Thursday, September 19, 2019

Word of the Day: whaling attack

 
Word of the Day WhatIs.com
Daily updates on the latest technology terms | September 19, 2019
whaling attack (whaling phishing)

A whaling attack, also known as whaling phishing or a whaling phishing attack, is a specific type of phishing attack that targets high-profile employees, such as the CEO or CFO, in order to steal sensitive information from a company, as those that hold higher positions within the company typically have complete access to sensitive data. In many whaling phishing attacks, the attacker's goal is to manipulate the victim into authorizing high-value wire transfers to the attacker.

The term whaling stems from the size of the attacks, and the whales are thought to be picked based on their authority within the company.

Due to their highly targeted nature, whaling attacks are often more difficult to detect than standard phishing attacks. In the enterprise, security administrators can help reduce the effectiveness of whaling attacks by encouraging the corporate management staff to undergo information security awareness training.

How whaling attacks work

The goal of a whaling attack is to trick an individual into disclosing personal or corporate information through social engineering, email spoofing and content spoofing efforts. For example, the attackers may send the victim an email that appears to be from a trusted source; some whaling campaigns include a customized malicious website that has been created especially for the attack.

Whaling attack emails and websites are highly customized and personalized, and they often incorporate the target's name, job title or other relevant information gleaned from a variety of sources. This level of personalization makes it difficult to detect a whaling attack.

Whaling attacks often depend on social engineering techniques, as attackers will send hyperlinks or attachments to infect their victims with malware or to solicit sensitive information. By targeting high-value victims, especially CEOs and other corporate officers, attackers may also induce them to approve fraudulent wire transfers using business email compromise techniques. In some cases, the attacker impersonates the CEO or other corporate officers to convince employees to carry out financial transfers.

These attacks can fool victims because attackers are willing to spend more time and effort constructing them due to their potentially high returns. Attackers will often use social media, such as Facebook, Twitter and LinkedIn, to gather personal information about their victim to make the whaling phishing attack more plausible.

Differences between phishing, whaling phishing and spear phishing

Because ordinary phishing attacks, whaling phishing attacks and spear phishing attacks are all online attacks on users in order to gain sensitive information or to social engineer the victim into taking some harmful action, the three are often confused.

A whaling attack is a special form of spear phishing that targets specific high ranking victims within a company. Spear phishing attacks can target any specific individual. Both types of attack generally require more time and effort on the part of the attacker than ordinary phishing attacks.

Phishing is a broader term that covers any type of attack that tries to fool a victim into taking some action, including sharing sensitive information, such as usernames, passwords and financial records for malicious purposes; installing malware; or completing a fraudulent financial payment or wire transfer. While ordinary phishing attacks usually involve sending emails to a large number of individuals without knowing how many will be successful, whaling phishing attacks usually target one specific individual at a time -- typically a high-ranking individual -- with highly personalized information.

Examples of whaling attack

One notable whaling attack occurred in 2016 when a high-ranking employee at Snapchat received an email from an attacker pretending to be the CEO. The employee was tricked into giving the attacker employee payroll information; ultimately, the FBI investigated the attack.

Another whaling attack from 2016 involved a Seagate employee who unknowingly emailed the income tax data of several current and former company employees to an unauthorized third party. After reporting the phishing scam to the IRS and the FBI, it was announced that thousands of people's personal data was exposed in that whaling attack.

Quote of the Day

 
"Security awareness training for executives teaches an enterprise's biggest fish to recognize potential whaling attacks -- before they take the bait." - Alissa Irei

Learning Center

 

Security awareness training for executives keeps whaling at bay
To a cybercriminal, your CEO might look a lot like Moby Dick. Here's what you need to know about whaling attacks and how security awareness training for executives can help protect your organization's sensitive data.

Words to go: Email phishing security
Email phishing security poses a unique challenge to IT professionals because it's not easily addressed through software alone. Take critical precautionary measures to educate employees on cybersecurity awareness and the risks phishing attacks pose to the organization.

What are the top enterprise email security best practices?
From deploying security protocols to educating end users on how to protect themselves from malicious messages, enterprise email security best practices run the gamut. Learn how to keep your enterprise email secure.

Top 5 email security issues to address in 2019
The top five email security issues come from a variety of places security professionals need to monitor and address. Security consultant Kevin Tolly examines end-user behavior, targeted phishing attacks, account takeovers, IoT and mobile device challenges, and perimeter security.

How important is security awareness training for executives?
Security awareness training for executives is more important than ever as hackers try to find new ways to obtain important corporate secrets.

Quiz Yourself

 
The phishing email warned that unless I updated my contact information, my eBay account would be ______________.
a. canceled
b. cancelled

Answer

Stay in Touch

 
For feedback about any of our definitions or to suggest a new definition, please contact me at: mrouse@techtarget.com

Visit the Word of the Day Archives and catch up on what you've missed!

FOLLOW US

TwitterRSS
About This E-Newsletter
The Word of the Day is published by TechTarget, Inc., 275 Grove Street, Newton, Massachusetts, 02466 US.

Click to: Unsubscribe.

You are receiving this email because you are a member of TechTarget. When you access content from this email, your information may be shared with the sponsors or future sponsors of that content and with our Partners, see up-to-date Partners List, as described in our Privacy Policy. For additional information, please contact: webmaster@techtarget.com.

© 2019 TechTarget, Inc. all rights reserved. Designated trademarks, brands, logos, and service marks are the property of their respective owners.

Privacy Policy | Partners List
TechTarget

No comments: