In an ocean of messages, it’s easy to mistake bait for the real thing – especially now criminals are using AI to up their game and make fakes even more believable. It’s important to remind yourself and your team that there’s more than one way to fish for information, and that these ‘ishing’ attacks are happening all the time.

PHISHING

L'invio di email fraudolente che incoraggiano i destinatari a cliccare su un link che scarica malware o raccoglie dati personali o aziendali.

SPEAR-PHISHING

È come il phishing, ma è molto più mirato. L'email include (o sembra includere) dettagli rilevanti per il destinatario per renderla più credibile.

QUISHING

Si tratta di phishing con un codice QR stampato su un oggetto, sullo schermo o all'interno di un'email. Se lo scansionate, vi porta al sito fraudolento.

VISHING

The same principles apply – this is when bad actors make fake calls or leave voice messages to get people to go a website that will download malware or gather illicit data.

SMISHING

Yes, you get the idea – this is phishing, but using fake SMS messages. Fraudsters send a text message with a link to their data-harvesting website.

Employee awareness is essential in preventing ‘ishing’ attacks

Training is all well and good – but over time, the key points can be forgotten, complacency sets in, new team members join… Everything changes over time.

But the need for vigilance doesn’t ever change. Like any other security or safety measure, phishing awareness needs to be embedded so that it becomes second nature. And that takes practice.

Libraesva PhishBrain vi permette di inviare email realistiche di "falso phishing", in modo da individuare le aree di rischio maggiori, misurare l'efficacia della formazione e rafforzare la consapevolezza e i comportamenti di sicurezza in tutta l'azienda.

Interested in learning more?