I'm looking for some content ideas and for things that I may assume people understand/are aware of with reference to phishing and social engineering attacks, but really aren't. I'm constantly surrounded by phishing and social engineering information and love to share my knowledge, but sometimes assume too much about what folks already know.
Likewise, are there things you learned that blew your mind?
For example, a very popular Business Email Compromise attack (BEC) involves redirecting escrow funds to an attacker-owned bank account. This is usually a product of a successful credential phishing attack, but the attacker stay quiet until the account number is sent for the funds transfer, they then follow up quickly with an "account correction" email from the actual victims email account, thus sending the funds to the new account. Attackers may stay silent for a month or two just monitoring activity and waiting to send that message. In DC I was doing some talks to some House subcommittees and a Secret Service guy said he just worked a case like that where $500k was redirected. A decent payday for a month or two of work :)
A lot of folks I talk to don't know about this type of attack, or the fact that some cyber insurance won't cover this as it was an individual that transferred the funds (they try to put it under the "crime" policy instead, which also may not cover the "willful act" of the employee transferring the funds.)
submitted by [comments]
SOCIAL SHARE CARD GENERATOR