Taming the ever-evolving phish risk

Opinion
Feb 2, 20052 mins

* Phishing attacks evolve

Security vendors and anti-phishing organizations report that such targeted phishing attacks on enterprise networks – sometimes called spear phishing – are on the rise. What’s at stake is not only the theft of personal financial information, but also loss of intellectual property, trade secrets and other highly sensitive information.

Taming the ever-evolving phish risk

By Cara Garretson

At an industry conference last year, the head of security for a state port authority told of how a phisher – possibly a current or former employee, or someone in cahoots with one – bluffed his way onto the corporate network by first spoofing an internal e-mail address. The ploy, apparently designed to elicit application passwords, got responses from about 50 workers before one called the IT department to raise a red flag, according to a conference attendee.

Once a phisher has successfully spoofed a corporate e-mail address, the damage that can ensue is substantial, experts say. In the port authority case, the phisher could have found a number of ways into the corporate network once he convinced employees that his e-mail actually came from a co-worker. For example, the phisher could have attached a key-logging program to the e-mail that recorded an unsuspecting employee’s password while he was accessing an application, thus granting the phisher access as well. Officials with the port authority won’t comment further on the incident.

Security vendors and anti-phishing organizations report that such targeted phishing attacks on enterprise networks – sometimes called spear phishing – are on the rise. What’s at stake is not only the theft of personal financial information, but also loss of intellectual property, trade secrets and other highly sensitive information.

“Thieves have discovered a gold mine, and they’re not going to let up until the technology gets better,” says Avivah Litan, a vice president and research director with Gartner.

These targeted phishing attacks on companies take much more work on the part of the phisher than simply sending out thousands of e-mails that spoof eBay in hopes of catching a handful of consumer victims. But experts say that doesn’t mean companies should assume it won’t happen to them because phishers can do much damage with very little purloined information.

For the full story, please go to:

https://www.nwfusion.com/news/2005/013105phishing.html?nlt

For questions or comments regarding this newsletter’s content, contact Newsletter Editor Jeff Caruso at mailto:jcaruso@nww.com