1
00:00:00,090 --> 00:00:00,960
In this lesson,

2
00:00:00,960 --> 00:00:03,840
we'll talk about how you can prevent phishing attacks

3
00:00:03,840 --> 00:00:06,240
from occurring in your enterprise networks.

4
00:00:06,240 --> 00:00:07,890
Now, these days, phishing attacks

5
00:00:07,890 --> 00:00:11,070
have become one of the most persuasive attack vectors

6
00:00:11,070 --> 00:00:12,660
used by attackers.

7
00:00:12,660 --> 00:00:14,670
These phishing attacks and campaigns

8
00:00:14,670 --> 00:00:16,470
focuses on tricking individuals

9
00:00:16,470 --> 00:00:18,270
into revealing sensitive information

10
00:00:18,270 --> 00:00:20,850
that can lead to significant financial loss

11
00:00:20,850 --> 00:00:23,250
and data breaches in your organization.

12
00:00:23,250 --> 00:00:25,770
However, by implementing the right strategies

13
00:00:25,770 --> 00:00:28,710
and providing user security awareness training,

14
00:00:28,710 --> 00:00:31,020
the threat of a successful phishing campaign

15
00:00:31,020 --> 00:00:34,170
against your organization can be mitigated effectively.

16
00:00:34,170 --> 00:00:36,000
An anti-phishing campaign

17
00:00:36,000 --> 00:00:39,450
is an essential user security awareness training tool

18
00:00:39,450 --> 00:00:41,610
that can be used to educate individuals

19
00:00:41,610 --> 00:00:42,990
about the risk of phishing

20
00:00:42,990 --> 00:00:46,440
and how to best identify potential phishing attempts.

21
00:00:46,440 --> 00:00:48,300
These anti-phishing campaigns

22
00:00:48,300 --> 00:00:51,900
typically involve some training being provided to your users

23
00:00:51,900 --> 00:00:53,430
and then the performance

24
00:00:53,430 --> 00:00:56,520
of a simulated phishing campaign against your organization

25
00:00:56,520 --> 00:00:57,960
by an outside contractor

26
00:00:57,960 --> 00:01:00,180
or software-as-a-service platform

27
00:01:00,180 --> 00:01:03,600
that can provide your users with some practical experience

28
00:01:03,600 --> 00:01:07,560
in spotting and responding to potential phishing attempts.

29
00:01:07,560 --> 00:01:10,080
To help prevent phishing, your organization

30
00:01:10,080 --> 00:01:13,050
should regularly conduct user security awareness training

31
00:01:13,050 --> 00:01:16,590
that contains coverage of the various phishing techniques,

32
00:01:16,590 --> 00:01:19,290
such as phishing, spear phishing, whaling,

33
00:01:19,290 --> 00:01:22,260
business email compromise, phishing and smishing,

34
00:01:22,260 --> 00:01:25,260
along with other relevant cyber threats and attacks

35
00:01:25,260 --> 00:01:27,390
that may affect your organization.

36
00:01:27,390 --> 00:01:29,310
This training should also highlight

37
00:01:29,310 --> 00:01:31,680
the common characteristics of phishing emails,

38
00:01:31,680 --> 00:01:35,310
including generic greetings, spelling and grammar errors,

39
00:01:35,310 --> 00:01:37,380
and spoofed email addresses.

40
00:01:37,380 --> 00:01:39,060
These security training programs

41
00:01:39,060 --> 00:01:41,400
and their associated anti-phishing campaigns

42
00:01:41,400 --> 00:01:42,960
should be an ongoing effort

43
00:01:42,960 --> 00:01:46,470
since cybersecurity threats are continually evolving.

44
00:01:46,470 --> 00:01:49,710
As part of these anti-phishing campaigns, your organization

45
00:01:49,710 --> 00:01:52,320
should also provide in-depth remedial training

46
00:01:52,320 --> 00:01:54,060
for any of your users who fall victim

47
00:01:54,060 --> 00:01:56,010
to the simulated phishing emails.

48
00:01:56,010 --> 00:01:58,950
Now, the best way to prevent being the victim

49
00:01:58,950 --> 00:02:00,240
of a phishing attack

50
00:02:00,240 --> 00:02:03,930
is to be able to recognize a potential phishing attempt.

51
00:02:03,930 --> 00:02:06,330
There are some commonly used key indicators

52
00:02:06,330 --> 00:02:08,130
that are associated with phishing attacks,

53
00:02:08,130 --> 00:02:11,070
including urgency, unusual requests,

54
00:02:11,070 --> 00:02:14,310
mismatched URLs, strange email addresses,

55
00:02:14,310 --> 00:02:16,830
and poor spelling or grammar being used

56
00:02:16,830 --> 00:02:19,470
in the emails received from an attacker.

