Phishing

Phishing

Spot a phishing email before you click.

What Is Phishing?

Phishing targets the person rather than the software, which is why it is still the most common way an attacker gets a first foothold. You'll work a suspicious email in a 3D office: inspect the sender address for a subtle misspelling, check where a link actually points, and name the urgency and authority cues doing the persuading. Then you'll report it through the proper channel and see how one set of stolen credentials becomes a full account takeover.

What You'll Learn in Phishing

Phishing — Training Steps

  1. Introduction

    Today, you will learn about phishing attacks and how to protect yourself and the company from them.

  2. Email Notification

    While working from home, Alice receives a new email notification titled 'Urgent: Update Your Security Question'. Intrigued, she opens her mail inbox.

  3. Reading the Email

    Alice opens the email, which urges her to update her security questions via the employee portal. The email's professional tone and sense of urgency might compel her to act swiftly. Alice, trusting the source, decides to follow the email's instructions.

  4. Enter Credentials

    The login page requests Alice's company username and password to proceed with updating her security questions. The page's resemblance to the legitimate employee portal makes it easy for her to assume it is safe, so Alice continues with entering her credentials without a second thought.

  5. Error Message

    After 'logging in', the web browser displayed an error window instead of Alice's account dashboard, which left Alice worried.

  6. Email Notifications

    Soon, Alice receives two new emails and proceeds to read them.

  7. Bob's Malicious Actions

    Unbeknownst to Alice, Bob gains access to her credentials. Using her account, he performs malicious actions: he accesses the company's financial system and initiates a fraudulent transaction, transferring $10,000 to a fake vendor, 'Shadow Corp.' Additionally, he downloads sensitive files, including vendor contracts and payment details, from Alice's account.

  8. Report Phishing Email

    To mitigate the damage, Alice decides to follow the steps proposed by the IT Department's email. First, she uses her mailing client to report the malicious email.

  9. Login to Web Portal

    Alice opens her web browser and navigates to the company's internal security incident reporting portal: https://securetech.com/report-incident

  10. Reporting the Incident

    After successfully entering the internal IT support ticketing system, Alice fills out a ticket form, detailing the suspicious email and unauthorized transaction.

Security Framework Coverage

MITRE ATT&CK

  • T1566.002 Phishing: Spearphishing Link

CIS Controls

  • CIS 14.2 Train Workforce Members to Recognize Social Engineering Attacks

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind