{"id":42,"date":"2018-10-26T08:29:00","date_gmt":"2018-10-26T08:29:00","guid":{"rendered":"https:\/\/cms.digitalbes.com\/?p=42"},"modified":"2018-10-26T08:29:00","modified_gmt":"2018-10-26T08:29:00","slug":"phishing-attacks-why-is-email-still-such-an-easy-target-for-hackers","status":"publish","type":"post","link":"https:\/\/cms.digitalbes.com\/?p=42","title":{"rendered":"Phishing attacks: Why is email still such an easy target for hackers?"},"content":{"rendered":"<p>Phishing attacks: Why is email still such an easy target for hackers?\u00a0The majority of cyber attacks begin with one simple phishing email. So will it ever be possible to close this door to hackers, once and for all?<\/p>\n<p>Email is incredibly useful, which is why we all still use it. But chief among its downsides (along with getting caught in a group-cc\u2019d message hell) is that email remains one of the most common routes for hackers to attack businesses.<\/p>\n<p>Around\u00a0one in every hundred messages sent is a malicious hacking attempt.\u00a0That might not seem like a large figure, but when millions of messages are sent every day, it adds up \u2014 especially when it just takes one employee to fall victim to a phishing message and potentially lead to a whole organisation being compromised.<\/p>\n<p>For example,\u00a0the cyber attack against the Democratic National Committee\u00a0that led to thousands of private emails being exposed in the run up to the US Presidential election started with just one successful phishing email, while countless\u00a0espionage and malware campaigns\u00a0have also gained entry to organisations via an email-based attack.<\/p>\n<p>But if email leaves us so vulnerable to attempts at hacking, why do we stick with it?<\/p>\n<p>\u201cEmail is still the main way that two entities who may not have a relationship get together and communicate. Whether it\u2019s a law firm communicating with a business or a candidate applying for a job, email is still the bridge to getting these entities communicating. It\u2019s not going away,\u201d says Aaron Higbee, co-founder and CTO at anti-phishing company Cofense.<\/p>\n<p>As long as email is here, phishing will also remain a problem \u2014 and while some phishing campaigns are really sophisticated and based around cyber criminals performing deep reconnaissance on targets, other email-based attacks aren\u2019t so sophisticated \u2014 and yet are still worryingly successful.<\/p>\n<p>Locky ransomware was often delivered to targets in blank phishing messages\u00a0containing just an attachment. In the vast majority of cases, people didn\u2019t open this, but given how Locky was successful, it\u2019s evident that a number of people did. Why did they click the attachment in a blank message?<\/p>\n<p>\u201cAt the end of the day, we\u2019re people and sometimes we make mistakes. Even careful and aware people could and would click on malicious attachments. Why is that? Because education isn\u2019t enough; people will continue to click on things that look suspicious,\u201d said Liron Barak, CEO and co-founder at security company Bitdam.<\/p>\n<p>\u201cWe can definitely see there\u2019s been a rise in email attacks in the last year. And something that I believe is that attackers are becoming more and more sophisticated \u2014 attacks are bypassing Microsoft, Gmail and other channels,\u201d she adds.<\/p>\n<p>Many phishing and spam messages do get blocked by mail providers but there are those that continue to sneak through \u2014 especially into consumer mailboxes, despite the efforts of email providers.<\/p>\n<p>While enterprises might not think too seriously about the actions their employees take using their personal inboxes, it could have serious consequences; not only is it likely that employees will examine their own emails at the office, many people use their personal email addresses to conduct business activity \u2014 and that\u2019s a security risk.<\/p>\n<p>\u201cOne of the lessons that comes up very regularly is that one thing people often do wrong is when they conduct official business out of a consumer mailbox as they often don\u2019t understand there\u2019s no defence there,\u201d says Matthew Gardiner, director of product at email security company Mimecast.<\/p>\n<p>\u201cThe lesson is to have good security defences on your business email and then use your business email for business, not your consumer email. Because once they\u2019re into your personal account, they could be\u00a0loading malware\u00a0onto the machine you use for both,\u201d he says.<\/p>\n<p>So, when this provides a potential risk to businesses, why is the security of some consumer mailboxes still so relatively poor compared with their enterprise cousins?<\/p>\n<p>\u201cOne of the sadder situations is here we are protecting the enterprise and they\u2019re getting the full focus and top knowledge to protect them \u2014 but then when you go down to consumers and even small businesses, they\u2019re not really looked after by the security industry,\u201d says Ken Bagnall VP of email security at FireEye.<\/p>\n<p>There\u2019s also the fundamental problem around email that it\u2019s relatively simple to spoof names and addresses, allowing attackers to claim to be anyone \u2014 perhaps celebrities offering prizes or\u00a0your boss asking you to look at a document or to make a transfer.<\/p>\n<p>\u201cThere\u2019s really no embedded security in the basic internet for email. So you can claim to be anyone and send an email and the average person will probably trust that,\u201d says Gardiner.