Phishing Attack Trends in 2022 – What you can do to protect your data
We work with clients every day to help them mitigate risk and protect their data, intellectual property and prevent interruptions to core business systems. There are countless horror stories in Australia and globally of systems being compromised which can cause a huge impact on a brand’s reputation and financial losses are hard to ignore.
This is also important for your brand’s social accounts which are often cloud platforms. At the very minimum, ensure you have 2FA enabled on all of your core systems. Recently, the Instagram account of SA lifestyle and news website Glam Adelaide was hacked. Kelly Noble, who founded the popular brand in 2007 said this had a huge impact on the business.
“We’ve lost access to 10 years of work, thousands of hours and over 21,000 posts promoting SA destinations and businesses,” she said.
Here are some actions you can take to protect your data. If you’d like to know more or get a risk assessment on your business and processes. Get in touch with our team.
In 2020, 75% of companies around the world experienced a phishing attack. Phishing remains one of the biggest dangers to your business’s health and wellbeing because it’s the main delivery method for all types of cyberattacks.
One phishing email can be responsible for a company succumbing to ransomware and having to face costly downtime. It can also lead a user to unknowingly hand over the credentials to a company email account that the hacker then uses to send targeted attacks to customers.
Phishing takes advantage of human error, and some phishing emails use sophisticated tactics to fool the recipient into divulging information or infecting a network with malware.
Mobile phishing threats skyrocketed by a whopping 161% in 2021.
Your best safeguards against the continuous onslaught of phishing include:
- Email filtering
- DNS filtering
- Next-gen antivirus/anti-malware
- Ongoing employee cybersecurity awareness training
To properly train your employees and ensure your IT security is being upgraded to meet the newest threats you need to know what new phishing dangers are headed your way.
Here are some of the latest phishing trends that you need to watch out for in 2022.
Phishing is increasingly being sent via text message
Fewer people are suspicious of text messages than they are of unexpected email messages. Most phishing training is usually focused on the email form of phishing because it’s always been the most prevalent.
But cybercrime entities are now taking advantage of the easy availability of mobile phone numbers and using text messaging to deploy phishing attacks. This type of phishing (called “smishing”) is growing in volume.
People are receiving more text messages now than they did in the past, due in large part to retailers and service businesses pushing their text updates for sales and delivery notices.
This makes it even easier for phishing via SMS to fake a shipment notice and gets a user to click on a shortened URL.
Business email compromise is on the rise
Ransomware has been a growing threat over the last few years largely because it’s been a big money-maker for the criminal groups that launch cyberattacks. A new up-and-coming form of attack is beginning to be quite lucrative and thus is also growing.
Business email compromise (BEC) is on the rise and being exploited by attackers to make money off things like gift card scams and fake wire transfer requests.
What makes BEC so dangerous (and lucrative) is that when a criminal gains access to a business email account, they can send very convincing phishing messages to employees, customers, and vendors of that company. The recipients will immediately trust the familiar email address, making these emails potent weapons for cybercriminals.
Small businesses are being targeted more frequently with spear phishing
There is no such thing as being too small to be attacked by a hacker. Small businesses are targeted frequently in cyberattacks because they tend to have less IT security than larger companies.
43% of all data breaches target small and mid-sized companies, and 40% of small businesses that become victims of an attack experience at least eight hours of downtime as a result.
Spear phishing is a more dangerous form of phishing because it’s targeted and not generic. It’s the type deployed in an attack using BEC.
It used to be that spear-phishing was used for larger companies because it takes more time to set up a targeted and tailored attack. However, as large criminal groups and state-sponsored hackers make their attacks more efficient, they’re able to more easily target anyone.
A result is small businesses receive more tailored phishing attacks that are harder for their users to identify as a scam.
Business impersonation is being used more often
As users have gotten savvier about being careful of emails from unknown senders, phishing attackers have increasingly used business impersonation. This is where a phishing email will come in looking like a legitimate email from a company that the user may know or even do business with.
Amazon is a common target of business impersonation, but it also happens with smaller companies as well. For example, there have been instances where website hosting companies have had client lists breached and those companies sent emails impersonating the hosting company and asking the users to log in to an account to fix an urgent problem.
More business impersonation being used in phishing attacks mean users have to be suspicious of all emails, not just those from unknown senders.
Is your company adequately protected from phishing attacks?
It’s important to use a multi-layered strategy when it comes to defending against one of the biggest dangers to your business’s wellbeing. Get started with a cybersecurity audit to review your current security posture and identify ways to improve.
Risk Assessments [as recommended by The Australian Cyber Security Centre ACSC] will review your environment in accordance with the Essential Eight Mitigation Strategies, and is the best solution to protect your business from cyber attacks.
Article used with permission from The Technology Press.
About Blackbird IT
Blackbird IT strategically implements technology in workplaces to deliver powerful operational efficiencies, competitive advantage and innovation for every business. See some of our client case studies and partnerships here.
Get in touch for a quote or to check current hardware supply times and what’s new in this space. We deliver an outcome-driven approach for managing all your technology needs and help you realise your potential.