Staying informed about the latest cybersecurity threats is key to protecting your organization’s technology infrastructure. Phishing, a prevalent form of cyberattack, has undergone significant advancements, posing new challenges for individuals and organizations alike.

Let’s take a look at what phishing is and then dig deeper to highlight some of the latest sophisticated techniques being employed. We’ll also share some suggested best practices to protect your systems and prevent your team members from becoming the next phishing victims.

What is Phishing?

Phishing is a type of cybercrime where attackers masquerade as trustworthy entities to deceive individuals into disclosing confidential information. This deceptive practice dates back to the early days of the internet, where it initially focused on emails attempting to lure individuals into revealing passwords, credit card numbers, and other sensitive data. The term “phishing” is a twist on the word “fishing,” as it involves baiting individuals and “fishing” for personal information.

Modern phishing email campaigns are highly sophisticated, often replicating the look and feel of legitimate communications from well-known companies or organizations. These emails often create a sense of urgency or fear, prompting the recipient to act quickly, thus bypassing their better judgment and leading to the disclosure of sensitive data.

The evolution of phishing has mirrored the advancements in technology and communication platforms. Cybercriminals have expanded beyond email to utilize social media, text messages, and even phone calls to execute phishing attacks. The goal remains consistent: to trick individuals into providing personal information or downloading malware.

 

New Forms of Phishing Attacks

Being alert to new trends helps everyone better protect their systems and employees. The threat of email phishing is ever-present, and cybercriminals are becoming more adept at disguising their bait. However, there are other, yet more sophisticated attacks that you should be aware of. Be on the lookout for these new trends.

1. QR Code Phishing

QR code phishing is a relatively new phishing technique where scammers use QR codes to trick people into visiting malicious websites or downloading malware. This method takes advantage of the growing popularity and convenience of QR codes, which are often used for legitimate purposes like accessing menus in restaurants or connecting to Wi-Fi networks. In an attack, a scammer embeds a harmful link in a QR code. When an unsuspecting user scans the code with their smartphone, they are directed to a phishing website or unintentionally download malicious software.

The danger of QR code phishing lies in the inherent trust people place in these codes and the difficulty in discerning a malicious QR code from a benign one. Users scanning QR codes often do not take note of where the code leads them until after they have scanned it and their browser navigates to the encoded URL. This lack of visibility creates a perfect opportunity for scammers to exploit.

To protect against QR code phishing, try these tips:

  • Exercise caution when scanning QR codes. Did the code come from an unknown or unverified source? Users should avoid scanning QR codes that appear in unsolicited emails, flyers, or public places where they could have been easily tampered with.
  • Use QR scanners that display the URL before opening. This allows the user to verify the legitimacy of the link.

Staying informed about this newer form of phishing and adopting cautious practices when dealing with QR codes are key steps in protecting personal information from these types of cyberattacks.

2. Phishing via Instant Messaging and Text Messaging

Cybercriminals have increasingly turned to instant messaging platforms as a venue for phishing attacks, leveraging the widespread use and trust in these communication tools.

One common technique is angler phishing, which involves the use of fake URLs, instant messages, or profiles on messaging apps to obtain sensitive data. Cybercriminals create profiles that appear like a legitimate business or impersonate someone the victim knows or trusts. They then send messages that often contain malicious links or requests for personal information. The deceptive nature of these messages makes it challenging for users to recognize the malicious intent.

To protect against such phishing attempts on instant messaging platforms, try these ideas:

  • Be wary of unexpected messages. Does the message come from a new number or profile? Be especially cautious with messages that contain links or requests for sensitive information.
  • Verify the authenticity of messages. Does it seem to come from someone you know? Contact them via a different channel to confirm, particularly when they prompt for immediate action or personal data.

Regular updates to security software and awareness of the latest phishing tactics can also enhance protection against these evolving cyber threats.

3. Social Media Phishing

Cybercriminals use social media for phishing attacks in several sophisticated ways, exploiting the vast amount of personal and professional information users share on these platforms. Here’s an overview of how they conduct these attacks:

  • Gathering Personal Information: Social media users often share a wealth of information about their personal and professional lives, such as job updates, travel photos, and family details. This information is incredibly valuable for hackers, who use it to craft targeted and effective attacks. For instance, posting a boarding pass or a birthday shout-out can provide hackers with critical data like travel plans or workplace details.
  • Conducting Targeted Attacks: Hackers conduct extensive research on their targets, including studying company structures, relationships, and individual behaviors. This reconnaissance helps them identify entry points, impersonate credible third parties, and subtly nudge targets toward compliance. For example, they might use out-of-office messages and other publicly available information, along with knowledge of your company structure available on LinkedIn, to trick your accounting staff into initiating a wire transfer in CxO fraud schemes.

