Free Phishing Test

A phishing campaign using false job offers from over 30 recognizable brands steals login details to Google accounts belonging to marketing specialists. Will Thomas, senior advisor at Team Cymru, identified at least 34 domains used in this operation, which has been running continuously for at least five months

What is this phishing campaign and who does it attack?

The attack impersonates recruitment. The victim receives a message from a “recruiter” looking for candidates for marketing positions. The message contains the recipient’s name and surname and refers to his/her actual industry, which indicates prior recognition of the target’s professional profile before the fake message was sent.

What is phishing in this release?

Classically, it is an attempt to extort data or money by impersonating a trusted entity. Here, the role of a trusted entity is played by a well-known brand (Adobe, Netflix, Coca-Cola, OpenAI and several others) and by a specific, named recruiter.

The campaign differs from typical phishing attacks in that it does not lead the victim immediately to a malicious domain. It first passes it through several legitimate SaaS platforms, making it difficult to detect by standard security filters.

The operation targets only people working in marketing. This choice is not accidental. The marketing department regularly contacts external recruiters, agencies and partners, so employees in this area have a lower natural vigilance towards recruitment messages than, for example, the IT or security departments.

How the attack works: fake job offer step by step

Message from the “recruiter” with real name and photo

Attackers sign messages with the name and photo of a real recruiter employed in the impersonated company, which gives the fake job offer credibility that is difficult to verify at first glance. In one documented case, fake news impersonated Paulina Manzo, an Adidas recruiter, who publicly warned about the use of her identity on LinkedIn. She never sent such an email herself.

Source: https://www.bleepingcomputer.com/news/security/phishing-poses-as-big-brand-job-interview-to-steal-google-accounts/

Redirection chain through four platforms with two different functions

Instead of taking the victim straight to the malicious domain, the attack passes them through four successive platforms before reaching the final phishing site. It is worth distinguishing two different functions that these platforms perform in the chain.

The first three links are used to “borrow” the domain’s trust and reputation. The email is sent from PeopleForce, a real, cloud-based HR and ATS (Applicant Tracking System) platform. The link continues to exct.net, a Salesforce Marketing Cloud domain operating under the former ExactTarget brand. From exct.net, traffic is redirected to Wise Agent, a cloud-based CRM system for real estate agents, completely unrelated to recruitment. Each of these three domains has an established reputation and real business use, so spam filters that evaluate the first link in the message have no reason to block it.

The fourth link is the phishing site itself, hosted on Netlify, a free platform for publishing static websites, such as mckinsey-careers[.]com. Netlify isn’t borrowing brand reputation here like the previous three platforms. Its role is different: it is a fast, free and easy-to-rotate hosting that allows attackers to set up and replace landing pages without affecting earlier stages of the email chain. This difference is important for defenders because it requires two different types of detection: analysis of the reputation of intermediary domains and monitoring of newly registered, cheap hosting sites that are confusingly similar to your own brand name.

It is unknown how attackers gained access to PeopleForce, Salesforce Marketing Cloud and Wise Agent. They could set up test accounts specifically for the campaign or use the compromised login details of an existing customer. None of these paths require hacking into the infrastructure of the service providers themselves.

Fake Google Login Window: Browser-in-the-Browser (BitB) Technique

After reaching the final phishing page, the victim sees a “Continue with Google” button and a button to schedule a call. Clicking opens a window that closely resembles a native browser window with a Google login form, complete with a URL bar, icons, and a layout typical of a real OAuth window. In fact, it’s just HTML and CSS rendered inside the phishing page itself, not a separate system window.

This technique, known as Browser-in-the-Browser, neutralizes the most popular piece of advice given to employees: check the address in the browser bar before entering your login credentials. Since the address bar is also part of the fake graphic, the victim has no easy way to distinguish it from the real Google login page unless they pay attention to the fact that the entire window does not behave like an independent system process, for example, it cannot be moved beyond the borders of a browser tab.

What brands and sectors were used in the campaign

The campaign covers at least 34 domains impersonating companies from six different industries, which shows that the attackers did not limit themselves to one sector, but built infrastructure for a wide range of potential victims.

The scale and sectoral scope of this campaign indicate anorganized and well-planned operation, conducted on a continuous basis, rather than a one-off incident. This does not have to mean a large budget: registering a domain and setting up a template career subpage on free hosting is a cheap and partially automated process today. It proves operational consistency and a long operating horizon rather than the scale of financing, which is difficult to estimate based on the number of domains alone.

Why marketers are the main target of this attack

Marketers fall victim to this campaign not by accident, but because their everyday work requires openness to contact with previously unknown people: agencies, freelancers, influencers, potential business partners and recruiters. This professional openness, which is an advantage in other circumstances, becomes a weakness in the context of phishing. The natural vigilance towards an unknown sender is lower in this group than, for example, in the IT or security department, where contact with external entities is subject to stricter procedures.

