Happy Father’s Day

But don’t worry! In the spirit of giving, we created this phishing link to demonstrate the differences between a true link and a fake, and what you should be looking out for when opening any links.

Understanding the difference in a true and a fake link is vital for any person and business, to help reduce the risk of sensitive data being stolen. In 2020 SlashNext created a report of the state of phishing and estimated that around 50,000 phishing emails are sent every day. Many of these containing links to websites which looks real, when in fact these are fake, to try and get the user to login to the website using actual credentials. Then stealing these credentials, manipulating them or using them.

Common Signs

To help prevent against the likeliness of this from occurring, here are some things you should be on the look for when opening emails and clicking on attachments:

  1. Check to see if the URL link that you may be pressing is shortened. Though link shortening services such as TinyURL or bit.ly are legitimate services, it is often the case that attackers will look to leverage them to conceal their link’s true destination. The best way is to paste the short link into a link expansion service such as CheckShortURL.com to reveal the link’s true destination.
  2. Phishing URL attacks often try to hide the address within a link by using a URL encoding, to replace some characters with special characters. An example of this would be the letter B translates to %42.
  3. Cyber criminals also use script spoofing to register lookalike websites. They use letter combinations, foreign letters, and numbers to resemble a letter (or letter combinations) visually:
  • “m” looks like “rn” at first glance
  • “í” looks like “i”
  • “0” looks like “O” 
  • For example, the link to this article used on social media was changed to https://www.csp.partners/2O22/O6/16/happy-fathers-day/ – so that the zeros was swapped for O’s to show its an incorrect and potentially harmful link.
 
Email Phishing

Also, phishing links may often be used in conjunction within emails. So, below we have some more quick tips around email phishing:

  1. If the message is asking you to act ‘urgently’ – This is to try to make you panic in order to act carelessly. Be wary of emails that are threatening ‘Your account will be closed’.
  2. Unofficial “From” address – Look out for a sender’s email address that is similar to, but not the same as, a company’s official email address. Often, it may have extra letters or punctuation.
  3. Bad grammar or spelling errors – Unsurprisingly, one of the biggest giveaways that an email is fraudulent is the spelling and grammar. If an email is badly written, and claims to be from a legitimate business, there should be immediate cause for concern that the sender isn’t who they claim to be due to this unprofessional content.
  4. Requests for personal information – Real businesses will very rarely ask you to send sensitive information about yourself or others by email, especially out of the blue. Because of this, if you receive a suspicious email that asks you for information like your national insurance number, your bank details or your home address, it’s always a smart move to double check the sender and previous correspondence.

 

To help prevent phishing attacks, you should try to follow the top tips above, although this is just some of the best practices. Make sure your systems are always updated to help protect against known vulnerabilities. Protect devices and systems with reputable security software and firewall protection. Without this, it could potentially cost you your personal details, finances and shutdown of devices/systems.

Since the weak link in phishing attacks is the end user, you should provide proper end-user security awareness training. Click here to see how CSP can help you and your business.

Leave a Reply

Your email address will not be published. Required fields are marked *