1
00:00:00,000 --> 00:00:00,833
In this lesson,

2
00:00:00,833 --> 00:00:02,880
we're going to cover phishing attacks.

3
00:00:02,880 --> 00:00:05,610
We will discuss the different types of phishing attacks,

4
00:00:05,610 --> 00:00:08,223
including phishing, vishing, smishing,

5
00:00:09,600 --> 00:00:14,070
whaling, spear phishing, and business email compromise.

6
00:00:14,070 --> 00:00:16,079
First, we have phishing.

7
00:00:16,079 --> 00:00:18,240
Phishing is an attack that involves sending

8
00:00:18,240 --> 00:00:21,660
fraudulent emails that appear to be from a reputable source,

9
00:00:21,660 --> 00:00:23,670
with the aim of convincing individuals

10
00:00:23,670 --> 00:00:25,170
to reveal personal information

11
00:00:25,170 --> 00:00:27,240
such as passwords or credit card numbers.

12
00:00:27,240 --> 00:00:30,480
These attacks often lure victims with a sense of urgency

13
00:00:30,480 --> 00:00:33,660
or fear, and will prompt them to click on malicious links

14
00:00:33,660 --> 00:00:37,830
or attachments that lead to the theft of sensitive data.

15
00:00:37,830 --> 00:00:40,470
Phishing is like a fisherman who casts a wide net

16
00:00:40,470 --> 00:00:44,250
into the sea in hopes to catch as many fish as possible.

17
00:00:44,250 --> 00:00:47,250
Cyber criminals send out mass email campaigns

18
00:00:47,250 --> 00:00:49,560
to hundreds of thousands of email addresses

19
00:00:49,560 --> 00:00:52,290
while trying to appear to be from a trusted source

20
00:00:52,290 --> 00:00:55,350
in hopes that some recipients will fall for the tricks

21
00:00:55,350 --> 00:00:56,850
and click on a malicious link,

22
00:00:56,850 --> 00:00:59,430
or providing system information.

23
00:00:59,430 --> 00:01:01,320
For example, if you click on a link

24
00:01:01,320 --> 00:01:02,970
that looks like it's from Google,

25
00:01:02,970 --> 00:01:06,300
asking you to verify your identity by logging in,

26
00:01:06,300 --> 00:01:08,790
and you enter your email address and password,

27
00:01:08,790 --> 00:01:11,190
and then the attacker can capture those credentials

28
00:01:11,190 --> 00:01:13,380
that you just entered and then use them later on

29
00:01:13,380 --> 00:01:15,480
for their own malicious purposes.

30
00:01:15,480 --> 00:01:17,310
Second, we have spear phishing.

31
00:01:17,310 --> 00:01:20,250
Spear phishing is a more targeted form of phishing

32
00:01:20,250 --> 00:01:22,950
that is used by cyber criminals who are more tightly focused

33
00:01:22,950 --> 00:01:26,520
on a specific group of individuals or organizations.

34
00:01:26,520 --> 00:01:29,040
These attackers will first gather detailed information

35
00:01:29,040 --> 00:01:31,260
about their targets in order to make

36
00:01:31,260 --> 00:01:33,420
their spear phishing attack more personalized

37
00:01:33,420 --> 00:01:34,530
and convincing.

38
00:01:34,530 --> 00:01:37,170
This means that spear phishing is more targeted

39
00:01:37,170 --> 00:01:39,300
and more sophisticated than phishing,

40
00:01:39,300 --> 00:01:42,000
since it uses a higher level of customization

41
00:01:42,000 --> 00:01:44,250
to make detecting this type of attack harder,

42
00:01:44,250 --> 00:01:46,950
and the attack itself potentially more damaging.

43
00:01:46,950 --> 00:01:49,860
At its core, spear phishing is just like phishing,

44
00:01:49,860 --> 00:01:52,710
but more targeted, and has a higher success rate

45
00:01:52,710 --> 00:01:54,810
in convincing users that the email they receive

46
00:01:54,810 --> 00:01:55,860
is really genuine.