A marketer’s Google account can also be a gateway to resources that go far beyond just your mailbox. Many organizations use Google Workspace as a central login (SSO) mechanism for other tools, from Google Analytics and Google Ads through campaign data spreadsheets to content management platforms. So taking over one account can open access to advertising budgets, brand social media accounts and campaign data simultaneously, not just to private correspondence.

An additional risk factor is that marketers regularly click on links from external sources as part of their work: they track competitors’ campaigns, test landing pages, and analyze marketing tools. This means that clicking on a link from a “recruiter” does not evoke the same suspicion that it would in a team accustomed to a limited, verified set of external contacts.

What risk do fake recruitments pose to the organization

Operational risk: escalation via Google account and SSO

The takeover of one Google account rarely ends with the theft of private correspondence. In many organizations, this account acts as a central login mechanism for other systems, so its loss opens the door to a much wider security incident.

An attacker with access to the marketer’s mailbox gains insight into the history of communication with agencies, suppliers and internal teams, material sufficient to prepare another, even more credible attack, for example in the Business Email Compromise formula, where the compromised account is used to sending fake payment orders or changing transfer details on behalf of a real employee.

The consequence may also be the leakage of data, contact lists or access data to other tools saved in the mailbox or in Google Workspace.

Reputational risk: use of recruiters’ identity and brand

Using the name and photo of a real recruiter without his knowledge damages the company’s credibility, even when the organization itself is not to blame for the attack.

Paulina Manzo, an Adidas recruiter, had to publicly warn her network of contacts on LinkedIn that she had never sent the disputed message. This is a situation that no employee should be put into by the actions of third parties.

Candidates, partners and customers who encounter a fake job offer may persistently associate the brand with the scam, regardless of how quickly the company responded. Organizations with a recognizable name should treat monitoring domains that are confusingly similar to their own brand as a permanent element of reputation protection, not a one-time reaction to a report.

Regulatory risk: incident reporting obligations

Large organizations covered by the National Cybersecurity System and the EU NIS2 directive are obliged to report significant security incidents within specified deadlines. Taking over an employee’s Google account, which led to the leak of customer data, campaigns or access to subsequent systems, may qualify as such an incident, which shifts the responsibility for the response from the marketing department straight to the desk CISO and management.

How companies and employees can protect themselves

Browser-in-the-Browser Technique

The most effective technical answer to the Browser-in-the-Browser technique is phishing-resistant authentication: FIDO2 keys or passkeys, which bind the login process to a specific domain address. They cannot be captured through a fake window rendered in HTML because they will simply refuse to work on a page that is not real Google, no matter how legitimate it looks.

This distinguishes them from the password and classic one-time code: there is no publicly confirmed evidence that this particular campaign captures and uses an SMS or OTP code in real time to log into a real account, so simple two-factor authentication is still a real barrier to simple password capture.

FIDO2 and passkeys, however, remain the strongest security because they eliminate the risk of providing data on a fake website, regardless of how exactly the attacker’s background works.

Verification procedure

The second pillar of protection is the procedure of verifying the recruiter through company channels before the employee clicks on any link in the job message. A simple rule, checking the recruiter’s profile on the company’s website or contacting him via the official address and not via an email link, neutralizes most variants of this attack, because attackers do not have access to the real communication channels of the impersonated organization.

Monitoring of registered domains

Organizations with a recognizable brand should implement constant monitoring of registered domains that are confusingly similar to their own name (such as “-careers”, “-hiring”, “-jobs”) and have a ready procedure for reporting such domains to block fake websites at registrars and browsers, instead of reacting only after reporting from an employee or candidate.

Monitoring full redirect chains in links

IT and security teams should additionally analyze full redirect chains in links contained in emails, not just the first visible URL. This campaign shows that a filter that evaluates only the first hop of the link (the PeopleForce domain) will pass a message that leads several redirects to a phishing website. Link sandboxing and full redirect chain tracking at the mail gateway detects this technique much more effectively than static domain reputation lists.

Persistent procedures

If login details have already been provided on a suspicious website, the speed of response is key. The employee should immediately change the password to the Google account, and the IT administrator should log out all active sessions, check the mail forwarding rules and review the list of third-party applications connected to the account via OAuth. The access token for such an application may survive a password change alone, so without this review, an attacker may retain access even after the credentials are reset.

High security awareness – Practical Anti-Phishing Training

The most lasting element of defense remains the preparation of people, because this entire campaign is based on social engineering, not on malware or technical exploits. Social engineering tests show in numbers how many employees would click on a similar message, but the diagnosis itself does not build immunity – practical training in response to a specific attack scenario is needed.

Practical Anti-Phishing Training teaches the team to recognize warning signals in current, real attack scenarios. Unlike one-time theoretical training, training is based on cyclical simulations of cyberattacks tailored to the specificity of a given department, which is particularly important in teams with naturally lower vigilance towards external contacts, such as marketing. Building cybersecurity culture in such teams requires more frequent and focused exercises than standard annual company-wide training.

Thanks to PTA you can

Organizations that want to see how their team would react to a message similar to the one described in this article can start with Free Phishing Test – with no cost or obligation.

