Protection Against Phishing, Vishing & Co. - Seven Golden Rules Against Social Engineering
Have you already seen such an email in your inbox? Did you also feel a brief moment of fear of losing valuable data or a frequently used account? Would you have clicked the link?
In that case, you would likely have landed on a fake website of the presumed company, which would have prompted you to enter your account details. As you probably already suspect, this example is a typical phishing email.
The term "phishing" is derived from "password harvesting" and "fishing," and is also a reference to "phreaking," an early form of hacking. Fake emails, text messages, or websites pretend to come from a legitimate source. Seeming trustworthy at first glance, they typically redirect the user to equally fake login portals and prompt them to log in or download a hidden Trojan. Urgency is often created to prevent victims from consulting others or verifying the facts. Furthermore, severe consequences are threatened if immediate action is not taken. The goals are frequently the plundering of a private bank account or the theft of confidential company information, which is only accessible with the victim's login credentials. Phishing is categorized as a social engineering attack.
The goal of social engineering is to obtain confidential information or to induce a specific action. Psychological basic principles, such as sympathy for people in distress or reciprocity when providing assistance, are skillfully exploited. From an evolutionary perspective, these traits were important in small groups to ensure survival. In a digitized and globalized world, these traits can quickly become a weakness. In social engineering, no technical vulnerability is exploited, but primarily the "human vulnerability." In addition to phishing, "vishing" (social engineering over the telephone) and "CEO fraud" are relevant attack vectors. A look at the media confirms that phishing and social engineering attacks remain highly relevant. Currently, the Corona crisis is frequently used as a presumed reason for contact.
Anyone wishing to secure their company or themselves from an information security perspective should not only consider purely technical attack vectors and protective measures. A holistic approach is necessary, one that incorporates their own human vulnerabilities and those of executives and employees into the considerations of information security. The goal should be a high level of awareness among all human actors working with information systems. Only those who are informed about the dangers and can identify them have a chance to recognize social engineering before sensitive data is disclosed. A central lever for this is the corporate culture, which is why executives in particular should be sensitized. Regular social hacking exercises, training with live hacking demonstrations , and training as part of security consultancy contribute significantly to higher awareness among employees.
aramido GmbH provides a fact sheet with effective strategies against social engineering . These help identify phishing emails, vishing calls, and other social engineering attacks and how to handle them successfully. Feel free to use it to educate your team and family members about social engineering attacks and thus actively contribute to greater cybersecurity awareness in society.

With the fact sheet and a demonstration of the cold-boot attack , aramido participates in the European Cyber Security Month (ECSM). Under the motto "Think Before You Click #ThinkB4UClick," European Union institutions organize this year's action month to sensitize citizens, companies, and society to cybersecurity and to inform them about dangers and protective measures. This year's focal points are "Digital Skills" and "Cyber Scams." In Germany, the action month is coordinated by the BSI. So far, over 200 actions with a wide variety of topics and target audiences have been submitted to the BSI.

On 15.10.2020 in the category Communication Security published.