47
00:01:55,860 --> 00:01:58,290
For example, if I send an email to 1 million

48
00:01:58,290 --> 00:02:01,440
random Americans and try to impersonate Bank of America

49
00:02:01,440 --> 00:02:03,870
in that email, and told the email recipients

50
00:02:03,870 --> 00:02:05,550
that their account was compromised

51
00:02:05,550 --> 00:02:07,620
and they need to click a link in the email

52
00:02:07,620 --> 00:02:09,720
to reset the password to secure their account,

53
00:02:09,720 --> 00:02:12,540
that may work out pretty well for me as an attacker

54
00:02:12,540 --> 00:02:14,580
since there are 68 million Americans

55
00:02:14,580 --> 00:02:16,080
with a Bank of America account

56
00:02:16,080 --> 00:02:19,530
out of the total population of 340 million Americans.

57
00:02:19,530 --> 00:02:22,980
This means that out of every five Americans,

58
00:02:22,980 --> 00:02:25,890
one of them is a Bank of America customer.

59
00:02:25,890 --> 00:02:28,050
But if we can conduct this campaign,

60
00:02:28,050 --> 00:02:30,870
we would classify it as phishing and not spear phishing

61
00:02:30,870 --> 00:02:33,870
since I just sent emails to a million random Americans

62
00:02:33,870 --> 00:02:36,570
in hope that they were a Bank of America customer.

63
00:02:36,570 --> 00:02:38,520
Unfortunately, for the attacker though,

64
00:02:38,520 --> 00:02:40,560
if they sent this to me, it wouldn't work

65
00:02:40,560 --> 00:02:43,470
because I have never been a Bank of America customer,

66
00:02:43,470 --> 00:02:45,120
so I would instantly recognize this

67
00:02:45,120 --> 00:02:47,850
as an impersonation-based phishing campaign.

68
00:02:47,850 --> 00:02:50,880
Now, on the other hand, if I had my personal bank account

69
00:02:50,880 --> 00:02:54,660
at a financial institution named Dion Savings and Loan,

70
00:02:54,660 --> 00:02:57,780
who suffered a data breach over the past year or so

71
00:02:57,780 --> 00:02:59,610
that caused their customers' names

72
00:02:59,610 --> 00:03:02,010
and emails to be posted on the dark web,

73
00:03:02,010 --> 00:03:05,880
then an attacker could pick 500 people from that list

74
00:03:05,880 --> 00:03:08,310
and send them a well-crafted and targeted

75
00:03:08,310 --> 00:03:10,800
spear phishing email trying to trick them

76
00:03:10,800 --> 00:03:13,320
into resetting the password or disclosing

77
00:03:13,320 --> 00:03:15,330
other sensitive information to the attacker.

78
00:03:15,330 --> 00:03:17,250
Now, notice a difference here.

79
00:03:17,250 --> 00:03:19,890
Phishing is the widest net, and the attacker

80
00:03:19,890 --> 00:03:22,470
is essentially trying a spray and pray approach

81
00:03:22,470 --> 00:03:24,930
by sending out 1 million untargeted emails

82
00:03:24,930 --> 00:03:27,570
in hopes that some of those people have an account

83
00:03:27,570 --> 00:03:31,170
with the impersonated bank, but with spear phishing,

84
00:03:31,170 --> 00:03:33,750
we are only targeting people who are known

85
00:03:33,750 --> 00:03:36,270
to have a connection with this specific organization,

86
00:03:36,270 --> 00:03:39,420
and the size and scope of our attack is much more limited.

87
00:03:39,420 --> 00:03:42,630
The spear phishing emails that the attacker sends

88
00:03:42,630 --> 00:03:45,090
is tailored to recipients, and this makes it harder

89
00:03:45,090 --> 00:03:47,700
to recognize it as a potential attack vector.

90
00:03:47,700 --> 00:03:50,430
It's almost as if the hunter has been studying

91
00:03:50,430 --> 00:03:52,140
their prey's habits and behaviors

92
00:03:52,140 --> 00:03:54,990
before they craft their attack and strike at their prey.

93
00:03:54,990 --> 00:03:57,480
Third, we have whaling.

94
00:03:57,480 --> 00:03:59,250
Whaling is a form of spear phishing

95
00:03:59,250 --> 00:04:03,480
that targets high profile individuals like CEOs or CFOs.

96
00:04:03,480 --> 00:04:06,300
This is called whaling because an attacker

97
00:04:06,300 --> 00:04:09,120
isn't trying to catch the little fish in the organization,

98
00:04:09,120 --> 00:04:12,000
but instead, they want to catch one of the executives,

99
00:04:12,000 --> 00:04:14,970
board members, or higher level managers in the company,

100
00:04:14,970 --> 00:04:17,820
since the rewards are potentially much greater.

