December 20, 2016 By Douglas Bonderud 2 min read

It’s the mea culpa every organization dreads: The admission that staff members were fooled by a phishing email and scammers were able to access the personal data of customers or clients. According to CSO Online, that’s exactly what happened in Los Angeles County when a well-crafted hooked reeled in more than 100 government employees.

The good news is that law enforcement issued a warrant for the perpetrator. The bad news is that more than 750,000 citizen records were compromised, putting valuable personal information at risk.

LA County Reeled In by Phishing Email Scam

While the LA County Chief Executive Office hasn’t provided any specifics about the content or form of the phishing email, a few details have emerged. As reported by Forbes, LA County has now issued breach warnings to 756,000 Californians along with the promise of free identity theft monitoring. They’re going to need it, since cybercriminals made off with addresses, phone numbers, birth dates, Social Security numbers, medical treatment histories and even financial information.

The breach targeted a host of different departments, including the assessors office, children and family services, health services, human resources, public works and even the public library. Alarmingly, the breach warnings were just issued even though the incident happened in May.

The county cited instructions from law enforcement to help track down the responsible party, Austin Kelvin Onaghinor of Nigeria, who now has a warrant out for his arrest. That’s cold comfort to anyone whose personal information may have been floating around the Dark Web for the past six months.

Small Phish, Big Payoff

This breach illustrated the continuing impact of phishing scams. Despite their simplicity — or perhaps because of it — phishing campaigns are extremely effective.

Dark Reading pointed out that cyberattackers are now smart enough to differentiate between human interactions and virtual security sandbox processes, allowing them to actively target the weakest links the security chain: users. It’s nice to offer words of apology, provide free credit monitoring and point to law enforcement for the delay in disclosure, but this isn’t the optimal resolution. Ideally, companies need better ways to both detect and avoid phishing scams.

Let Employees Off the Hook

The solution comes in two parts: First, employees must be trained to report any suspicious email activity. This includes messages that look or sound fraudulent and any interaction with these emails. In other words, staff members need to know that if they make a mistake, they won’t be unduly punished.

The best defense against a phishing attack in progress is early warning. Come down hard on employees for their errors, and they’ll delay reporting until there’s no other choice. Help them sort out the problem, and they’ll report earlier.

It’s also critical to provide relevant training so users can more easily avoid the hook. For example, train employees to scan strange messages for spelling and grammatical errors, which are the hallmarks of low-skill attacks. Sophisticated efforts won’t contain these errors, however, so encourage staff members to examine any embedded links to ensure they lead to official, secure sites.

Better still, teach workers to bypass emails altogether, especially if they demand immediate action. Instead, search out legitimate linked sites using a web browser to reduce the chance of malicious mail success.

Phishing attacks continue to succeed thanks to social pressure and user uncertainty. Increased awareness combined with better training can help keep employees from getting hooked.

More from

What can businesses learn from the rise of cyber espionage?

4 min read - It’s not just government organizations that need to worry about cyber espionage campaigns — the entire business world is also a target.Multipolarity has been a defining trend in geopolitics in recent years. Rivalries between the world’s great powers continue to test the limits of globalism, resulting in growing disruption to international supply chains and economics. Global political risk has reached its highest level in decades, and even though corporate attention to geopolitics has dropped since peaking in 2022, the impact…

How I got started: AI security executive

3 min read - Artificial intelligence and machine learning are becoming increasingly crucial to cybersecurity systems. Organizations need professionals with a strong background that mixes AI/ML knowledge with cybersecurity skills, bringing on board people like Nicole Carignan, Vice President of Strategic Cyber AI at Darktrace, who has a unique blend of technical and soft skills. Carignan was originally a dance major but was also working for NASA as a hardware IT engineer, which forged her path into AI and cybersecurity.Where did you go to…

DHS awards significant grant to improve tribal cybersecurity

4 min read - The Department of Homeland Security (DHS) has awarded $18.2 million in grants through the Tribal Cybersecurity Grant Program to boost cybersecurity defenses among Native American Indian Tribes. The program takes a big step in addressing the unique digital threats faced by tribal communities — a dedicated effort to improve cybersecurity infrastructure across these regions. The $18.2 million grant is just one component of DHS's broader strategy to enhance national cybersecurity. Administered by the Federal Emergency Management Agency (FEMA) in partnership…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today