Snapchat Employee Data Leaks Out Following Phishing Attack
41–50 of 62 posts
Re: Snapchat Employee Data Leaks Out Following Phishing Attack
#42Re: Snapchat Employee Data Leaks Out Following Phishing Attack
#43Earlier quoted context omitted.
Social engineering attacks will probably be a thorn in security's side for a very long time, if not indefinitely... There's a sort of fundamental disconnect inherent in "Trust the system! It's secure! Except be careful because sometimes something that is not the system will pretend to be the system..."
We keep treating falling for phishing emails as a user error. But, perhaps, having our most "official" means of communicating online (email) be a protocol that has no identity verification, no authentication and no encryption, is actually a technical bug, not a human one. I mean, you would expect that we should at least be able to tell that if you get a x@snapchat.com email in your y@snapchat.com inbox, it actually c…
Maybe it's time to start something like an SPF Everywhere campaign.
Re: Snapchat Employee Data Leaks Out Following Phishing Attack
#44Re: Snapchat Employee Data Leaks Out Following Phishing Attack
#45Minor rant: The 401(k) provider regularly sends a plaintext deposit confirmation email (deposit amount, confirmation number) with each payroll cycle. Any time a change in contribution amount is changed, they send a plaintext email with the new contribution percentage. Occasionally they send plaintext statements containing dividend amounts.
When asked to stop sending these e-mails, the 401(k) administrator replied that it wasn't possible, supposedly due to the way they integrate with they integrate with a 3rd party mail provider. (what?)
Re: Snapchat Employee Data Leaks Out Following Phishing Attack
#46Earlier quoted context omitted.
We keep treating falling for phishing emails as a user error. But, perhaps, having our most "official" means of communicating online (email) be a protocol that has no identity verification, no authentication and no encryption, is actually a technical bug, not a human one. I mean, you would expect that we should at least be able to tell that if you get a x@snapchat.com email in your y@snapchat.com inbox, it actually c…
I thought we had this through SPF. Ie. Your mail server can reject mail if the domain doesn't match spf records in dns. Maybe it's time to start something like an SPF Everywhere campaign.
Hell, if I get bob@company.com on my Gmail inbox, I cannot really tell whether even the @company.com part has been authenticated or not. There isn't even an HTTPS like lock icon or anything, let alone a "Google has verified that this email comes from Amazon.com" assurance.
Re: Snapchat Employee Data Leaks Out Following Phishing Attack
#47Earlier quoted context omitted.
Sending requests by mail with official looking letterheads for example.
Or fake invoices. I get them regularly.
http://consumerist.com/2016/02/04/arizona-wendys-jack-in-the...
An unknown person told the manager on the phone that they were with the fire department and needed to conduct a diagnostic test on the fire system, police said. The manager followed instructions and turned on the restaurant’s fire suppression system. The caller then said what the manager had done had caused a gas leak, so everyone had to evacuate the restaurant and the employee was told to break all the windows to avoid an explosion.
Wendy’s employees complied and smashed every single window, while waiting for the fire department to show up. Once officials arrived, they confirmed the call was a hoax.
Re: Snapchat Employee Data Leaks Out Following Phishing Attack
#48Every company should inform their employees of the email impersonation scams going around. > In the scam, a criminal mimics a chief executive’s email account and directs an employee to wire money to an overseas bank account. By the time the company realises it has been duped, the money is gone. > [This scam] has cost businesses around the globe more than $2bn in little over two years, according to the US Federal Bure…
I'd go a step further and say it's a failing of management and process at said company if any employee felt that the CEO emailing for payroll information was "normal".
As the company scales, we may add other people like a CFO to the bank account, but we will always require two people to authorize wire transfers.
Re: Snapchat Employee Data Leaks Out Following Phishing Attack
#49The most effective part of our program is the internal phishing attempts. They aren't annually or quarterly but almost monthly and sometimes weekly. It works very, very well and keeps phishing at the top of everyone's mind. There is nothing quite like teaching someone how easy it is to be caught off guard by showing them how easily someone can be phished and how they took the bait. It disarms them and the ego part of the conversation. It makes it a psychologically safe element of the corporate culture. It changes the conversation from "You're a dummy It's an interesting part of our security awareness program. In fact, we've built out a small application that sends the phishing email with a remote to track the email view(see the bait).
We then track them hitting the link through a unique URL (taking the bait), and track the final push of a login button or web-form (swallowing the hook entirely.)
It allows us to track how effective the campaign is and understand who may need some remedial training and of course how we can better improve the security awareness training because if a high percentage take the bait, the security awareness training wasn't effective.
In fact, I sent this article around the office this afternoon and sometime mid-week, plan to send another phishing attempt to see if it helped.
This strategy of course requires an organization to be fairly emotionally intelligent and have the right corporate culture. One of trust and transparency in a psychologically safe environment where people aren't mocked or made fun of but properly educated if they take the bait. I know that this kind of culture may not be the norm.
NOTE: We don't have as much to secure as a SnapChat and we aren't a high profile target. We just figured these things were the bare-minimum things to do to protect our employees and our customers.
Re: Snapchat Employee Data Leaks Out Following Phishing Attack
#50Its much easier to teach people to access their emails using a particullar application then it is to make them aware for phising attacks which sometimes can be very sophisticated.
While this does not work if you have to receive emails from unknowns, it is a no brainer to use something like this at a comapny level for all online communication. In my opinion not doing so is really careless behaviour especially for a tech company...