<\/p>\n<p>Add to that how the make-up of phishing messages is changing all the time and you have an evolving problem.<\/p>\n<p>\u201cWhile we continually evaluate and improve our automated screening protocols to help protect users, spam is an industry-wide ongoing challenge. Bad actors and opportunistic promoters quickly alter their approaches, which makes it difficult for any vendor to address 100 percent of spam,\u201d says Jeff Jones, senior director at Microsoft.<\/p>\n<p>There\u2019s even\u00a0whole underground marketplaces\u00a0dedicated to conducting phishing attacks, with professional hackers offering their services to crack specific inboxes.<\/p>\n<p>\u201cTrying to guess what the next step of the attackers will be will always leave us behind, because there\u2019s someone else controlling the landscape and trying to evade us and thinking strategically about bypassing security,\u201d says Bitdam\u2019s Barak.<\/p>\n<p>Much of the issue lies with the fundamental way in which email works and how this method of communication has become so pervasive in our everyday lives.<\/p>\n<p>\u201cFor email based phishing to really go away, we\u2019re going to have to come together as a world and say this email protocol that was designed decades ago, it just isn\u2019t working anymore,\u201d says Higbee.<\/p>\n<p>There is one system that could help and it\u2019s called DMARC \u2014 short for \u201cDomain-based Message Authentication, Reporting &amp; Conformance.\u00a0It\u2019s an email authentication protocol\u00a0that enables users to determine what a legitimate email is and what\u2019s spam, complete with a reporting function for ongoing improvement and protection.<\/p>\n<p>Many have argued that it would massively release spam, but\u00a0it still isn\u2019t widely used in industry\u00a0as it can be tricky to implement, actually blocking all messages if set up incorrectly.<\/p>\n<p>Another solution to this could be a reputation score system \u2014 something that Dr Ian Levy, technical director at the UK\u2019s National Cyber Security Agency (NCSC) wants to encourage the industry to pick up. He argues that it could make differentiating between trusted sources and malicious sources much easier for users \u2014 therefore reducing the risk of phishing attacks.<\/p>\n<p>\u201cWe\u2019re trying to get the industry to do a reputation score,\u201d he says. For example, if an email address has been in use for years, has never sent a bad message that\u2019s one thing; an email address registered today via a Tor node sending its first email may be something that should be treated with a little more caution, he argues.<\/p>\n<p>\u201cWe want to give people that reputation information about email accounts so they can make decisions.\u201d<\/p>\n<p>But for now, this is just an idea and phishing attacks against email users are as successful as they ever were \u2014 and some are resigned to this continuing to be a problem for a long time to come.<\/p>\n<p>\u201cI saw my first phishing email professionally in 1998 \u2014 and if I thought I\u2019d still be working on this phishing problem in 2018, it would\u2019ve seemed unimaginable,\u201d says Cofense\u2019s Higbee. \u201cIt\u2019s such a huge challenge that in five or ten years from now, the email phishing problem will be the same as it is today.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Phishing attacks: Why is email still such an easy target for hackers?\u00a0The majority of cyber attacks begin with one simple phishing email. So will it ever be possible to close this door to hackers, once and for all? Email is incredibly useful, which is why we all still use it. But chief among its downsides [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-42","post","type-post","status-publish","format-standard","hentry","category-tech-news"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Phishing attacks: Why is email still such an easy target for hackers? - Digitalbes Limited Premium Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cms.digitalbes.com\/?p=42\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Phishing attacks: Why is email still such an easy target for hackers? - Digitalbes Limited Premium Blog\" \/>\n<meta property=\"og:description\" content=\"Phishing attacks: Why is email still such an easy target for hackers?\u00a0The majority of cyber attacks begin with one simple phishing email. So will it ever be possible to close this door to hackers, once and for all? Email is incredibly useful, which is why we all still use it. But chief among its downsides [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cms.digitalbes.com\/?p=42\" \/>\n<meta property=\"og:site_name\" content=\"Digitalbes Limited Premium Blog\" \/>\n<meta property=\"article:published_time\" content=\"2018-10-26T08:29:00+00:00\" \/>\n<meta name=\"author\" content=\"dbl\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"dbl\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=42#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=42\"},\"author\":{\"name\":\"dbl\",\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/#\\\/schema\\\/person\\\/501f983dd73df2b3abf7b41c11a10904\"},\"headline\":\"Phishing attacks: Why is email still such an easy target for hackers?