Free Phishing Test
CYBER THREATS

Phishing – The Greatest Modern Threat on the Internet

02-oct-2022 4 minutes read

What is phishing?

Although the word itself may sound harmless, phishing describes dangerous fraud based on manipulation and deliberately misleading the recipient.

Phishing is a human-targeted attack in which a hacker uses social engineering and deception to persuade a victim to take a specific action, such as:

  • clicking a link;
  • sharing login credentials, such as a username and password;
  • sharing payment-card details;
  • making a transfer;
  • providing personal data, such as a name, PESEL number, identity-document details, date of birth or mother’s maiden name, which may be used to authenticate someone elsewhere;
  • downloading an infected attachment;
  • sending a file containing specific information;
  • sending other information that may appear confidential or insignificant;
  • installing malware;
  • installing remote-management software and giving the attacker access to the device.

Sometimes a cybercriminal begins by building a relationship that will make the later attack more credible and help them achieve their goal. They may use principles of social influence—such as authority, reciprocity, liking, commitment and consistency—as well as emotional manipulation.

Phishing methods

A hacker can try to “hook” a victim through a range of electronic communication channels:

  • Email—the most common channel for mass campaigns and targeted attacks such as spear phishing;
  • SMS;
  • messaging apps such as WhatsApp;
  • social media and online games;
  • phone calls.

Social engineering can also take place face to face or through traditional mail and leaflets. A criminal might even deliver a USB drive containing malware or a mug with a hidden microphone, disguised as a gift from a business partner.

Phishing traps and pretexts

Hackers use many channels and attack in many ways. They target employees to gain access to companies, steal money and obtain private information.

They impersonate well-known brands, institutions and organizations—banks, social-media platforms, everyday apps, shops, auction sites, energy and courier companies, and government bodies such as tax offices, ZUS and the National Health Fund. They may pose as either sellers or buyers.

Criminals create messages and websites that closely imitate legitimate ones. They use them to persuade recipients to disclose data or perform a specific action. Common pretexts include an unpaid invoice, a prize, an inheritance or an extra payment for a parcel.

It is impossible to list every phishing scenario. Attackers constantly develop and refine their methods, adapting them to current events and trends in Poland and around the world. During the COVID-19 pandemic, campaigns commonly referred to:

  • an urgent update to the company’s security policy, with a link to a file that installed malware;
  • redundancies caused by the company’s difficult financial situation;
  • offers of COVID-19 medication;
  • vaccination appointments before vaccines were widely available;
  • fake COVID-19 test results.

Examples of phishing attacks

Help with voting

After hijacking a social-media account, hackers use it to contact people on the victim’s friends list. The message often asks the recipient to vote at a supplied link or claims that compromising photos have been leaked.

Example of a phishing message asking the recipient to vote
Source: CERT

Example of a phishing message

Online-banking login theft and stolen funds

After clicking a link sent by a cybercriminal, the user is redirected to a fake online-banking login page. Entering their details gives the attacker access to the bank account and may allow the funds to be stolen.

Example of a fake online-banking login page
Source: CERT

Courier company: an extra payment for a parcel

The message does not identify a specific brand and omits whether the recipient is the sender or recipient of the parcel. This ambiguity is likely intended to make the pretext feel relevant to more people.

Example of a parcel-delivery phishing message

Notification from a government website

The user is told that a notification is waiting on a government website and that a copy is attached. In reality, the attachment is an archive containing a malicious script that infects the system when opened.

Example of a fake government notification
Source: CERT

How to recognize phishing?
8 tips for your team!

Gain specialised knowledge about cybersecurity

Build a resilient cybersecurity culture with our support

Let's discuss your organization's cyber needs

Fill in the form

Would you like to test the resilience of your systems?

Fill in the form to schedule a free, no-obligation consultation. We will discuss the scope of the penetration tests and prepare a proposed approach tailored to your organization and infrastructure.
Would you prefer to speak to us directly?
+48 732 123 579