Get to know our original phishing simulation platform – personalized scenarios (instead of generic templates), Polish solution (data stays in the EU) and readiness for audits and controls (GDPR, DORA, UKSC/NIS2).

WhatsApp is changing the way users identify themselves on the platform. From June 2026 Meta allows you to reserve unique usernames that will eventually replace your phone number as your primary contact ID. The change affects over 3 billion users in 180 countries and has a direct impact on one of the most common fraud vectors in recent years – phishing conducted by WhatsApp.

What is WhatsApp?

WhatsApp is Meta’s messaging app, used by over 3 billion people in 180 countries for private conversations, voice and video calls, and communication with businesses. The application encrypts messages end-to-end, which means that only the sender and recipient can read the content of chats, not WhatsApp itself.

Why is a change in the application important for company security?

For organizations, WhatsApp has long gone beyond the private sphere:

This means that any change in the mechanism for identifying WhatsApp users is important not only for the individual, but also for the risk model of the entire organization.

The very need that Meta addresses with the introduction of usernames is simple and well known to anyone who has used group chats. As the company describes it, joining a chat with parents from your child’s sports team or neighborhood group previously required giving your phone number to people you didn’t know.

The phone number, unlike the username, is permanently linked to your identity, credit history, bank account and many other services – hence sharing it with strangers carried a risk that went far beyond the application itself.

What are usernames in WhatsApp and how do they work

A WhatsApp username is a unique identifier that the person sharing it shares instead of a phone number.

A contact who does not have a number in his address book will only see username after implementing the function, not numbers. The mechanism works on Android, iOS, Windows and the web version.

Source: https://wabetainfo.com/whatsapp-is-rolling-out-the-username-feature-on-android-and-ios/

Reservation and username generator

Reservations can be made now, although the full launch of the function will take place in the second half of 2026, gradually, country by country.

The path is short: Settings > Account > Username, after updating to the latest version of the application. The name must be between 3 and 35 characters long, contain at least one letter, and can consist of lowercase letters, numbers, dots, and underscores. It cannot start with “www.” or end with a domain such as “.com” or “.net” – this is protection against names imitating website addresses. Since over 3 billion people use WhatsApp, many obvious names are already taken, so Meta has also provided a generator that suggests variants of available usernames.

Username key as first contact control layer

In addition to the name itself, you can set an optional username key – a short code that a person contacting you for the first time must know together with the username. Without the key, the name itself is not enough to write the message. WhatsApp does not maintain any directory or search engine for users and does not suggest contacts – you need to know the exact name to start a conversation.

Option for creators, companies and organizations

Businesses who want to maintain a consistent online presence can take over a username on WhatsApp that they already have on Instagram or Facebook, after ownership is verified by the Accounts Center. This choice facilitates brand recognition, but it also has consequences, which I return to in the section about new risks.

Naming rules and restrictions

The username must be available on WhatsApp, Instagram and Facebook at the same time – if someone has previously taken it on one of these platforms, it cannot be used on WhatsApp without proof of ownership. Some names are reserved in advance for governments, public figures and companies and will not be available to you as a regular user. You can change or delete the name at any time, but once it is released, it becomes available to someone else.

Why has the phone number been WhatsApp’s weak point so far?

The phone number as an account identifier had one fundamental flaw: it was permanent, public and used many times outside of WhatsApp itself – in banking, with the operator, in two-step verification systems of other services. Each data leak that included phone numbers automatically gave criminals a ready-made list of potential WhatsApp victims.

How phishers used the phone number – verification code and call forwarding mechanism

A large group of methods is to use the WhatsApp registration process itself, for which a telephone number is required.

Verification code as the easiest way to take over your account

The attacker does not have to break any of WhatsApp’s security measures – he just needs to know the victim’s phone number. The pattern looks like this: the victim’s phone number, a request to register an account on the attacker’s device, a real six-digit code sent by WhatsApp to the victim’s number, a fake website or message prompting him to reveal this code, transfer of the code, account takeover.

The Singapore Police Force described a wave of such attacks in November 2025, in which, after taking over an account, the fraudster sent loan requests to the victim’s contacts, impersonating their credible identity (source). The mechanism is simple precisely because it is based on knowledge of the number and a moment of inattention of the account owner, not on a technical loophole in the application itself.

Call forwarding and USSD codes – limitations of the mechanism

The Indian I4C center warned in December 2025 against fraudsters impersonating couriers who persuaded victims to dial a USSD code starting with *21 and containing a number controlled by the criminal, which activated call forwarding.

It is worth being precise here: call redirection does not mean the automatic transmission of standard SMS messages, and an attack on WhatsApp is possible primarily when the attacker has previously activated the account registration on the victim’s number and chooses to transmit the code in an automatic voice call – WhatsApp officially allows receiving a six-digit code both via SMS and by phone call.

The USSD codes themselves and their operation vary depending on the country, operator and network configuration, so it is impossible to talk about one universal “Whatsapp hijacking code”.

