phishing awareness

23
Phishing Awareness

Upload: phishingbox

Post on 18-Dec-2014

602 views

Category:

Education


2 download

DESCRIPTION

Slideshare that can be use as an educational training tool for employees to be aware of the risks of phishing attacks. This presentation covers the threat of phishing and what strategies can be done to mitigate phishing attacks.

TRANSCRIPT

Page 1: Phishing awareness

Phishing Awareness

Page 2: Phishing awareness

What is Phishing?

Page 3: Phishing awareness

Phishing Is A Fake Email

The long definition is that phishing is the act of attempting to acquire information such as usernames and passwords by masquerading as a trustworthy entity in an electronic communication.

Page 4: Phishing awareness

Is Phishing A Threat?

Page 5: Phishing awareness
Page 6: Phishing awareness

29%of security breaches involve social tactics, such as phishing

Page 7: Phishing awareness

Source: 2013 Verizon Data Breach Investigations Report

71%

Phishing Is The Most Used Social Tactic

Page 8: Phishing awareness

91% of targeted attacks use spear-phishing emails.

Spear-Phishing is when detailed information about the recipient, company or others is used to make the email look more credible.

Page 9: Phishing awareness

And It’s Getting Worse

Page 10: Phishing awareness

Phishing Is On The Rise

Page 11: Phishing awareness

The total number of phishing attacksincreased 59 percentfrom 2011 to 2012

Page 12: Phishing awareness

In 2012-2013, 37.3 million users worldwide were subjected tophishing.

Page 13: Phishing awareness

Phishing In The News

Page 15: Phishing awareness

The attack on the AP Twitter Account has a serious impact on the stock market.

Page 16: Phishing awareness

Impact of the attack on the stock market

Page 17: Phishing awareness

No Company Is Immune!Even security companies can fall victim.

Page 18: Phishing awareness

What Can You Do?

Page 19: Phishing awareness

1. Know the signs of a phishing attack

2. Report phishing attacks

Page 20: Phishing awareness

1. Generic greeting

2. Invokes fear

1

2

3. Requires action3

4. Threating language4

55. Grammar Issues

Common Phishing Traits

6. Generic Closing6

Page 21: Phishing awareness

DO hover over links verify its location

DO NOT click on unknown links

DO report the suspected attack

DO NOT reply to suspicious requests

4

What To Do

Page 22: Phishing awareness

There’s More:DO NOT rely on the “from” and “reply to” email addresses as these can be faked

BE SUCPSIOUS of unsolicited attachments

CONFIRM information out of band. That is, contact the sender on a known line, email, website, or other method.

DO NOT use information in the email.

Page 23: Phishing awareness

Phishing attacks are only limited to the creativity of the attacker.

When In Doubt, Ask Your Security Office.DO NOT CLICK, RESPOND, OR DOWNLOAD!