101
00:04:17,820 --> 00:04:19,740
The challenge with whaling is that it takes

102
00:04:19,740 --> 00:04:21,930
a lot more preparation, effort,

103
00:04:21,930 --> 00:04:24,030
and precision to pull off this type of attack.

104
00:04:24,030 --> 00:04:26,640
If they're able to trick one of these executives, though,

105
00:04:26,640 --> 00:04:28,680
it can lead to massive financial gains,

106
00:04:28,680 --> 00:04:30,720
since these people usually have the ability

107
00:04:30,720 --> 00:04:32,610
to approve large fund transference

108
00:04:32,610 --> 00:04:34,170
on behalf of their organization.

109
00:04:34,170 --> 00:04:37,890
Often, whaling is used as the first part of an attack

110
00:04:37,890 --> 00:04:40,770
so that the attacker can take over the executives account

111
00:04:40,770 --> 00:04:42,540
and use it for following attacks

112
00:04:42,540 --> 00:04:44,820
across the rest of their organization.

113
00:04:44,820 --> 00:04:47,790
Fourth, we have business email compromise.

114
00:04:47,790 --> 00:04:50,520
A business email compromise, or BEC,

115
00:04:50,520 --> 00:04:52,470
is a sophisticated type of phishing attack

116
00:04:52,470 --> 00:04:54,030
that usually targets businesses

117
00:04:54,030 --> 00:04:57,000
by using one of their internal email accounts

118
00:04:57,000 --> 00:04:59,040
to get other employees to perform

119
00:04:59,040 --> 00:05:03,000
some kind of malicious action on behalf of the attacker.

120
00:05:03,000 --> 00:05:05,970
A business email compromise involves taking over

121
00:05:05,970 --> 00:05:08,280
a legitimate business email account

122
00:05:08,280 --> 00:05:11,340
through social engineering or cyber intrusion techniques

123
00:05:11,340 --> 00:05:14,010
to conduct unauthorized fund transfers,

124
00:05:14,010 --> 00:05:17,370
redirect payments, or again, steal sensitive information.

125
00:05:17,370 --> 00:05:19,320
With a business email compromise,

126
00:05:19,320 --> 00:05:21,690
the attacker impersonates a senior executive

127
00:05:21,690 --> 00:05:25,410
or a trusted partner and sends seemingly legitimate requests

128
00:05:25,410 --> 00:05:28,740
for wire transfers or confidential data

129
00:05:28,740 --> 00:05:31,800
to employees in finance or human resources.

130
00:05:31,800 --> 00:05:34,380
The malicious actor relies on the trust

131
00:05:34,380 --> 00:05:36,420
established by the compromised account

132
00:05:36,420 --> 00:05:40,230
to deceive the recipient into taking the desired action,

133
00:05:40,230 --> 00:05:43,380
which often leads to significant financial losses

134
00:05:43,380 --> 00:05:46,290
and data breaches for the targeted organization.

135
00:05:46,290 --> 00:05:50,010
According to the FBI's Internet Crime Complaint Center,

136
00:05:50,010 --> 00:05:52,650
there was a 14.5% increase

137
00:05:52,650 --> 00:05:55,560
in business email compromise attacks last year,

138
00:05:55,560 --> 00:05:59,760
and this cost businesses 2.7 billion in losses.

139
00:05:59,760 --> 00:06:03,390
So business email compromises are definitely a significant

140
00:06:03,390 --> 00:06:06,000
and costly threat that you need to be aware of.

141
00:06:06,000 --> 00:06:07,770
Fifth, we have vishing.

142
00:06:07,770 --> 00:06:10,080
Vishing, or voice phishing is an attack

143
00:06:10,080 --> 00:06:11,970
where an attacker tricks their victims

144
00:06:11,970 --> 00:06:14,880
into sharing personal or financial information

145
00:06:14,880 --> 00:06:16,200
over the phone.

146
00:06:16,200 --> 00:06:19,320
The attackers often impersonate legitimate organizations,

147
00:06:19,320 --> 00:06:21,480
such as banks or government agencies,

148
00:06:21,480 --> 00:06:24,660
and use social engineering techniques to manipulate victims

149
00:06:24,660 --> 00:06:27,480
into providing sensitive or confidential data.