Malicious links, QRLJacking and fake app versions – from WhatsApp Gold to today

The same goal of taking control of an account or device is also achieved without any verification code. QR codes shared in chats can, when scanned, connect the attacker’s device to the victim’s WhatsApp Web session – a technique known as QRLJacking.

The lure of “WhatsApp Gold,” a supposedly enhanced version of the app with additional features, has been circulating on chain messages since at least 2016 and recurs periodically, leading to malware or fake paywalls.

This shows that tricks based on fake updates and links are not new for 2025 or 2026 – only the packaging changes, as in the previously mentioned VBS file campaign described by Microsoft.

Other examples of cyberattacks using WhatsApp

Takeover of group administrator accounts

In a group of parents from a sports team, the administrator asked participants to provide a code supposedly needed to participate in the meeting. In fact, it was a security code for their WhatsApp accounts – an attack that Derbyshire Police and Castle Gresley Parish Council described as a wave of group account takeovers in early 2025 (source). The telephone number of each group member was the account identifier for which the attacker initiated the takeover process, and the group itself provided him with a ready list of subsequent victims and a credible excuse.

GhostPairing – hijacked by a fake pairing link

Gen Digital and Avast researchers described an attack in which the victim received an “I found your photo” message from a friend’s already compromised account, leading to a page imitating Facebook. The site guided her through the legal process of pairing WhatsApp with a new device, so the victim was unknowingly authorizing the attacker’s access (Gen Digital, Avast).

False voting in the competition as bait in a global campaign

Whalebone Threat Intelligence recorded the same pattern as GhostPairing, based on fake voting in the competition, in over 15 countries around the world – mainly in Central and Southern Europe (Czech Republic, Slovakia, Slovenia, Serbia, Romania, Bulgaria, Poland, Croatia), but also in Spain, Italy, Brazil and Mexico – with language variants tailored to local audiences and an extensive phishing infrastructure of over 200 blocked domains (source).

Impersonating loved ones from a hijacked account

A joint bulletin from Sussex Police and Surrey Police described the case of a person from Sussex who received a WhatsApp message from her sister’s compromised account asking for money and lost almost £500 before realizing she was talking to a fraudster (source). The telephone number and the resulting trust in contacts from the friends’ list are crucial here – the victim did not verify the interlocutor because the message came from an account he had known for years.

Malicious files and device infection

Microsoft described a campaign running since the end of February 2026 in which malicious VBS files were sent via WhatsApp, triggering a multi-stage chain of infections and installing MSI backdoors providing remote access to the system (source).

Fake “WhatsApp Security Center”

HKCERT warned in June 2026 against fake “WhatsApp Security Center” websites, which, under the pretext of unblocking an allegedly suspended account, encouraged people to scan a QR code or enter a pairing code (source).

What is WhatsApp phishing

Phishing via WhatsApp is an attack method in which the criminal uses a message, a voice call or a link shared in the messenger to impersonate a well-known brand, institution or person from the victim’s contacts in order to extort personal data, money or access to the account.

It differs from email phishing by several features that work to the advantage of the attacker on WhatsApp:

  1. End-to-end encryption protects the content of conversations from eavesdropping, but at the same time means that WhatsApp cannot automatically scan chats for malicious links or fraudulent text – detecting an attack depends entirely on the recipient.
  2. The messenger is also a space built on trust in close contacts, so a message from a “friend” or “group administrator” arouses less suspicion than an analogous email from an unknown sender.
  3. Additionally, the message is sent to the phone with a real-time notification, which prompts a faster, less thoughtful response than in the case of email.

Phishing via WhatsApp takes many specific forms – from false verification codes and pages imitating a security center, through malicious links and files, to impersonating loved ones from a compromised account. The common denominator of all variants is the use of trust and time pressure to bypass the victim’s common sense, without breaking the technical security of the application itself.

How usernames can reduce phishing on WhatsApp

Username really hinders one specific stage of the attack: the first, unsolicited contact based on knowledge of the phone number itself.

However, it does not protect against account takeover when the attacker already knows the number, has access to the registration code or operates from the account of a person the victim knows and trusts.

What does username actually block?

Auto-dialer bots that massively scan number ranges for active WhatsApp accounts are losing their basic advantage. The number itself is no longer sufficient to establish first contact – an exact username is needed, and if the username key is enabled, an additional code is also needed.

The lack of a directory and contact suggestions also means that you can’t “browse” WhatsApp users like you can browse profiles on other social networking sites.

For victims of mass spam campaigns and first-contact scams, such as fake lotteries or job offers sent to a number from a leaked database, this is a real, measurable barrier.

What username does not block

None of the account takeover cases described earlier would have disappeared based on the username alone.

In other words, username shifts the threshold for attacks based on anonymous, mass reaching out to numbers, but leaves open a whole category of attacks based on taking over an existing account, which in the source material from 2025-2026 outnumbers classic cold phishing to an unknown number.

December is here – a time when the holiday rush and the end of the year in the office create the perfect environment for clever hackers. Both in the nooks and crannies of company servers and in the privacy of your home, you can fall into their traps. So before you dive into your duties and Christmas preparations, read the article and don’t let them turn you into a reindeer (the Christmas version of a deer!).

