I don't know about you, but I've been receiving many SMS-based phishing attacks, known as smishing, lately. You may be familiar with "your account is on hold" or "click here to track your UPS package", or even the classic "you're a winner". So do we need to be worried about these attacks? The short answer is yes, every organisation and person should take these attacks seriously.
They are abundant and work. Sophisticated or not, many people lose money or are duped into providing user names and passwords (business and personal). Here is an example from less than two weeks ago. In this case, two Indonesian men were arrested for successfully swindling over 60 million dollars using SMS-based phishing scams. It impacted over 30,000 U.S. citizens out of the over 200 million citizens targeted. Two guys…200 million malicious text messages…60 million in stolen money. And you know we only catch the stupid ones.
The biggest reason to prevent smishing attacks from being successful is to protect both you and your organisation. Every skill you teach someone about how to recognise and correctly react to a smishing assists in doing this. It reduces risk to both employee and business.
If an SMS message has the slightest chance of being a malicious phishing message, NEVER click on the URL. Learning how to tell the difference between a rogue and legitimate URL can help immensely. Many phishing SMS messages (and legit ones) have "shortened" URLs. A shortened URL is where the original, usually longer URL, is swapped out for a shorter one. And when the shorter one is clicked on, it redirects the clicker to the longer one. You can use a URL expander service to check the URL.
Chris Haigh
Chief Information Security Officer, Mercury IT
|