The Norman Transcript

Business

September 30, 2012

Spear phishing emails work all too well

NORMAN — By now, most of us have seen so-called “phishing” emails, designed by scammers to separate us from our money. These messages look legitimate, as if they are from bona fide companies trying to protect us, directing us to login and “verify” our online accounts. They are, of course, totally fake.

For the past few years, more sophisticated phishing email scams have appeared, called “spear phishing.” The word “spear” has been added because these bogus emails are much more targeted and focused in their approach, including personal details such as your name, the company your work for, and even your street address. In addition, they seem to come from someone you actually know. Spear phishing is proving to be a much more lucrative con than old-fashioned phishing.

Spear phishing’s success is in the details. Would a spear phishing attack fool you? Imagine your name is Bob Everyman and you work for Acme Widgets at 123 Main Street. You get an official-looking email from “John” in the Acme Widgets I.T. department that says, “Dear Bob Everyman. We have noticed increased spam activity on the company network, with spammers trying to access company email accounts. To end this problem, we are issuing new passwords for all email accounts.”

“Please reply to this message by sending us your current password and we will issue you a new alpha-numeric password for your email account. Thank you for helping enhance email security at Acme Widgets.” The message is signed by “John Jones, Acme Widgets I.T. Department” and includes the correct company address and phone number. Plus, the company logo is right there at the top of the message.

Would you do it? Would you send “John the I.T. guy” your password?

Computer security guru Bruce Schneier, quoted by the New York Times, describes the situation like this: “It’s a really nasty tactic because it’s so personalized. It’s an e-mail from your mother saying she needs your Social Security number for the will she’s doing. This is hacking the person, it’s not hacking the computer.”

Research by security firm FireEye has noted that spear phishing emails often try to trick the recipient into downloading dangerous attachments seemingly related to some sort of important mail delivery or parcel shipment. Shipping and postage-related words are some of the most common words included as part of the names of these attachments.

Popular attachment names used by the bad guys include DHL document.zip, Fedex_Invoice.zip, and Label_Parcel_IS741-1345US.zip. Also popular are words like notification, delivery, label, invoice and post.

“One way cybercriminals fool users is by sending files purporting to be notifications about express shipments,” FireEye states in their research. “Given the ubiquity of these services, and their inherent importance and urgency, users are being compelled to open malicious files labeled with shipping-related terms.”

The Federal Trade Commission manages a website called Onguard Online, which has some good ideas on computer safety. The website has an amusing game you can play to test your spear phishing IQ at onguardonline.gov/media/game-0011-phishing-scams. There are also some clever videos that are good for a laugh, as well as good information; take a look.

Dave Moore has been performing computer consulting, repairs, security and networking in Oklahoma since 1984. He also teaches computer safety workshops for public and private organizations. He can be reached at 405-919-9901 or www.davemoorecomputers.com.

For local news and more, subscribe to The Norman Transcript Smart Edition, or our print edition.

Text Only | Photo Reprints
Business
  • Norman Conquest draws regional participation

    Eighteen years ago the Norman Conquest bike ride was born when the Bicycle League of Norman talked to Jeff Stewart about the possibility of O’Connell’s Irish Pub and Grill sponsoring a local bike ride. “Norman Conquest originated at ...

    June 16, 2013

  • Crowe & Dunlevy awards $8,000 in minority scholarships

    Oklahoma-based Crowe & Dunlevy law firm has selected two first-year University of Oklahoma College of Law students as the recipients of its 2013 minority scholarships in the amount of $4,000 each....

    June 16, 2013

  • Norman Conquest Local bike retailers have a cycle for everyone

    The 18th annual Norman Conquest bicycle ride is right around the corner. Get ready to conquer now at one of Norman’s bicycle shops — all of which have a substantial inventory with bicycle season in its peak. All Norman’s bike shops also service the products they sell. Personnel are experienced riders and can offer cycling advice including safety tips, maintenance know-how and the best gear for your style of riding.

    June 16, 2013 1 Photo

  • Chamber hosts Legislative Lunch

    Oklahoma Speaker TW Shannon will address Norman Chamber members at the annual Legislative Lunch scheduled for 11:30 a.m. Wednesday, June 26, at the Oklahoma Memorial Union. Shannon will give a recap of legislative accomplishments from ...

    June 16, 2013

  • business briefs

    Free app to cut waste Cartridge World is offering a new free software app, called PrintEco, to reduce the amount of wasted paper and cut paper costs by as much as 24 percent. With the click of a button, the PrintEco app optimizes print ...

    June 16, 2013

  • Some valuable course work

    Presuming that the final round of the men’s U.S. Open is being played this afternoon, golf fans who do not want to see the championship swinging and putting end just yet can roll out to the OU Jimmie Austin Golf Club this week as the U.S. ...

    June 16, 2013

  • building permits

    The following commercial new construction and commercial addition/alteration permits were issued between May 29 and June 5....

    June 16, 2013

  • What to do if you’ve been hacked, Part 2

    Last week I told the story of Mary, one of my customers whose Hotmail account was hijacked by the Internet bad guys....

    June 16, 2013

  • real estate transactions

    Seller(s): Landau, Brent C., Bangs, Elizabeth T.; Buyer(s): Martin, Eric R. and MaryAnn E.; Amount: $232,000; Westwood Estates Blk 17-22; Lot 20; Block21 Seller(s): Ideal Homes Of Norman LP; Buyer(s): Booze, Charles F., III and Karen J.; ...

    June 16, 2013

  • Oklahomans to enjoy lower prices

    Beginning Nov. 1, Oklahoma consumers will enjoy legal Black Friday and other low-price sales for the first time since the 1940s. Gov. Mary Fallin has signed Senate Bill 550, by Sen. David Holt, R-Oklahoma City, and Rep. Tom Newell, ...

    June 11, 2013