57
00:02:19,470 --> 00:02:21,600
First, we have urgency.

58
00:02:21,600 --> 00:02:24,240
Phishing emails often create a sense of urgency

59
00:02:24,240 --> 00:02:27,150
by prompting the recipient to act immediately.

60
00:02:27,150 --> 00:02:29,640
For example, if a user receives an email

61
00:02:29,640 --> 00:02:32,820
that states that they won a brand-new iPhone

62
00:02:32,820 --> 00:02:35,250
but must click on a link to claim their products

63
00:02:35,250 --> 00:02:38,190
within the next four hours or the offer will expire,

64
00:02:38,190 --> 00:02:41,100
this is usually an indication of a phishing attack.

65
00:02:41,100 --> 00:02:43,680
Second, we have unusual requests.

66
00:02:43,680 --> 00:02:46,230
If you receive an email requesting sensitive information,

67
00:02:46,230 --> 00:02:48,750
such as passwords or credit card numbers,

68
00:02:48,750 --> 00:02:51,660
you should treat these emails with a lot of suspicion.

69
00:02:51,660 --> 00:02:53,520
Remember, your technical support team

70
00:02:53,520 --> 00:02:54,630
will never contact you

71
00:02:54,630 --> 00:02:57,090
asking you for your login information,

72
00:02:57,090 --> 00:02:59,700
and your bank will never ask you for your credit card number

73
00:02:59,700 --> 00:03:01,920
over an email or a phone call.

74
00:03:01,920 --> 00:03:03,510
Both of these kinds of requests

75
00:03:03,510 --> 00:03:07,020
should set off an alarm bell any time you see them.

76
00:03:07,020 --> 00:03:10,530
Third, we have a mismatched URL.

77
00:03:10,530 --> 00:03:13,470
Did you know, when you see a website link in an email,

78
00:03:13,470 --> 00:03:14,700
it doesn't always take you

79
00:03:14,700 --> 00:03:16,770
to the place that it says it will?

80
00:03:16,770 --> 00:03:19,650
When you're looking at an HTML-based email,

81
00:03:19,650 --> 00:03:22,560
the words you are reading are called the display text,

82
00:03:22,560 --> 00:03:24,600
but the underlying URL of the web link

83
00:03:24,600 --> 00:03:26,340
could be set to anything you want.

84
00:03:26,340 --> 00:03:30,090
For example, I can send you an email saying, "Click here"

85
00:03:30,090 --> 00:03:32,670
and the words "Click here" are not a URL,

86
00:03:32,670 --> 00:03:34,710
but the URL link to those words

87
00:03:34,710 --> 00:03:38,430
might be for the homepage of diontraining.com.

88
00:03:38,430 --> 00:03:39,900
Alternatively, phishing attacks

89
00:03:39,900 --> 00:03:42,090
that rely on brand impersonation

90
00:03:42,090 --> 00:03:45,870
often says one thing like paypal.com/login,

91
00:03:45,870 --> 00:03:46,950
but when you click it,

92
00:03:46,950 --> 00:03:49,140
you'll be redirected to a malicious URL

93
00:03:49,140 --> 00:03:53,490
of paypal.hacked.xyz or something like that.

94
00:03:53,490 --> 00:03:57,270
To check if the text-based link matches the underlying URL,

95
00:03:57,270 --> 00:03:59,220
you should always hover your mouse

96
00:03:59,220 --> 00:04:01,890
over the link in the email for a few seconds,

97
00:04:01,890 --> 00:04:04,110
and this will reveal the actual URL

98
00:04:04,110 --> 00:04:05,970
that the link is connected to.

99
00:04:05,970 --> 00:04:09,150
If the text-based URL, like paypal.com,

100
00:04:09,150 --> 00:04:12,090
doesn't match the underlying URL shown

101
00:04:12,090 --> 00:04:13,560
when you hover over the link,

102
00:04:13,560 --> 00:04:16,079
then it most likely is an email

103
00:04:16,079 --> 00:04:18,839
that is trying to attempt a phishing attack.

104
00:04:18,839 --> 00:04:20,880
While this is an old and simple trick,

105
00:04:20,880 --> 00:04:23,010
users in our modern enterprise network

106
00:04:23,010 --> 00:04:25,860
still fall for this technique time and time again,

107
00:04:25,860 --> 00:04:28,710
so you and your users must always practice caution

108
00:04:28,710 --> 00:04:31,650
when clicking on links inside of an email.

109
00:04:31,650 --> 00:04:34,110
Fourth, we have email addresses.

