
E-mail Security
Email is still very much a thing particularly in the business world so allow me to indulge myself with what I call Campbell's law.
Campbell's law
Any email that asks for personal information must be ignored and here is what safely you can do that, I use a common example of a spam campaign that occurs every year particularly around tax time you get an email that appears to be from the IRS stating that you got a refund coming to you or worse that they are taking you to court.
Spam is designed to prey on people's fear's and people do fall for it but you've probably heard organizations like IRS or the banks or the other institutions telling you that they will never contact you via email asking information or discussing personal matters. Regardless of the policy if you receive such an email and suspect it might be legitimate the appropriate response is to save a copy of the email, take up the phone and dial the number of the institution that way you know that you are dealing with the actual organization.
Common spam techniques used by hackers and spammers to trick you
Spear phishing is used by getting some personal information on you upfront your name, may be some details about where you work, what you do, who your colleagues are and that kind of things and then crafting an email just for you so that its more devious that general spam like the IRS example.
Nigerian 419 scam has been around as long as email. Named after the section nigerian criminal code that deals with fraud. This is scam where someone pretending to be a prince or a rich person contacts you and asks for help to get money out of the country. All you have to do is wire them some money first as a show of good faith. This foot is fairly new but as a security professional I must admit that I am surprised it took this long.
E-mail address spoofing you receive an email apparently from your own email account with a message telling you that you have been hacked. The scammer may get into a bit of detail on how they did it but its all sketchy, the spelling and grammar are poor they give a bitcoin wallet address to send them a payment. If you receive such an email you can completely ignore it.
Impersonating the Boss which is a bit of a spear phishing campaign and a bit of email spoofing. You receive an email from the CEO, a senior executive, an owner like email spoofing this is known as impersonating fraud and employees should know what to look for so they can detect these scams.
Here are some common ways that hackers and spammers try to get you to infect your organizations network
Spammers and Phishing to get a reply from you. Even if you its spam you feel like replying to ask the emailer not to contact you again don't. Some of these scammers want to validate that this is the email address you use so that they can bombard you with more emails.
Fake links appear to be one thing but actually another. This technique is similar to email spoofing and sense that the hacker or spammer impersonates legitimate web address, If you know anything about HTML then you know that when you create a weblink you can give it a different name than the url useful because urls can get quite long so you see a link in an email that says www.IRS.gov or abcbank.com it looks legit right? dont click it. A good email address reader should allow you to hover the mouse over the link and popup the actual address if your email reader doesn't have that capability then simply right click the link and choose copy link in the flyup menu then paste it into a text editor if its anything but a legitimate link then its fraudulent.
Another trick attackers user is create a link that it looks like its from legitimate company but they add a domain extension to the end for example IRS.gov.org or abcbank.org.biz something other than the actual site the last extension is always the one to look for because that is the one which determines where the link will navigate to.
Chameleon attachments are attachments pretending to be something else for example what looks like a pdf is actually an executable.
Common warning signs of a scam
False sense of urgency (act now!) An email telling you have to act now or face threats of legal action.
Poor spelling and grammar is a classic tell that an email is not legitimate
Asking for personal information just ignore then email
Threats (Your account will be locked)
E-mail safety best practices
- Don't open attachments unless you are absolutely certain that its from a legitimate sender.
- Think before you click
- Familiarize yourself with e-mail spoofing
- Hover over links (don't click on them_
- Don't use your personal email for business purpose
- Use your malware scanner to scan emails
- Treat email password like others
- Don't enable macros
- Learn how to recognize scams
- Understand how URLs work
- Protect your email address
You must be logged in to post a comment.