Martin Hořický
Similar to phishing attacks, victims are lured into disclosing their personal information, only instead of e-mail communication, SMS text messages are used. Attackers try to obtain sensitive data from users, which they then try to dispose of. Incoming SMS messages often pretend to come from the bank where the user has a bank account and are trying to steal bank details.
The target groups are usually employees of the companies concerned, customers of a particular institution, subscribers to mobile networks, university students or residents of the area. The attacker's disguise is usually related to the institution they are trying to access.
OUR APPROACH AND SOLUTIONS
Social engineering is usually the first step to infiltrating a company. At BDO, we implement smishing and phishing campaigns, the aim of which is to verify what proportion of target users fall victim to social engineering.
It is a form of attack where the attacker tries to lure user´s data by using a fraudulent e-mail message or a page that resembles a familiar website or e-mail address. When the attack is successfully carried out, login data or even access data to bank accounts is stolen. The best targeted group is the elderly, who do not have sufficient knowledge in Internet security and are easily lured by fraudulent e-mails.
Most often, phishing attacks can be associated with topics such as:
However, there are ways to effectively defend against phishing attacks. In addition to properly set mail hygiene in the company (allowed and forbidden mail servers, spam filters, content filters, etc.), it is very important to ensure that employees are regularly trained in cybersecurity, thus ensuring their vigilance.
OUR APPROACH AND SOLUTIONS
Social engineering is usually the first step to infiltrating a company. At BDO, we implement smishing and phishing campaigns, the aim of which is to verify how many of target users fall victim to social engineering.
Campaign steps:
Martin Hořický