1 min read

Voicemail Phishing Attacks Called Vishing Are On The Rise

While “vishing” is by no means a new threat, it’s not something that has ever happened with sufficient frequency to get most people’s attention. So, if you haven’t heard the term before, you’re not alone.

“Vishing” is short for voicemail phishing, and it is apparently on the rise based on data collected by the security firm Zscaler. Attackers are specifically targeting tech firms and US military installations.

No actual voice mails are involved, which is interesting.  What the attackers do is send emails with links that supposedly point the way to voicemail messages stored on LinkedIn, WhatsApp, or other services. The idea behind the attacks are is to trick an unsuspecting recipient into disclosing his or her Outlook or Office 365 credentials.

To make their credential capture page more convincing, the attackers have even taken to deploying a CAPTCHA system, which makes the page look just annoying enough to be legitimate.

A spokesman for Zscaler had this to say about the company’s recent discovery of the surge in vishing attacks:

“Voicemail-themed phishing campaigns continue to be a successful social engineering technique for attackers since they are able to lure the victims to open the email attachments. This combined with the usage of evasion tactics to bypass automated URL analysis solutions helps the threat actor achieve better success in stealing the users’ credentials.”

The folks at Zscaler have a point. If your employees haven’t been made aware that this kind of attack is not only possible but growing in popularity in certain sectors, make sure they know what to be on the lookout for. Kudos to the sharp-eyed folks at Zscaler for spotting the trend.

The Goal is to Frustrate Hackers’ Efforts

We may not be able to keep hackers from making the attempt. However, if we can warn enough people about the tricks they’re using, we can frustrate their efforts and that’s a good start.

Used with permission from Article Aggregator

Not Every Job on Your List Deserves an AI Bot. Here's How to Tell Which Do

Not Every Job on Your List Deserves an AI Bot. Here's How to Tell Which Do

Not every process deserves an AI bot. Here's how to tell which ones do and why the first one matters most.

Read the full blog
Your IT Security Posture Might Be in the Dark. A Risk Assessment Turns the Lights On

Your IT Security Posture Might Be in the Dark. A Risk Assessment Turns the Lights On

A cybersecurity risk assessment doesn't create your problems. It just turns the lights on so you can see what's already there.

Read the full blog
The Law Office Has Left the Building. Your Security Needs to Keep Up

The Law Office Has Left the Building. Your Security Needs to Keep Up

The office has left the building. Here's what securing a distributed law firm actually requires and where most firms fall short without realizing it.

Read the full blog

1 min read

Update Now If You Run This WordPress Plugin

Millions of people around the world have leveraged the awesome power of WordPress to build their sites. Whether for personal or business use,...

Read the full blog

1 min read

Fortinet VPN User Passwords May Have Been Leaked Online

Hackers recently released a list of nearly half a million Fortinet VPN usernames and passwords onto the Dark Web. The group behind the attack claims...

Read the full blog
The Future of Cybersecurity - Unifying People, Processes, & Technology

1 min read

The Future of Cybersecurity - Unifying People, Processes, & Technology

You can buy the most expensive, diamond-encrusted lock for your front door, but if you leave the key under the mat, that lock is nothing more than an...

Read the full blog