Endpoint

9/8/2017
12:00 PM
Kelly Sheridan
Kelly Sheridan
Slideshows
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

7 Tips to Fight Gmail Phishing Attacks

Popular email platforms like Gmail are prime phishing targets. Admins can adopt these steps to keep attackers at bay.
Previous
1 of 8
Next

(Image: wk1003mike via Shutterstock)

(Image: wk1003mike via Shutterstock)

Phishing is not a new threat to the enterprise, but it is becoming subtler and more complex as threat actors adopt new strategies to trick their chosen victims.

"Phishing attacks are much more focused, more targeted," explains Mark Risher, director of product management for Google Sign-In, Abuse, and API. "It's no longer about broad-based, opportunistic attacks … now, the phisher is doing his or her homework."

Today's attackers know their victims and learn enough about their circumstances to add credible details to their attacks. Everyone in the consumer space is a potential target, says Risher, who says phishers cast a "fairly wide net" to achieve their goals.

"We have definitely seen a rise in sophistication of phishing attacks over the past few years and a shift toward 'quality' over 'quantity,'" says Amy Baker, vice president of marketing at Wombat Security. Broad-based attacks are still happening, but spearphishing and BEC are on the rise.

"Cybercriminals are increasingly using social media channels to mine for data and lay the groundwork for high-value attacks," Baker continues. "In these situations, we see multi-faceted approaches that incorporate social engineering techniques outside of email that ultimately make an email communication more believable."

Hackers want to take advantage of users' familiarity with Gmail, and other products from high-visibility organizations like Amazon and Facebook. If they can't get a phishing email through corporate safeguards, they know users have fewer barriers on their personal accounts.

"If an employee makes a personal mistake while on a corporate network, that's a win for an attacker," says Baker.

Aaron Higbee, cofounder and CTO at PhishMe, says many pieces of traditional phishing advice still hold true: watch for misleading URLs and don't click on suspicious documents.

However, Gmail users can take precautions by adjusting permissions - one of the tips Google shares in a blog post on the subject.

Here are ways to reduce the risk of phishing attacks specific to Gmail users.

 

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Previous
1 of 8
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
NeilB915
50%
50%
NeilB915,
User Rank: Apprentice
9/12/2018 | 2:21:32 AM
Gmail Password Reset
Thank you for providing such an useful tips to fight with Gmail Phishing Attacks. It really helpful for us to avoiding this type of attack & make our account secure. If still you are facing this issue after using this above tips, then i would like to suggest you to make a contact with Gmail Password Reset Team.

 

Higher Education: 15 Books to Help Cybersecurity Pros Be Better
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
'PowerSnitch' Hacks Androids via Power Banks
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/8/2018
Worst Password Blunders of 2018 Hit Organizations East and West
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: camera, camera everywhere, not a single news to rely on
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-16873
PUBLISHED: 2018-12-14
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go package, or a package that imports it directly or indirectly. Specifically, it is only vulnerable in GOPATH mode, b...
CVE-2018-16874
PUBLISHED: 2018-12-14
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the import path of a malicious Go package which contains curly braces (both '{' and '}' characters). Specifically, it is only vulnerable in GOPATH mode, but not in mod...
CVE-2018-16875
PUBLISHED: 2018-12-14
The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers accepting client certificates and TLS clients are ...
CVE-2018-14623
PUBLISHED: 2018-12-14
A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix for CVE-2016-3072. Version 3.10 and older is vulne...
CVE-2018-18093
PUBLISHED: 2018-12-14
Improper file permissions in the installer for Intel VTune Amplifier 2018 Update 3 and before may allow unprivileged user to potentially gain privileged access via local access.