Company traps

Gift vouchers and cards from the company are a gift that will please every employee. But beware! Hackers do not sleep and impersonate popular benefit platforms, sending phishing emails asking people to click on a link or log in to a fake platform to “receive” a gift.

An invitation to a Christmas Eve meeting may also be a fake with a link to a fake website or a file with malware.

Requests to share summaries, analyzes, budgets are also common lures for criminals.

Before you click, enter your details, upload documents or log in – always try to determine whether the message is fake. Errors in the sender’s email address will disqualify the email, but the absence of errors does not mean the message is secure.

Problematic packages

During the season, when parcel lockers are bursting at the seams and couriers work tirelessly, watch out for fake news about delivery problems, the need to pay extra or customs fees.

Before you reply to the message or click on the link, verify the information directly on the courier company’s website.

Express promotions

Of course, holiday price offers, sales “only until the end of the year”, fantastic New Year’s Eve offers too good to be true – most often they are fake.

Before you provide your data and pay for the basket, analyze the domain, check the credibility and history of the store or travel agency, read opinions on the Internet.

Wishes from (non)friends

During the holiday season, when even strangers become close, be careful because not all wishes come from your friends. Cards, links to wishes, memories and photosmay lead to viral files or websites that will try to exploit vulnerabilities on your device.

Whether in the company or at home, the period of celebrating holidays and the upcoming New Year causes our attention to be distracted, and this is a perfect opportunity for cybercriminals. 

Cybersecurity Team:
8 tips to unmask phishing

There are a few days left until Christmas, a dozen or so until the end of the year – don’t give up! Spend this time carefully and joyfully, without unpleasant experiences or despair over lost data or money.

Merry and safe Christmas 🎅

Business Email Compromise (BEC) is a social-engineering attack in which a criminal impersonates an employee, manager or business partner and sends a fraudulent email to obtain money, data or another benefit.

Every organization is exposed, regardless of size or industry. Employees may receive a request to transfer money, change a payment account, send a file or disclose information. Education is therefore a key part of defense.

How to prepare employees to defend against BEC attacks

Train and test regularly

Conduct practical training and realistic simulations. They help employees recognize potential BEC attacks, respond without rushing and report suspicious messages. The results can show the organization’s level of exposure and guide additional risk-reduction measures.

Teach the warning signs

Write clear procedures

Document rules for passwords, confidential data, identity verification, payments, multi-factor authentication and reporting. Procedures should be easy to understand, kept up to date and available to every employee.

Practice and report

Verify employees’ practical knowledge periodically. Give them a simple way to report suspicious email to IT and encourage everyone to warn colleagues about current threats. Each employee should understand their role in the company’s security culture.

Effective BEC protection is continuous. It combines employee awareness, clear procedures and appropriate technology. Better preparation increases the chance of stopping an attack before it causes a financial loss.

Check your employees’ vulnerability to BEC attacks for free

What is a scam?

A scam is a form of fraud that has existed for centuries. It involves deceiving people in order to obtain money or another benefit. The internet has made scams even more common because criminals can reach much larger groups of potential victims. They use social engineering and emotional manipulation to make their schemes convincing.

The consequences can be financial and emotional. Victims may lose money or valuable property and may experience shame, disappointment, fear or guilt. Scammers target both companies and private individuals.

How to recognize a scam

The BBC reported that, in the United Kingdom alone, 45 million people fell victim to scams during the summer of 2021. There is no single formula for recognizing every scam: fraudsters constantly vary their tactics. Anyone can become a victim, so your safety depends on awareness, knowledge, the ability to recognize threats and vigilance when something feels wrong.

Warning signs that may indicate a scam

Are scams and phishing the same thing?

Scams and phishing are related, but they are not identical. Phishing is a specific type of scam in which attackers use email, SMS or another communication channel to deliver deceptive content and persuade a person to take an unsafe action. Read more in Phishing: The Greatest Modern Threat on the Internet.

How to protect yourself against scams

Scams are a serious cyber threat because criminals can use inexpensive tools to reach millions of people. They exploit trust, naivety, fear, curiosity, empathy, the desire for profit, the need to be noticed and the hope of finding a good opportunity.

Use common sense and do not give unverified requests the benefit of the doubt. Do not believe promises of effortless wealth, and follow these rules:

  1. If a message is unusual, unlikely or openly suspicious, ignore it. Do not click links, reply or call back.
  2. Never share your password, PIN or access code.
  3. Before shopping online, confirm that the store exists and that the address in the browser is genuine.
  4. Slow down. Rushing is especially dangerous when making a payment or transfer.
  5. Before approving a bank transaction, check both the recipient and the amount.
  6. Before opening an unfamiliar file, check its extension and verify the sender or download site.
  7. Before entering a password, confirm that the form is hosted at the correct domain and that the connection is protected.
  8. Never transfer money to a “safe account” at the request of someone claiming to be from a bank or the police. That is a classic scam.
  9. Avoid public Wi-Fi for sensitive activity; use a trusted hotspot or a secure connection instead.
  10. Do not let strong emotions override your normal verification steps.

