- Microsoft will float cloud OS this month
- Top 16 Chinese iPhoneys
- Pimp your ride: Cool car technology
- Laptop stolen from McCain campaign
- Cisco, Microsoft roll out server, networking appliance
Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:Application Performance Solutions | App Performance | Networking Solution | SafeGuard Enterprise Solution Center | SOA | Value of WDS
With targeted phishing attacks on the rise, it’s no surprise that cybercriminals are doing their research and aiming at those with the most to lose – executives.
According to security vendor MessageLabs, targeted phishing – e-mail scams that are directed at certain employees at an organization or members of a group, also called spear phishing – has grown significantly in the past two years. In 2005, the company would see roughly two targeted phishing e-mails per week; the company now sees roughly 10 per day, according to Paul Wood, senior analyst with MessageLabs.
Earlier this year, the company spotted two outbreaks of what is now being called whaling. In these scams, phishers find the name and e-mail address of a company’s top executive or handful of executives – often information freely available on the Web – and craft an e-mail specific to those people and their role at the company. The e-mail attempts to lure the executives into clicking on a link that will bring them to a Web site where malware is downloaded onto their machine that can copy keystrokes or ferret out sensitive information or corporate secrets, according to Wood. The e-mails purport to be from the Better Business Bureau to alert the executives of a complaint posted on a Web site, or from a recruitment company or information about an invoice, Wood says.
In June, MessageLabs’ hosted e-mail security service caught 514 e-mails bound for its customers all targeted at C-level executives in various organizations in a two-hour period. In September another blast consisted of 1,100 whaling attacks within 15 hours. The company believes the same organization is behind the blasts.
What’s unique about whaling is its reliance on research and social engineering. Traditionally spam, and to some extent phishing, depends on reaching the greatest number of people with the smallest amount of effort, considering the response rate to these e-mail abuses tends to be miniscule but still enough to make the practice worth it. With whaling, the sender must do some upfront research about the target as well as the subject in order to craft an e-mail that sounds convincing, says Wood.
“It’s really the social engineering that has tipped the balance now; now [phishers] are becoming much more technologically sophisticated as well as applying psychology to what they’re doing,” he says. “Now they conduct a lot of research before they attack, so it becomes much more difficult to recognize those attacks.”

The Vista era of Windows is here. Yet most organizations will retain Windows XP alongside new Vista...
Vulnerability Management For DummiesDownload this concise book "Vulnerability Management for Dummies," to learn about the simple steps...
Security Considerations When Deploying Remote Access SolutionsEffective network security is most successful when you use a layered approach, with multiple...

The Vista era of Windows is here. Yet most organizations will retain Windows XP alongside new Vista...
Turning information into a Competitive AdvantageCompanies today are realizing that competitive advantage is harder to sustain when based solely on...
PoE Plus: Impact on the PoE MarketThe standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Discover why Unified Threat Management Firewalls are ready for the enterprise today. High...
The Evolution of Network SecurityWe have so many holes punched in our firewalls today that many industry insiders question the value...
The self-managed networkWe aren't there yet, but advances in network and systems management tools are making it possible to...
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment