How's the 'phishing'? Sneaky email attacks not only more common but also harder to distinguish from real ones —even from co-workers

How’s the ‘phishing’? Sneaky email attacks not only more common but also harder to distinguish from real ones —even from co-workers

  • Peninsula Daily News news services
  • Monday, August 19, 2013 5:12pm
  • News

Peninsula Daily News news services

PORT ANGELES — At least 2 million people, many of them on the North Olympic Peninsula, received a recent email notifying them that an order they had just made on “Wallmart’s” website was being processed, though none of them had done any such thing.

Still, thousands of people clicked on the link in the email, taking many of them to a harmless Google search-results page for “Walmart.”

Others weren’t so fortunate.

The link led to the invisible download of malware that covertly infected their personal computers, turning them into remotely controlled robots for hackers, according to email security firm Proofpoint.

These sorts of “phishing” attacks are not only becoming more common but also are getting more lethal, with fake emails becoming harder to distinguish from real ones.

In the fake-Walmart attack, people missed clear warning signs — such as the company name being misspelled and the sender’s address being very long and strange.

But in another recent case, an email claiming to be from American Airlines carried no visible hints that it was illegitimate.

The sophisticated attacks are targeting the likes of attorneys, oil executives and managers at military contractors.

The phishers are increasingly trying to get proprietary documents and pass codes to access company and government databases.

Nearly every incident of online espionage in 2012 involved some sort of a phishing attack, according to a survey compiled by Verizon, the nation’s largest wireless carrier.

Several recent breaches at financial institutions, media outlets and in the video-game industry have started with someone’s login information being entered on a false website that was linked to in an email.

When an Associated Press staff member received an email in April that appeared to be from a colleague, the individual didn’t hesitate to click on the link.

But that link led to the installation of a “key logger” that enabled a hacker to monitor keystrokes and see the password for The Associated Press’ Twitter account.

The hacker posted a tweet from the account saying that someone had bombed the White House.

As investors reacted to the tweet, the S&P 500 index’s value fell $136 billion.

The parody news site the Onion fell prey to a similar, though less costly, attack.

Chandra McMahon, the chief information-security officer for military-technology giant Lockheed Martin, said phishing attacks aimed at its employees try to replicate emails and websites of industry organizations that its employees visit on a regular basis.

“They are compromised by adversaries because they are the perfect spot to put malware because a lot of the employees from the industry will go there,” McMahon said.

As technology firms find ways to make emails safer for consumers, some security experts suggest treating every link skeptically.

How to avoid trouble

So if you can never click on a link in an email again, what options are left?

Here are some suggestions from security experts:

■   Open links on an email app on Apple’s iPad or iPhone.

These devices have fewer vulnerabilities so malware is unlikely to stick or get attached by clicking on a bad link.

Android devices aren’t as foolproof, but smartphones certainly have fewer holes than personal computers.

■   A few tech companies are promoting a new technology known as Domain-based Message Authentication, Reporting & Conformance, or DMARC.

It offers users a visual indication that an email is coming from the legitimate vendor.

For example, real emails from eBay in Gmail include a key next to the “from” field.

In Microsoft’s Outlook, a green key is the sign.

Despite a push from firms such as email-security provider Agari Data, not every major company has joined this effort.

Other companies are taking different approaches.

Wal-Mart Stores, for one, is devising its own tool.

Others are trying to block bad emails from reaching the inbox by harnessing the power of big data to see whether a message has the right context clues, anyone’s ever received a similar email or whether the sender’s ever been replied to.

With the warnings about these sophisticated and consequential attacks starting to grow, it’s possible employees could start facing repercussions for not being cautious with links.

Peter Toren, a former Justice Department computer-crimes prosecutor, said he hasn’t heard of any companies firing someone for introducing malware into a corporate system by clicking a link.

But he said a company might eventually have to make an example of someone.

“They certainly wouldn’t sue an employee because they don’t have deep pockets to pay a claim,” Toren said.

“But it certainly could be grounds for termination. You failed to listen to us. You failed to follow training.”

More in News

Crews work to remove metal siding on the north side of Field Arts & Events Hall on Thursday in Port Angeles. The siding is being removed so it can be replaced. (Dave Logan/for Peninsula Daily News)
Siding to be replaced

Crews work to remove metal siding on the north side of Field… Continue reading

Tsunami study provides advice

Results to be discussed on Jan. 20 at Field Hall

Chef Arran Stark speaks with attendees as they eat ratatouille — mixed roasted vegetables and roasted delicata squash — that he prepared in his cooking with vegetables class. (Elijah Sussman/Peninsula Daily News)
Nonprofit school is cooking at fairgrounds

Remaining lectures to cover how to prepare salmon and chicken

Port Townsend Main Street Program volunteers, from left, Amy Jordan, Gillian Amas and Sue Authur, and Main Street employees, Sasha Landes, on the ladder, and marketing director Eryn Smith, spend a rainy morning decorating the community Christmas tree at the Haller Fountain on Wednesday. The tree will be lit at 4 p.m. Saturday following Santa’s arrival by the Kiwanis choo choo train. (Steve Mullensky/for Peninsula Daily News)
Decoration preparation

Port Townsend Main Street Program volunteers, from left, Amy Jordan, Gillian Amas… Continue reading

Port Angeles approves balanced $200M budget

City investing in savings for capital projects

Olympic Medical Center Board President Ann Henninger, left, recognizes commissioner Jean Hordyk on Wednesday as she steps down after 30 years on the board. Hordyk, who was first elected in 1995, was honored during the meeting. (Paula Hunt/Peninsula Daily News)
OMC Commissioners to start recording meetings

Video, audio to be available online

Jefferson PUD plans to keep Sims Way project overhead

Cost significantly reduced in joint effort with port, city

Committee members sought for ‘For’ and ‘Against’ statements

The Clallam County commissioners are seeking county residents to… Continue reading

Christopher Thomsen, portraying Santa Claus, holds a corgi mix named Lizzie on Saturday at the Airport Garden Center in Port Angeles. All proceeds from the event were donated to the Peninsula Friends of Animals. (Dave Logan/for Peninsula Daily News)
Santa Paws

Christopher Thomsen, portraying Santa Claus, holds a corgi mix named Lizzie on… Continue reading

Peninsula lawmakers await budget

Gov. Ferguson to release supplemental plan this month

Clallam County looks to pass deficit budget

Agency sees about 7 percent rise over 2025 in expenditures

Officer testifies bullet lodged in car’s pillar

Witness says she heard gunfire at Port Angeles park