Check if your employees can recognize a scam

Most people have encountered an email that appeared to come from someone else. More than 90% of cyberattacks begin with an email or another form of communication aimed at people in private life, business and public institutions. This article explains what spoofing is, how email and domain spoofing work and how to reduce the risk.

Spoofing—what is it?

Spoofing is an attack in which a criminal pretends to be an institution, company, bank, public office or person that the recipient knows and trusts. The objective is usually to steal data or money.

Common types include:

This article focuses on the first two types.

What is email spoofing?

Email spoofing is the impersonation of a sender in a message. It can support spam or phishing campaigns. The criminal wants the email to appear genuine and to persuade the recipient to click a link, open an infected file, transfer money or install an application.

To increase credibility, the attacker copies the company’s template, tone, logo and signature. The message may therefore be difficult to distinguish from legitimate correspondence unless the sender address, links and context are checked carefully.

Domain spoofing

In domain spoofing, the criminal creates a domain or address that resembles a trusted one. A single changed character, an additional word or a different top-level domain may be enough to mislead the recipient. The same manipulation can be used to impersonate a supplier, bank or internal department.

How to protect yourself against spoofing

Attacks targeting people are increasing because criminals know that human attention is a key security boundary. Everyone is susceptible to social engineering, so awareness should include employees, family members and colleagues.

Remember to protect yourself and your company

Regular training and practical phishing simulations help people recognize spoofed messages and develop safer habits.

How to recognize a spoofed message: 8 tips for your team

Increase your team’s security awareness
A ready-made list of cybersecurity questions and answers

The weeks before Christmas are exceptionally busy for many companies. Reporting, month- and year-end closing, stocktaking, holiday planning and budgeting are just some of the demands competing for attention.

Fake emails

A large part of everyday work and communication takes place over email and cloud applications. They save time and make collaboration easier, but they also create more opportunities for cyberattacks.

Cybercriminals know that December is a “hot” period for businesses. They send messages to employees’ inboxes designed to prompt a click, an attachment opening or the disclosure of data. If the message fits the context of the recipient’s work, the company may quickly find itself in serious trouble.

How to avoid falling into a cybercriminal’s trap

How to recognize phishing?
8 tips for your team!

Christmas brings increased shopping and a rush to get everything done. As more people buy gifts online, busy stores also create more opportunities for cybercriminals seeking data, passwords and money.

Problems with parcel delivery

December is an exceptionally busy period for couriers. Customers often lose track of how many items they have ordered, and cybercriminals exploit that distraction and the holiday shopping rush.

A parcel locker may be full, or a parcel expected on Monday may arrive on Wednesday. That uncertainty makes it easier for scammers to send thousands of messages claiming that a recipient must take action before a parcel can be delivered.

Two common parcel-delivery scams

In the first, the attacker impersonates an unspecified courier and claims that a parcel is being held because of an underpayment. The recipient is asked to pay a fee or resolve another supposed delivery problem.

The attacker avoids naming the courier because the message is sent to thousands of people and is meant to sound plausible to as many recipients as possible. An email or text contains a link that appears to track the parcel, but actually redirects to a fake payment service. Entering online-banking credentials may give the attacker an opportunity to steal money from the account.

The second common method is impersonating a specific courier brand. The attacker claims that delivery failed and includes a link to track or redirect the parcel.

Clicking the link opens a fake courier website that may ask the user to download and install a malicious app. The attacker can then monitor activity, steal data and drain the victim’s savings.

Mentioning a popular courier does not mean the attacker knows which service you use. Popular brands are chosen because they make the pretext more likely to succeed.

If the recipient does not respond, the scammer may send another message while impersonating a different courier. Other pretexts include an overweight parcel, a changed delivery address or an imminent collection deadline. Each message includes a link that supposedly solves the problem.

How not to become a victim

Fake deals in online stores

The pursuit of holiday bargains can be risky. Cybercriminals exploit our naivety, especially when a product price looks unusually attractive. A tempting discount is one of the most common lures used by online scammers.

Fake websites may ask for:

Sharing such information can lead to the loss of savings and expose data that may later be used for further crimes.

Read more about social engineering in Social Engineering: Good or Bad Manipulation?

How to avoid fake websites

Help people in need—not hackers

During the holidays, many of us become more sensitive to other people’s situation. We are happy to support people in need financially and help them have a better Christmas. We donate to large families, single parents, sick children and abandoned animals.

But how can you be sure that the money will reach the intended recipients? Fake charity collections are a common pretext used by cybercriminals, particularly during the holiday season.

How to support legitimate causes

Last-minute holiday travel

Dreaming of Christmas in the mountains or abroad by a warm sea? Be careful with unusually attractive online offers. A “bargain” from a well-known travel agency, a private listing or a cheap-flight offer can all be a hacker’s trap.

How to avoid the trap

What is social engineering?

