How good is your Password?
Test it.
Are you safe?
EdTech Conference
2024
“Dear valued customer,”
You have been Phished!
By: Sarah and Malie Tupou
Objective:
Identifying phishing scams, thus preventing you from being phished!
The Facts
2013 - Cryptolocker ransomware infected 250,000 personal computers
According to Microsoft, some of the innovative ways they’ve seen phishing attacks evolve so far in 2020 include: Pointing email links to fake Google search results that point to attacker-controlled malware-laden websites, pointing email links to non-existent pages on an attacker-controlled website so that a custom 404 page is presented that can be used to mimic logon pages for legitimate sites, spoofing company-specific Office 365 sign-in pages to look so realistic that users would think it's the real thing.
3.4 billion phishing emails daily | 83% of companies experience phishing attacks | 36% of all data breaches involve phishing | every 11 sec phishing attack |
https://www.getastra.com/blog/security-audit/phishing-attack-statistics/
Here are the top most intriguing recent phishing attacks statistics you should be aware of in 2024.
3.
2.
84% of US-based organizations have stated that conducting regular security awareness training has helped reduce the rate at which employees fall prey to phishing attacks.
92% of Australian organizations suffered a successful phishing attack, showing a 53% increase from the year 2021.
4.
Highly impersonated brands for phishing are Amazon and Google at 13%, Facebook and Whatsapp at 9%, and Netflix and Apple at 2%.
5.
Breaches caused by phishing took the third longest mean time to identify and contain at 295 days according to IBM’s 2022 Data Breach Report.
What is Phishing? What can happen if you are phished?
Personal phishing risks include:
At work, phishing risks include:
https://www.cisco.com/c/en/us/products/security/email-security/what-is-phishing.html#~ai-and-phishing
Phishing Techniques
4 techniques commonly used when phishing
Session Hijacking
Spear Phishing
Content Injection
Link Manipulation
In session hijacking, phishers exploit web session controls to steal user information, often using sniffers to intercept data for illegal access.
Spear phishing is a targeted email attack that uses personalized details to deceive a specific person or organization into compromising their security.
Content injection involves a phisher altering part of a trusted website's content to redirect users to a fraudulent page, prompting them to enter personal information.
Link manipulation is when a phisher sends a deceptive link, redirecting users to their own malicious website, often revealed by hovering over the link.
3 Stages of Phishing
Step 1: Bait
Step 2: Hook
Step 3: Catch
Gathering target details to create convincing bait
Promising rewards or instilling fear in the target
Send the email and then exploit gained access for more attacks
Activity QR code
Empower Your Users:
Highest Score Wins!
Using the rules sheet, look at the points for both the techniques and red flags and score this example
Example:
phishing.learn45@gmail.com
Email: phishing.learn45@gmail.com
Take Aways
You and Students: Change password every year
When, Where and Why inputting data
Keep devices updated
Pause and Think
*AI is
empowering
phishing
References
Feedback Form