ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Getting Phish'd

    IT Discussion
    8
    24
    3.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • MattSpellerM
      MattSpeller @Dashrender
      last edited by

      @Dashrender nah still dollar sign but you were on the right path with nationality

      1 Reply Last reply Reply Quote 0
      • MattSpellerM
        MattSpeller
        last edited by

        This phishing was so good I honestly asked my manager if we were being audited.

        1 Reply Last reply Reply Quote 0
        • DashrenderD
          Dashrender
          last edited by

          I wonder if filters are missing a possibly obvious point they could be providing protection. email address % matching.

          If the spam filter could have at least flagged this if not flat out blocked it because a name is 95% the same, these types of spam would be blocked.

          Of course I wouldn't want the level to be set at something like 95%, more like 70% would probably be enough to protect us 95% of the time with little false positives. of course if you're company like NTG this could be a problem.... [email protected] vs [email protected] is 47% different, well below the 70% matching... so I don't know..

          Additionally, blocking email from our domain that originate from outside our domain is something else we should be blocking.

          1 Reply Last reply Reply Quote 1
          • nadnerBN
            nadnerB
            last edited by

            That's nuts! So impressively close.
            On the subject have a read of Stu's post about a spear-phishing campaign deploying cryptolocker via dropbox: http://community.spiceworks.com/topic/868260-alert-new-ransomware-spearphish-uses-one-click-dropbox-attack?page=1

            1 Reply Last reply Reply Quote 0
            • david.wieseD
              david.wiese
              last edited by

              we had this a few weeks ago. The account on the pdf was a fully legit and active account out of a Chase bank in Skokie, IL. We contacted both the chase bank and ours as well as the local fbi field office since this would be considered interstate wire fraud. I still haven't heard anything from the fbi on this.

              1 Reply Last reply Reply Quote 0
              • tonyshowoffT
                tonyshowoff
                last edited by

                We get tons of different attacks via our various email addresses for billing. We get more emails from fake PayPal password recovery, updating account info, etc than we get from actual PayPal.

                david.wieseD 1 Reply Last reply Reply Quote 0
                • david.wieseD
                  david.wiese @tonyshowoff
                  last edited by

                  @tonyshowoff but these are different than those other phishing scams that you can tell are completely fake. These are detailed down to the very person who signs off on the wire transfers. The one we had here knew the name of our president, ceo, cfo, vp of finance and controller and had crafted the emails to look like it was being sent from the cfo to the controller (who signs off on the wire transfers). The email address that was being used was once again .co and not .com. They hid the email header information so these guys are really good. Using a real bank account that was detailed enough to get the name on the account, account number, routing number (which i know is easy to find). Whoever is doing this does their homework.

                  tonyshowoffT 1 Reply Last reply Reply Quote 1
                  • scottalanmillerS
                    scottalanmiller
                    last edited by

                    It's called spear-phishing.

                    1 Reply Last reply Reply Quote 1
                    • tonyshowoffT
                      tonyshowoff @david.wiese
                      last edited by

                      @david.wiese We get ones that are addressed to our two accountants though is what I was referencing, not just the obvious ones, their names too. Which is unusual because these email addresses are not public and do not contain their names. It made me wonder if PayPal got hacked or what a while ago.

                      DashrenderD 1 Reply Last reply Reply Quote 1
                      • DashrenderD
                        Dashrender @tonyshowoff
                        last edited by

                        @tonyshowoff said:

                        @david.wiese We get ones that are addressed to our two accountants though is what I was referencing, not just the obvious ones, their names too. Which is unusual because these email addresses are not public and do not contain their names. It made me wonder if PayPal got hacked or what a while ago.

                        This is precisely what makes it spear-phishing. The would-be thieves do their homework and everything they can to make the communication look as real as possible so someone just does what it says.

                        If they spend 20 hours on one email and get you to send hundreds of thousands of dollars, that's a pretty great payday!

                        tonyshowoffT 1 Reply Last reply Reply Quote 1
                        • tonyshowoffT
                          tonyshowoff @Dashrender
                          last edited by

                          @Dashrender I'm just saying we have a similar problem and it's really bizarre, and we go through a lot to keep much of our company operations hidden, not because we're the mob or anything, but because adult entertainment gets a lot of BS

                          DashrenderD 1 Reply Last reply Reply Quote 1
                          • DashrenderD
                            Dashrender @tonyshowoff
                            last edited by

                            @tonyshowoff said:

                            @Dashrender I'm just saying we have a similar problem and it's really bizarre, and we go through a lot to keep much of our company operations hidden, not because we're the mob or anything, but because adult entertainment gets a lot of BS

                            Considering how much money there is there, that makes you an even larger target.

                            tonyshowoffT 1 Reply Last reply Reply Quote 1
                            • tonyshowoffT
                              tonyshowoff @Dashrender
                              last edited by

                              @Dashrender said:

                              Considering how much money there is there, that makes you an even larger target.

                              You're telling me, we're #3-4-ish on the web as far as adult entertainment goes, and it wasn't a problem for a while, but over the last year it's gotten steadily worse.

                              ? 1 Reply Last reply Reply Quote 0
                              • ?
                                A Former User @tonyshowoff
                                last edited by

                                @tonyshowoff said:

                                @Dashrender said:

                                Considering how much money there is there, that makes you an even larger target.

                                You're telling me, we're #3-4-ish on the web as far as adult entertainment goes, and it wasn't a problem for a while, but over the last year it's gotten steadily worse.

                                I'd be okay if they took all the money out of those kind's of companies. (I personally think they should be illegal anyway).

                                tonyshowoffT 1 Reply Last reply Reply Quote 0
                                • tonyshowoffT
                                  tonyshowoff @A Former User
                                  last edited by

                                  @thecreativeone91 said:

                                  I'd be okay if they took all the money out of those kind's of companies. (I personally think they should be illegal anyway).

                                  Pornography? Well, then you get into grey areas of art vs pornography, etc. Full disclosure, I've never been big into porn at all, it's just never been a thing for me, what happened was I realised an opportunity to make money when YouTube stopped allowing adult content (or actually started policing it, whatever happened) and took advantage of it.

                                  1 Reply Last reply Reply Quote 0
                                  • 1
                                  • 2
                                  • 1 / 2
                                  • First post
                                    Last post