Social engineering is the use of influence to persuade someone to act in a way that may or may not serve their interests. It relies on emotions, curiosity and our tendency to trust other people. Its core techniques include persuasion, manipulation and the deliberate escalation of fear. In the hands of cybercriminals, social engineering can be a highly effective weapon.

Social engineering is part of everyday life

Even when we do not notice it, social engineering surrounds us every day. People use influence and manipulation in face-to-face conversations, phone calls, social media and advertising.

Did you know that we can decide whether to buy a product within 90 seconds of seeing it? Research also suggests that the logo, color and packaging can strongly influence our choice. Product designers and marketing specialists understand this and use it to increase sales.

Sales staff recommend products, clothes and accessories that seem perfectly suited to us—even when they were not part of our original plans. Shopping centers use carefully selected music and pleasant scents, while stores arrange products to encourage additional purchases. A bartender who puts a banknote in the tip jar or a waiter who adds a small gift to the bill may also be encouraging generosity. These are everyday examples of influence and manipulation.

Good versus evil

Social engineering is neither good nor bad in itself. It is a tool with many possible uses, and carefully designed interventions can benefit individuals or society as a whole.

For example, one company fitted park bins with motion sensors and speakers that played a cartoon-style falling sound whenever someone threw something away. The park quickly became cleaner, without the city having to pay for additional cleaning. In another example, ordinary stairs were redesigned to look and sound like piano keys, encouraging people to use them instead of the escalator. Both ideas changed behavior through positive, playful cues.

There is also a darker side. People and organized groups use social engineering to exploit others. Hackers manipulate decisions, clicks, attachment openings, logins to fake websites and software installations in order to steal money or data, demand a ransom, obtain access or permissions, spy on victims, misuse devices or identities, or disrupt companies and institutions.

The most common tool used by cybercriminals is phishing, together with variants such as spear phishing, BEC, CEO fraud, smishing and social-media scams. Attackers exploit emotions and continuously refine their methods around human weaknesses.

The weakest link in corporate cybersecurity

People are the weakest link in many corporate security chains. As many as nine out of ten cyberattacks target humans. Bypassing technical controls to reach a network and steal valuable information can take a hacker considerable time. Manipulating an employee to obtain the same information may take only minutes.

A cybercriminal will manipulate you into taking a specific action—share credentials, transfer money to a fraudulent account, run a file or click a link that exploits an application vulnerability, including a zero-day vulnerability. To achieve this, the attacker may exploit a sense of duty, fear, curiosity, sympathy or the desire to help. They try to prevent a careful review of the message’s technical details—such as the sender’s domain and the real link address—or its wider context, such as why an online store is contacting a corporate address. The manipulation is designed to be subtle enough that the victim may not realize what happened until it is too late.

How to strengthen your company against hacker attacks

Social-engineering attacks are constantly evolving and exploit gaps in employees’ security awareness. To protect the organization, strengthen both people’s skills and the processes around them. The sooner you act and choose effective measures, the sooner you reduce the risk.

Our mission is to promote a security culture and improve employees’ security awareness.

Practical Anti-Phishing Training is our proprietary program. It teaches safer behavior through controlled attack simulations that use the same techniques as real attackers. Employees can practice recognizing manipulation and responding correctly in a safe environment. By varying the social-engineering techniques and scenarios, the program builds vigilance, improves awareness and strengthens security at work and at home.

Check your team’s response to cyberattacks and test our training platform – without costs or obligations!

What is phishing?

Although the word itself may sound harmless, phishing describes dangerous fraud based on manipulation and deliberately misleading the recipient.

Phishing is a human-targeted attack in which a hacker uses social engineering and deception to persuade a victim to take a specific action, such as:

Sometimes a cybercriminal begins by building a relationship that will make the later attack more credible and help them achieve their goal. They may use principles of social influence—such as authority, reciprocity, liking, commitment and consistency—as well as emotional manipulation.

Phishing methods

A hacker can try to “hook” a victim through a range of electronic communication channels:

Social engineering can also take place face to face or through traditional mail and leaflets. A criminal might even deliver a USB drive containing malware or a mug with a hidden microphone, disguised as a gift from a business partner.

Phishing traps and pretexts

Hackers use many channels and attack in many ways. They target employees to gain access to companies, steal money and obtain private information.

They impersonate well-known brands, institutions and organizations—banks, social-media platforms, everyday apps, shops, auction sites, energy and courier companies, and government bodies such as tax offices, ZUS and the National Health Fund. They may pose as either sellers or buyers.

Criminals create messages and websites that closely imitate legitimate ones. They use them to persuade recipients to disclose data or perform a specific action. Common pretexts include an unpaid invoice, a prize, an inheritance or an extra payment for a parcel.

It is impossible to list every phishing scenario. Attackers constantly develop and refine their methods, adapting them to current events and trends in Poland and around the world. During the COVID-19 pandemic, campaigns commonly referred to:

Examples of phishing attacks

Help with voting

After hijacking a social-media account, hackers use it to contact people on the victim’s friends list. The message often asks the recipient to vote at a supplied link or claims that compromising photos have been leaked.

