data into insights and original content. Using IBM watsonx, a next-generation AI and data platform, the team built and managed the entire…

How the FBI Fights Back Against Worldwide Cyberattacks

5 min read - In the worldwide battle against malicious cyberattacks, there is no organization more central to the fight than the Federal Bureau of Investigation (FBI). And recent years have proven that the bureau still has some surprises up its sleeve. In early May, the U.S. Department of Justice announced the conclusion of a U.S. government operation called MEDUSA. The operation disrupted a global peer-to-peer network of computers compromised by malware called Snake. Attributed to a unit of the Russian government Security Service,…

How NIST Cybersecurity Framework 2.0 Tackles Risk Management

4 min read - The NIST Cybersecurity Framework 2.0 (CSF) is moving into its final stages before its 2024 implementation. After the public discussion period to inform decisions for the framework closed in May, it’s time to learn more about what to expect from the changes to the guidelines. The updated CSF is being aligned with the Biden Administration’s National Cybersecurity Strategy, according to Cherilyn Pascoe, senior technology policy advisor with NIST, at the 2023 RSA Conference. This sets up the new CSF to…