\",\"datePublished\":\"2018-10-26T08:29:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=42\"},\"wordCount\":1312,\"commentCount\":0,\"articleSection\":[\"Tech News\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/cms.digitalbes.com\\\/?p=42#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=42\",\"url\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=42\",\"name\":\"Phishing attacks: Why is email still such an easy target for hackers? - Digitalbes Limited Premium Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/#website\"},\"datePublished\":\"2018-10-26T08:29:00+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/#\\\/schema\\\/person\\\/501f983dd73df2b3abf7b41c11a10904\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=42#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/cms.digitalbes.com\\\/?p=42\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=42#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/cms.digitalbes.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Phishing attacks: Why is email still such an easy target for hackers?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/#website\",\"url\":\"https:\\\/\\\/cms.digitalbes.com\\\/\",\"name\":\"Digitalbes Limited Premium Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/cms.digitalbes.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/#\\\/schema\\\/person\\\/501f983dd73df2b3abf7b41c11a10904\",\"name\":\"dbl\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/32bb84d38230af21f8f3323e55011359ebae16aa5c7b6554ae4fbbdc77b32582?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/32bb84d38230af21f8f3323e55011359ebae16aa5c7b6554ae4fbbdc77b32582?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/32bb84d38230af21f8f3323e55011359ebae16aa5c7b6554ae4fbbdc77b32582?s=96&d=mm&r=g\",\"caption\":\"dbl\"},\"sameAs\":[\"https:\\\/\\\/cms.digitalbes.com\"],\"url\":\"https:\\\/\\\/cms.digitalbes.com\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Phishing attacks: Why is email still such an easy target for hackers? - Digitalbes Limited Premium Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cms.digitalbes.com\/?p=42","og_locale":"en_US","og_type":"article","og_title":"Phishing attacks: Why is email still such an easy target for hackers? - Digitalbes Limited Premium Blog","og_description":"Phishing attacks: Why is email still such an easy target for hackers?\u00a0The majority of cyber attacks begin with one simple phishing email. So will it ever be possible to close this door to hackers, once and for all? Email is incredibly useful, which is why we all still use it. But chief among its downsides [&hellip;]","og_url":"https:\/\/cms.digitalbes.com\/?p=42","og_site_name":"Digitalbes Limited Premium Blog","article_published_time":"2018-10-26T08:29:00+00:00","author":"dbl","twitter_card":"summary_large_image","twitter_misc":{"Written by":"dbl","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/cms.digitalbes.com\/?p=42#article","isPartOf":{"@id":"https:\/\/cms.digitalbes.com\/?p=42"},"author":{"name":"dbl","@id":"https:\/\/cms.digitalbes.com\/#\/schema\/person\/501f983dd73df2b3abf7b41c11a10904"},"headline":"Phishing attacks: Why is email still such an easy target for hackers?","datePublished":"2018-10-26T08:29:00+00:00","mainEntityOfPage":{"@id":"https:\/\/cms.digitalbes.com\/?p=42"},"wordCount":1312,"commentCount":0,"articleSection":["Tech News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/cms.digitalbes.com\/?p=42#respond"]}]},{"@type":"WebPage","@id":"https:\/\/cms.digitalbes.com\/?p=42","url":"https:\/\/cms.digitalbes.com\/?p=42","name":"Phishing attacks: Why is email still such an easy target for hackers? - Digitalbes Limited Premium Blog","isPartOf":{"@id":"https:\/\/cms.digitalbes.com\/#website"},"datePublished":"2018-10-26T08:29:00+00:00","author":{"@id":"https:\/\/cms.digitalbes.com\/#\/schema\/person\/501f983dd73df2b3abf7b41c11a10904"},"breadcrumb":{"@id":"https:\/\/cms.digitalbes.com\/?p=42#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cms.digitalbes.com\/?p=42"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/cms.digitalbes.com\/?p=42#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cms.digitalbes.com\/"},{"@type":"ListItem","position":2,"name":"Phishing attacks: Why is email still such an easy target for hackers?"}]},{"@type":"WebSite","@id":"https:\/\/cms.digitalbes.com\/#website","url":"https:\/\/cms.digitalbes.com\/","name":"Digitalbes Limited Premium Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cms.digitalbes.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/cms.digitalbes.com\/#\/schema\/person\/501f983dd73df2b3abf7b41c11a10904","name":"dbl","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/32bb84d38230af21f8f3323e55011359ebae16aa5c7b6554ae4fbbdc77b32582?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/32bb84d38230af21f8f3323e55011359ebae16aa5c7b6554ae4fbbdc77b32582?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/32bb84d38230af21f8f3323e55011359ebae16aa5c7b6554ae4fbbdc77b32582?s=96&d=mm&r=g","caption":"dbl"},"sameAs":["https:\/\/cms.digitalbes.com"],"url":"https:\/\/cms.digitalbes.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=\/wp\/v2\/posts\/42","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=42"}],"version-history":[{"count":0,"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=\/wp\/v2\/posts\/42\/revisions"}],"wp:attachment":[{"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=42"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=42"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=42"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}