6 Phishing Attacks in the digital threat landscape
Based on the 2021 Data Breach Investigation Report (DBIR), phishing accounted for 36% of all breaches, so let’s have a look at a few of the most common types of phishing attacks and some tips that organizations can use to protect themselves.
1.Deceptive Phishing
Phishing scams are most commonly associated with deceptive phishing. Hackers pose as legitimate companies to steal login credentials or personal information. Attackers use threats and a sense of urgency to scare users into doing what they want.
How to Defend Against Deceptive Phishing
For phishing to work, an email must resemble official correspondence from a spoofed company. Therefore, internet users should examine all URLs carefully for any redirections to unknown or suspicious websites. As well as generic salutations, spelling errors, and grammar errors, they should be vigilant.
2.Spear Phishing
Hackers tailor their attack emails to include the target’s name, position, company, work phone number, and other details to make the recipient believe they have a connection with the sender. Despite this, the goal is the same as deceptive phishing: get the recipient to click on a malicious URL or email attachment so that their personal information can be obtained. Considering the amount of data needed to craft a convincing attack attempt, it is no surprise that spear-phishing is commonplace on social networking sites like Linkedin, where attackers can use multiple sources to craft a customized attack email.
Spear Phishing: How to Protect Yourself
To avoid this type of scam, organizations should conduct ongoing employee security awareness training, which discourages employees from publishing sensitive personal or corporate information on social media. Additionally, companies should invest in solutions that analyze inbound emails for malicious links/attachments.Using this solution, malware and zero-day threats should both be picked up.

3.Whaling
An organization’s executives can also be targeted by spear phishing. “Whaling” attacks follow a similar logic. Scammers attempt to harpoon executives and steal their login details in these scams.
The fraudsters can choose to carry out CEO fraud if their attack proves successful. In the second stage of a business email compromise (BEC) scam, CEO fraud occurs when attackers use the compromised email account of a CEO or other high-ranking executive to authorize fraudulent wire transfers. They can also use that email address to conduct W-2 phishing by requesting W-2 information for each employee to file fake tax returns on behalf of the company or post the information on the dark web.
Whaling: How to Prevent It
An important reason why whale attacks work is because executives don’t participate in security training with their employees.As a precaution against CEO fraud and W-2 phishing, companies should ensure that all employees, including executives, participate in security awareness training on an ongoing basis.Additionally, organizations should consider injecting multi-factor authentication channels into their financial authorization processes so that payments cannot be authorized by email alone.
4.Vishing
The majority of phishing attacks we have discussed so far have relied on email. Nevertheless, fraudsters do sometimes target other media in their attacks.
Vishing, for example. In this type of phishing attack, an email is not sent but rather a phone call is made. The company pointed out that attackers can perpetrate a vishing campaign by setting up a Voice over Internet Protocol (VoIP) server that mimics various entities in order to steal sensitive information and/or funds. Those tactics were used by malicious actors to increase their vishing efforts and target remote workers in 2020, according to the FBI.
Defending yourself against Vishing
Vishing attacks can be prevented by not answering calls from unknown numbers, never providing personal information over the phone, and using a caller ID app.

5.Smishing
Vishing isn’t the only type of Phishing of digital fraud digital fraudsters can perpetrate using a mobile device. There is also a technique known as smishing. In this method, users are tricked into interacting with a malicious web link or revealing personal information by receiving malicious text messages.
Defending yourself against Smishing
Users can defend themselves against smishing attacks by researching unknown phone numbers and by calling the company named in suspicious SMS messages if they have any doubts.
6.Pharming
Some fraudsters are abandoning the idea of “baiting” their victims altogether as users become wiser to traditional phishing scams. These fraudsters use pharming instead. This method of phishing exploits cache poisoning against the domain name system (DNS), which allows sites on the Internet to convert alphabetical names, such as “www.microsoft.com,” into numerical IP addresses that allow them to locate and thereby direct users to computer networks and devices.
During a DNS cache poisoning attack, a pharmer targets a DNS server and changes the IP address associated with an alphabetical website name.As a result, a malicious website can be used to redirect users to an attacker’s choice.Even if the victim enters the correct website name, the problem still exists.
Defending yourself against Pharming
Organizations should encourage their employees to enter login credentials only on HTTPS-protected sites in order to prevent pharming attacks. Companies should also deploy anti-virus software on all corporate devices and update their virus databases regularly.In addition, they should stay on top of security updates issued by a trusted Internet Service Provider (ISP).

