
It’s summertime – you’re off on a fishing holiday. Meanwhile someone could be about to engage in their own phishing trip – more precisely spear-phishing. This is a targeted phishing attack intended to look credible to its recipient.
No-one is immune. The more senior you are the
more likely you are to be targeted by a spear-phisher or
be used as bait to target a junior member of staff.
Usually the spear-phisher aims to obtain information such as password and banking details to steal money or hold a firm to ransom. They may also seek to install malware on your computer systems.
Malware, as many of you know to your cost, can cause computer systems to grind to a halt. In seconds your business could be non-operational and worse, company data and confidential client data compromised – possibly irrevocably. Law firms are especially attractive targets.
A Security Breaches Survey by HM Government in 2015 revealed that 74% of small businesses and 90% of large organisations suffered a security breach in 2015. Symantec has described attackers as: “bigger, bolder and faster.”
How the spear-phisher operates
To be successful a spear-phisher needs to gather information from a variety of sources so that he can send a communication that appears to be from a trustworthy source. This is the reconnaissance phase.
Let’s say you’re a partner in a law firm and the firm’s website has your photo, email address and some information about you. You might also be on LinkedIn and even Facebook where perhaps you haven’t blocked non-Friends from seeing your account or you comment on the Wall of a Friend who hasn’t secured their Wall. Such disparate information can be fodder for the cyber criminal.
Construction and delivery of a Spear-phishing attack
Armed with this information they can send a personalised email which could be as simple as “Are you at your desk?”
Because it seems to come from someone you know, you might innocently respond and engage in further dialogue. This is where the cyber criminal has potentially got you hooked. So when they then send a link or an attachment or make a request that seems genuine if you take the bait then inadvertently you have enabled the cyber criminal to deliver their payload.
Don’t be a target!
There are some really simple steps that you and your firm can take to ensure you don’t become a target. For example:
have a cyber security strategy, implement it and monitor it regularly
update software regularly
install firewalls and use email cleansing
use a contact form rather than having your email address on your business website
be cautious how much information you share on social media sites
have robust anti-malware at the desktop
back-up data - this can save your business and your firm's reputation if a spear-phisher manages to install malware on your computer systems
educate your staff about cyber crime and cyber security via regular training
Something that Alchemy Systems advises on is simulating spear phishing attacks which enable law firms to rapidly identify risk.
So don’t be spear-phished !
Identify your areas of risk then develop and
implement a cyber security strategy.
Alchemy Systems have 19 years of IT systems experience and are a Microsoft Partner. Alchemy Systems Designs, Supplies, Installs, Supports and Protects clients’ IT systems. The legal sector has always been a strategic focus. Our staff are experienced in the specific needs and challenges of law firms from service desk to strategy to protection services.
Tel. 0330-043-080198 email. sales@alchemysys.co.uk