Forum Moderators: open

Message Too Old, No Replies

Report: 82 Seconds To Ensnare a Phishing Victim

         

engine

11:06 am on Apr 14, 2015 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



What, 82 seconds!

I suppose people are fooled and then quickly enter credentials, or open the site and it's done.

Only the other day i received a document that was perfectly timed to coincide with an update to a service I use. The document used an incoming e-mail address which must have been harvested. It was never given out to anyone apart from the spammers. My system indicated spoofed links, so it never got further. Had its timing been a week earlier or later it would have been ignored entirely.

It takes 82 seconds for cyber-thieves to ensnare the first victim of a phishing campaign, a report suggests.

Compiled by Verizon, the report looks at analyses of almost 80,000 security incidents that hit thousands of companies in 2014.

It found that, in many companies, about 25% of those who received a phishing email were likely to open it.

"Training your employees is a critical element of combating this threat," said Bob Rudis, lead author on the report. Report: 82 Seconds To Ensnare a Phishing Victim [bbc.co.uk]

J_RaD

2:29 pm on Apr 14, 2015 (gmt 0)



don't just catch a phishing email and delete it, report it so it can be taken down!

[us-cert.gov...]

engine

2:53 pm on Apr 14, 2015 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Does that actually do anything, J_RaD?

not2easy

3:29 pm on Apr 14, 2015 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



I do take the time to report them to the spoofed entity. I didn't know they had a .gov clearing house for reports.

J_RaD

7:24 pm on Apr 14, 2015 (gmt 0)




Does that actually do anything, J_RaD?

as far as I know it does, i've had some comcast and paypal phishing stuff come to me, reported it to cert and the offending site was down with a quickness.

if your corp network gets hit with some kinda big time hack you can also report this to CERT and they'll work with you to track down the dirt bags and bust them.