150
00:06:27,480 --> 00:06:30,180
In general, most people tend to be friendly,

151
00:06:30,180 --> 00:06:32,820
and I have personally found that it is much easier

152
00:06:32,820 --> 00:06:34,800
to trick people into providing their information

153
00:06:34,800 --> 00:06:36,720
over the phone than over an email,

154
00:06:36,720 --> 00:06:39,480
which makes vishing pretty effective.

155
00:06:39,480 --> 00:06:42,720
A simple example of vishing might involve an attacker

156
00:06:42,720 --> 00:06:45,090
pretending to be a bank representative

157
00:06:45,090 --> 00:06:47,400
with the aim of tricking you into revealing

158
00:06:47,400 --> 00:06:49,470
your personal banking information,

159
00:06:49,470 --> 00:06:51,450
or performing some sort of action

160
00:06:51,450 --> 00:06:53,250
that will compromise your security.

161
00:06:53,250 --> 00:06:54,929
Sixth, we have smishing.

162
00:06:54,929 --> 00:06:57,240
Smishing, or SMS phishing, is an attack

163
00:06:57,240 --> 00:06:59,160
that involves the use of text messages

164
00:06:59,160 --> 00:07:00,630
to trick individuals into providing

165
00:07:00,630 --> 00:07:02,010
their personal information.

166
00:07:02,010 --> 00:07:04,590
These text messages will often contain a link

167
00:07:04,590 --> 00:07:07,740
to a fraudulent website or a phone number to call,

168
00:07:07,740 --> 00:07:09,510
while attempting to bait the victim

169
00:07:09,510 --> 00:07:12,420
into action by creating a sense of urgency.

170
00:07:12,420 --> 00:07:15,660
So remember, phishing is not just a specific attack,

171
00:07:15,660 --> 00:07:18,300
but it is really an entire category

172
00:07:18,300 --> 00:07:21,930
of social engineering attacks that include phishing,

173
00:07:21,930 --> 00:07:25,602
spear phishing, whaling, business email compromise,

174
00:07:25,602 --> 00:07:28,380
vishing, and smishing to attempt to trick

175
00:07:28,380 --> 00:07:31,470
an organization's user to revealing sensitive information

176
00:07:31,470 --> 00:07:33,150
or performing actions that might

177
00:07:33,150 --> 00:07:35,820
compromise your enterprise's security.

178
00:07:35,820 --> 00:07:38,490
Phishing is a general method of tricking individuals

179
00:07:38,490 --> 00:07:41,820
into providing sensitive information or downloading malware

180
00:07:41,820 --> 00:07:44,850
by disguising it as a trustworthy entity.

181
00:07:44,850 --> 00:07:47,700
Spear phishing is a more targeted version of phishing

182
00:07:47,700 --> 00:07:49,770
where the attacker customizes the bait

183
00:07:49,770 --> 00:07:52,590
for a specific individual or organization.

184
00:07:52,590 --> 00:07:54,660
Whaling is similar to spear phishing,

185
00:07:54,660 --> 00:07:57,390
but specifically targets high profile individuals

186
00:07:57,390 --> 00:08:00,480
like CEOs or CFOs by attempting to trick them

187
00:08:00,480 --> 00:08:02,340
into revealing sensitive data

188
00:08:02,340 --> 00:08:05,190
or initiating unauthorized transactions.

189
00:08:05,190 --> 00:08:08,040
Business email compromise, or BEC,

190
00:08:08,040 --> 00:08:10,470
involves impersonating or compromising

191
00:08:10,470 --> 00:08:13,980
an executive's email account to deceive the organization

192
00:08:13,980 --> 00:08:16,020
to making unauthorized transfers

193
00:08:16,020 --> 00:08:18,330
or revealing sensitive information.

194
00:08:18,330 --> 00:08:21,300
Vishing, which is short for voice phishing,

195
00:08:21,300 --> 00:08:23,730
attempts to trick victims into providing

196
00:08:23,730 --> 00:08:26,070
sensitive information over the phone.

197
00:08:26,070 --> 00:08:29,670
Finally, smishing uses deceptive text messages

198
00:08:29,670 --> 00:08:31,800
to lure victims into downloading malware

199
00:08:31,800 --> 00:08:34,110
or revealing personal data.

200
00:08:34,110 --> 00:08:37,110
By understanding these different types of threats,

201
00:08:37,110 --> 00:08:39,900
you can be well positioned to implement countermeasures

202
00:08:39,900 --> 00:08:42,570
to protect yourself and your organization

203
00:08:42,570 --> 00:08:43,620
in the digital realm.