110
00:04:34,110 --> 00:04:35,520
When you receive an email,

111
00:04:35,520 --> 00:04:37,860
you should always check the sender's email.

112
00:04:37,860 --> 00:04:40,440
Just like a URL being displayed in the email,

113
00:04:40,440 --> 00:04:43,620
the email address you see is just a text-based display name

114
00:04:43,620 --> 00:04:46,620
and not the actual email address that sent the message.

115
00:04:46,620 --> 00:04:48,930
If you want to see the real email address,

116
00:04:48,930 --> 00:04:51,750
you can either hover over the display email address

117
00:04:51,750 --> 00:04:54,240
or double click the display email address

118
00:04:54,240 --> 00:04:56,610
to see the underlying email address.

119
00:04:56,610 --> 00:04:58,410
If the real email address

120
00:04:58,410 --> 00:05:01,170
and the displayed email address don't match,

121
00:05:01,170 --> 00:05:03,360
then the email should be treated as suspicious

122
00:05:03,360 --> 00:05:06,390
and possibly part of a phishing campaign.

123
00:05:06,390 --> 00:05:09,390
Similarly, if the organization's official domain

124
00:05:09,390 --> 00:05:11,430
is not used by the email,

125
00:05:11,430 --> 00:05:15,060
or if the email address is overly complicated,

126
00:05:15,060 --> 00:05:18,330
both of these are good signs that the email might be part

127
00:05:18,330 --> 00:05:20,790
of an attempted phishing attack.

128
00:05:20,790 --> 00:05:23,490
This is probably one of the most commonly used techniques

129
00:05:23,490 --> 00:05:26,220
in phishing emails, and I see them

130
00:05:26,220 --> 00:05:28,800
at least a few times a day in my inbox.

131
00:05:28,800 --> 00:05:30,360
Whether the email is from a person

132
00:05:30,360 --> 00:05:32,910
claiming to be a Microsoft tech support,

133
00:05:32,910 --> 00:05:35,820
PayPal, the Amazon customer support team,

134
00:05:35,820 --> 00:05:38,160
or a popular financial institution,

135
00:05:38,160 --> 00:05:40,800
when I hover over the email and see that the email

136
00:05:40,800 --> 00:05:45,800
is something like mr.weirdo578@yahoo.com,

137
00:05:46,080 --> 00:05:48,510
I know this is clearly a phishing attempt,

138
00:05:48,510 --> 00:05:51,600
and I mark the email as spam and move on with my day

139
00:05:51,600 --> 00:05:54,060
without clicking on any of the links in the email.

140
00:05:54,060 --> 00:05:57,990
Fifth and finally, we have poor grammar and spelling.

141
00:05:57,990 --> 00:06:00,510
Most professional organizations

142
00:06:00,510 --> 00:06:02,190
typically proofread their emails

143
00:06:02,190 --> 00:06:04,320
before sending them out to customers.

144
00:06:04,320 --> 00:06:06,780
If an email has a lot of broken English,

145
00:06:06,780 --> 00:06:09,420
poor grammar, or numerous spelling errors,

146
00:06:09,420 --> 00:06:12,420
it is likely to be part of a phishing campaign.

147
00:06:12,420 --> 00:06:13,620
These days, though,

148
00:06:13,620 --> 00:06:15,630
many attackers can write properly worded emails

149
00:06:15,630 --> 00:06:19,200
without any grammar or spelling errors relatively easy

150
00:06:19,200 --> 00:06:23,130
using generative AI, products like ChatGPT and Google Bard,

151
00:06:23,130 --> 00:06:24,180
to avoid being caught

152
00:06:24,180 --> 00:06:26,070
by this commonly sought after indicator

153
00:06:26,070 --> 00:06:27,540
of a phishing attack.

154
00:06:27,540 --> 00:06:28,620
With that being said,

155
00:06:28,620 --> 00:06:30,480
you will still find a ton of phishing emails

156
00:06:30,480 --> 00:06:32,580
that uses broken English, poor grammar,

157
00:06:32,580 --> 00:06:34,710
and contain numerous spelling errors.

158
00:06:34,710 --> 00:06:37,260
And you may be wondering why that is.

159
00:06:37,260 --> 00:06:39,000
Well, the reason is simple.

160
00:06:39,000 --> 00:06:41,730
If the phishing emails are too well done,

161
00:06:41,730 --> 00:06:43,020
everyone will fall for it,

162
00:06:43,020 --> 00:06:45,540
and this would simply overwhelm the attacker's ability

163
00:06:45,540 --> 00:06:48,660
to act on the phished user's information.

