Three in 10 employees fall for test-phishing done by their bosses
Sunday, 25 August 2019
It's not only crooks who phish company employees. Some bosses do it too.
The risks of a company's employees being phished was highlighted after two Air New Zealand employees got tricked by phishing emails into handing over data that revealed personal information of 112,000 airpoints customers.
Phishing is the word used for crooks sending fake communications via email, and sometimes social media channels, in a bid to get people to hand over valuable information such as passwords to company systems, or the email addresses of their customers.
Ben Morgan, managing director of technology company Accenture Interactive New Zealand, said it was far better for bosses to work out the weak links in their workforce by phishing their own employees than waiting for a real phishing attack to reveal them.
**READ MORE:
* Customers could face long-term privacy issues after Air New Zealand phishing fail
* Fears Airpoints members' personal information leaked
* Tracking the data breach that gave crooks my credit card details
* All you need to know about the proposed privacy laws**
Accenture sends fake phishing attacks to its own staff and a shocking number of employees at all levels of the company fall for them, Morgan said.
'About 30 per cent of people click on it because it doesn't take much to make it look and feel close enough.'
One tactic used by employers was to block the passwords of any employees who fell for a test-phish until they had completed a training module to reduce the chance of them falling for a real malicious phishing attack.
Phishing was the single most common form of cyber attack, said Morgan.
Cert NZ, the government cyber-security agency, says of the nearly 1000 reported cyber attacks on organisations reported in the first three months of the year, 45 per cent were phishing attacks.
Despite the threat, many organisations are not doing a good job of training employees to spot phishing attacks.
Companies had focused their cyber security defences on stopping hackers attacking their systems against direct 'brute force', Morgan said.
Much less effort was being put into training up employees to stop them falling for phishing attacks.
Morgan said many organisations spent more on training staff on their social media policies than they did on anti-phishing training.
Accenture' market-testing indicated around 7-10 per cent of cyber security budget was spent training employees.
'One of the most common types of unauthorised access is business email compromise,' according to Cert NZ 's latest quarterly report. 'This is when an attacker gains access to an employee’s email account and carries out a range of scams or attacks, like sending phishing emails or fake invoices to the business’s contacts, usually to access private or financial information.'
It may not be immediately obvious that a breach has taken place.
Sometimes attackers who had gained access to an employee's emails monitored for payment-related emails from goods and service providers, to understand the business’ billing cycles, Cert NZ said.
'The attackers then replicate and send legitimate-looking invoices mirroring the business’ behaviour. These invoices can be hard to detect as often the only difference is that the bank account details have been swapped out to direct the payment to the attacker’s account instead.'
The attacks were only going to intensify, Cert NZ predicted.
Not all phishing attacks were done through email, Morgan said. Approaches were sometimes made through social media channels like WhatsApp.
Morgan said there was a growing awareness from organisations that 'digital minimalism', where they only collect the data they really need from customers, was important.
'There's a real shift away from collecting as much data as possible,' Morgan said.
'We are seeing a real shift as when these hacks happen, organisations are struggling to justify why they are holding as much information as they have,' he said.
An earlier version of this article incorrectly stated that Accenture organises fake phishing attacks for organisations.