The key takeaway is that the information shared on social media, even seemingly harmless details, can be used by hackers in sophisticated phishing attacks. Users need to manage their digital footprints carefully and be cautious about the personal information they share online.

6. Deepfake Phishing

Deepfake phishing is a rapidly evolving cybercrime technique that leverages highly realistic AI-generated audio and video content used to impersonate trusted individuals, such as family members or corporate managers and executives.

The danger of deepfake phishing lies in its ability to bypass traditional security measures that rely on identifying suspicious or uncharacteristic communication. Because the deepfake content can closely mimic the voice, facial expressions, and mannerisms of real people, it becomes challenging for recipients to discern the fake from the real. This technology has advanced rapidly, with AI algorithms able to analyze and replicate minute details, making the impersonations more believable. Deepfake phishing can be used for various malicious purposes, including financial fraud, spreading misinformation, or stealing sensitive information.

To protect against deepfake phishing, individuals and organizations need to be aware of this emerging threat and implement advanced security measures. These may include:

  • Enhanced Verification Procedures: Implementing multi-factor authentication and verification protocols that go beyond visual or auditory recognition.
  • Employee Education: Regular training to raise awareness about deepfake technology and its use in phishing attacks.
  • Advanced Security Tools: Utilizing AI and machine learning-based security systems capable of detecting deepfake content.

Given the sophistication of deepfake technology, staying informed and vigilant is crucial in combating this new face of cybercrime.

Targeting Small Businesses

In 2024, small businesses are increasingly becoming targets for phishing attacks due to a combination of factors that make them more vulnerable compared to larger organizations. Here’s an overview of why small businesses are at a greater risk:

Limited Cybersecurity Resources and Knowledge:

  • Budget Constraints: Small businesses often operate with limited budgets, which can lead to underinvestment in cybersecurity infrastructure and advanced protection tools.
  • Lack of Dedicated IT Staff: Many small businesses do not have dedicated IT security teams, relying instead on general IT staff or external support, which may not be sufficient for identifying and mitigating sophisticated phishing attacks.
  • Inadequate Employee Training: There is often a lack of regular and comprehensive cybersecurity training for employees, making them less aware of the latest phishing tactics and how to recognize them.

Assumed Lower Risk:

  • Underestimation of Threats: Small business owners may believe that they are less likely to be targeted by cybercriminals compared to larger corporations, leading to a complacent attitude towards cybersecurity.
  • Valuable Data: Despite their size, small businesses can possess valuable data like customer information, intellectual property, and financial details, making them attractive targets for cybercriminals.

The increased targeting of small businesses by phishing attacks in 2024 emphasizes the need for these entities to prioritize cybersecurity. Implementing robust security measures, educating employees, and staying informed about the latest cyber threats are essential steps to protect their assets and data.

How to Protect Your Team and Your Data

While there are an ever-increasing number of threats, there are also measures to protect your organization from attack. Here are four basic principles to bolster your defenses:

  1. Continuous Education and Training: Regular training on the latest phishing trends is essential. Employees should learn to identify suspicious emails and messages.
  2. Advanced Security Solutions: Implement AI and ML-based security systems that can detect sophisticated phishing attempts.
  3. Regular Security Audits: Frequent audits help identify vulnerabilities in cybersecurity infrastructure.
  4. Two-Factor Authentication: Enforcing 2FA adds an extra layer of security, making it harder for attackers to gain access.

 

The threat landscape is continually changing, with phishing attacks becoming more sophisticated. It is crucial to stay informed and adopt robust security measures. Yet, if you’re a small business, or a nonprofit, operating on a limited budget, hiring staff and purchasing security solutions may seem out of your financial reach.

For that reason, we created Gryphon Guardian, a suite of tools and services to protect your organization at a price you can afford. Whether in the office or on the go, using corporate devices or a BYOD program, we have a solution to keep you safe.

Contact us today, and let us help fortify your defenses against these evolving cyber challenges.