Example of a phishing message asking the recipient to vote
Source: CERT

Example of a phishing message

Online-banking login theft and stolen funds

After clicking a link sent by a cybercriminal, the user is redirected to a fake online-banking login page. Entering their details gives the attacker access to the bank account and may allow the funds to be stolen.

Example of a fake online-banking login page
Source: CERT

Courier company: an extra payment for a parcel

The message does not identify a specific brand and omits whether the recipient is the sender or recipient of the parcel. This ambiguity is likely intended to make the pretext feel relevant to more people.

Example of a parcel-delivery phishing message

Notification from a government website

The user is told that a notification is waiting on a government website and that a copy is attached. In reality, the attachment is an archive containing a malicious script that infects the system when opened.

Example of a fake government notification
Source: CERT

How to recognize phishing?
8 tips for your team!

Hacker doesn’t sleep, hacker takes advantage of opportunities. A calendar year provides at least 365 opportunities for an online fraudster to attack. The cybercriminal will take advantage of the upcoming holidays, vacations, holidays and seasonal sales. He will do it because he knows that we are accompanied by absent-mindedness, inattention, lack of concentration, and he puts us in the right context of our thoughts and actions. Even seemingly simple manipulation tricks end with the hacker winning.

Types of phishing

When shopping online, it is easy to fall into the trap of cyber fraudsters, especially when we see new “promotions” all the time. Before holidays and during sales periods, we observe an increased number of emails informing about special offers, discounts, order confirmations, shipping, price reductions, shipping surcharges, and bank notifications. Some of them are phishing, which contains links to fake login pages to banks and stores, some messages have malware attachments or links to download infected files. Victims of hackers are not only private individuals, but also company employees who sometimes check their private email on work devices or phishing with social engineering regarding the private sphere is deliberately delivered to a business email.

So what should you do to avoid falling victim to cybercriminals? What to pay attention to? First of all, it is worth knowing the methods and goals of hacker attacks, the types of phishing messages they send, and being familiar with the social engineering traps used by criminals.

How to recognize phishing? Learn 8 tips that will help you with this!

Order confirmation

During the Christmas period, cyber fraudsters send email messages with false order confirmation. At first glance, they look like they come from well-known sellers and a quick click (without paying attention to the actual sender’s address and the address of the target website) will redirect you to the fake login form. This allows an internet fraudster can steal your login details, which can then be used, for example, to steal your identity or, depending on the scenario, attack phishing, to obtain credit card details.

Why does it work? The hacker uses sophisticated social engineering methods – it is based on emotions, causing surprise, anger and curiosity. Someone who didn’t order at all will click to explain the situation or glance to remember what they bought.

Shipment tracking

More online shopping that we do before the holidays means more opportunities for hackers to impersonate well-known companies and send links to websites where you can track your parcel, attachments with the status of the parcel, text messages about the need to pay a small amount for the parcel. If the manipulation is successful and, for example, you download the file, it is very likely that you willinfect your device’s system with malware (ransomware, spyware) or instead of paying an additional 1.67, you will confirm the payment to 4231.67.

You can read more about ransomware in the article “What is ransomware and why it should not be downplayed?”

Dangerous e-cards

Be careful when an e-card arrives in your email box. It does not necessarily have to be a manifestation of sympathy and memory. In fact, it can turn out to be an unpleasant and expensive experience. Before opening the message, make sure that the sender’s details are visible and identical to those of the person you know. If it is necessary to enter detailed personal data to unlock access to the content, it is almost certain that it is a phishing attack.

Charity fraud

We have been involved in charity events for a long time – many people ask for our help. This phenomenon increases even more in the periods before Christmas or Easter, when charity collections are conducted for excluded social groups. Unfortunately, hackers profit from this and exploit our good hearts without blinking an eye, impersonating aid organizations and desperate parents trying to save the lives of their beloved children. In this way, they extort money from us for transfers, donations, credit card details or bank logins. The case also applies to companies that are asked for support.

Therefore, if you want to make a donation, please check the case carefully or act through official, verified aid organizations and associations. Do not click on links sent by email, even if the message includes photos of people in need and the story described looks very credible.

Sales and promotions

When a message about a “mega deal” or “holiday sale” arrives in your email box, it’s hard to resist checking the offer, right? Unfortunately, these are often phishing messages that will redirect you to a fake website, or at best it will be clickbait. Don’t click on links. Check the promotions on the official website of a given store and enter the address yourself.

How to protect employees against phishing?

Companies are particularly vulnerable to the phishing attacks discussed above. Each period brings many cybersecurity challenges as hackers use any excuse to attack a company, and the most common tool they choose is phishing. What determines whether the attack will be successful?

Somewhat stubborn and determined by hackers, but many attacks can be repelled by well-prepared and attentive employees. Practical defense training, education and awareness of cyber threats can prepare your employees to resist most attacks. We encourage you to use a proven tool – Practical Anti-Phishing Training.

Does your team know how to spot phishing? Let’s check it out!