164
00:06:48,660 --> 00:06:52,740
So, many attackers have chosen to purposely include clues

165
00:06:52,740 --> 00:06:54,780
that their emails are phishing emails

166
00:06:54,780 --> 00:06:56,460
so that they can quickly weed out those

167
00:06:56,460 --> 00:06:58,230
who are more suspicious by nature

168
00:06:58,230 --> 00:07:00,990
and would catch their grammar and spelling errors.

169
00:07:00,990 --> 00:07:02,430
This leaves the phisher

170
00:07:02,430 --> 00:07:04,920
with only people who are more gullible

171
00:07:04,920 --> 00:07:06,720
and are likely to be more profitable

172
00:07:06,720 --> 00:07:07,950
for the attack over time

173
00:07:07,950 --> 00:07:10,590
than users who are better trained and more suspicious.

174
00:07:10,590 --> 00:07:13,770
So if you suspect an email is part of a phishing campaign,

175
00:07:13,770 --> 00:07:15,090
what should you do?

176
00:07:15,090 --> 00:07:16,500
Personally, I recommend

177
00:07:16,500 --> 00:07:18,720
that you promptly report suspicious messages

178
00:07:18,720 --> 00:07:20,670
to help your organization mitigate the risk

179
00:07:20,670 --> 00:07:22,860
of a phishing attack being successful

180
00:07:22,860 --> 00:07:24,930
against others on that network.

181
00:07:24,930 --> 00:07:27,120
Each organization has its own policies,

182
00:07:27,120 --> 00:07:30,240
which may include deleting the suspected phishing email,

183
00:07:30,240 --> 00:07:32,100
forwarding it to your security team's inbox,

184
00:07:32,100 --> 00:07:34,800
like phishing@yourdomain.com,

185
00:07:34,800 --> 00:07:38,670
or procedures that your organization has chosen to use.

186
00:07:38,670 --> 00:07:41,190
If you are working as a cybersecurity professional

187
00:07:41,190 --> 00:07:44,430
and you are asked to triage potential phishing attacks,

188
00:07:44,430 --> 00:07:46,770
you should first analyze the reported messages

189
00:07:46,770 --> 00:07:48,600
to confirm whether it's a phishing attempt

190
00:07:48,600 --> 00:07:52,260
using the commonly used and known indicators like urgency,

191
00:07:52,260 --> 00:07:54,630
unusual requests, mismatched URLs,

192
00:07:54,630 --> 00:07:55,800
suspicious email addresses,

193
00:07:55,800 --> 00:07:58,440
and poor spelling and grammar in the message.

194
00:07:58,440 --> 00:08:01,770
It is also important to inform all users about the threat,

195
00:08:01,770 --> 00:08:04,080
as other users might have also received

196
00:08:04,080 --> 00:08:07,290
a similar phishing email directed at your organization.

197
00:08:07,290 --> 00:08:09,540
In your notification or broadcast email,

198
00:08:09,540 --> 00:08:11,820
you should remind the enterprise users

199
00:08:11,820 --> 00:08:13,710
that they should not click on any link

200
00:08:13,710 --> 00:08:16,260
inside of the suspected phishing emails

201
00:08:16,260 --> 00:08:19,530
or provide any kind of sensitive or personal information

202
00:08:19,530 --> 00:08:20,430
to the attacker.

203
00:08:20,430 --> 00:08:22,410
If the phishing email was opened

204
00:08:22,410 --> 00:08:25,020
or any of the links in the email were clicked,

205
00:08:25,020 --> 00:08:27,090
you should conduct a quick investigation

206
00:08:27,090 --> 00:08:29,520
and triage all of the user's systems to determine

207
00:08:29,520 --> 00:08:31,980
if there was any potential damage caused by the attack.

208
00:08:31,980 --> 00:08:34,799
Lastly, if the phishing campaign was successful,

209
00:08:34,799 --> 00:08:38,340
the organization should use this incident as an opportunity

210
00:08:38,340 --> 00:08:41,370
to review and update their security countermeasures,

211
00:08:41,370 --> 00:08:43,380
such as updating spam filters

212
00:08:43,380 --> 00:08:46,920
or conducting additional user security awareness training.

213
00:08:46,920 --> 00:08:49,140
So remember, preventing phishing attacks

214
00:08:49,140 --> 00:08:51,600
requires a combination of effective training,

215
00:08:51,600 --> 00:08:53,700
vigilance in recognizing phishing attempts,

216
00:08:53,700 --> 00:08:56,700
and a swift response to reported suspicious messages.

217
00:08:56,700 --> 00:08:58,110
By implementing these strategies,

218
00:08:58,110 --> 00:08:59,220
individuals and organizations

219
00:08:59,220 --> 00:09:00,780
can significantly reduce their risk

220
00:09:00,780 --> 00:09:02,680
of falling victim to phishing threats.

