Ep. 236 - The SE ETC Series - Vishing, Phishing and SMiShing...Oh My! - End of Year Threats
Nov 27, 2023
auto_awesome
Topics discussed in the podcast include QR code attacks, holiday scams and fraud prevention, personal experiences with phishing attacks, phone scams and gift card fraud, and strategies to protect against social engineering attacks.
During the holiday season, be cautious of smishing attacks (phishing attacks via SMS) which often involve messages about missed deliveries or payment problems.
Gift card scams are prevalent during the holiday season, where scammers impersonate someone known to the victim, manipulate emotions, and create a sense of urgency to trick individuals into purchasing gift cards and providing the codes.
Deep dives
Be cautious of smishing attacks, especially during the holidays
During the holiday season, smishing attacks (phishing attacks via SMS) become more prevalent. These attacks often involve messages about missed deliveries, customs fees, or problems with payments, enticing recipients to click on malicious links or provide sensitive information. Attackers take advantage of the increased online shopping and the use of mobile devices to target unsuspecting individuals. It's important to be extra cautious and verify any suspicious messages before taking any action. Be aware that legitimate organizations like banks or retailers will never request sensitive information or ask you to provide payment details via SMS. If in doubt, contact the organization directly using verified contact information to confirm the validity of the message.
Beware of gift card scams
Gift card scams are unfortunately common during the holiday season. Scammers often impersonate someone known to the victim, such as a friend, neighbor, or employer, and request the purchase of gift cards for various reasons. These scammers manipulate emotions and create a sense of urgency to trick individuals into buying gift cards and providing the codes over the phone or through email. Once the codes are obtained, scammers can quickly redeem the funds, leaving victims without recourse. It's essential to remember that legitimate entities will never ask for payment via gift cards. If someone asks you to purchase gift cards, take a moment to verify the request directly with the individual using a trusted method of communication.
Stay vigilant against phishing attempts
Phishing attacks, especially via email or phone calls, tend to increase during the holiday season. Scammers may exploit the holiday spirit and use tactics like pretending to be a charity seeking donations or alarming recipients with fake security alerts. They aim to deceive individuals into divulging personal information, clicking on malicious links, or making fraudulent payments. It's crucial to remain vigilant and think twice before responding to unsolicited requests, even if they appear urgent or legitimate. Always verify the authenticity of the message by contacting the organization directly using verified contact information. Additionally, be cautious when providing personal or financial information online, particularly if the request seems suspicious.
Protect yourself with trust but verify and critical thinking
To safeguard against various scams during the holiday season, implementing trust but verify and critical thinking practices can greatly minimize your risk. Scammers often manipulate emotions and create a sense of urgency, which can cloud judgment and lead to impulsive actions. Take a moment to calm down and critically analyze any communication that elicits a strong emotional response. Trust, but verify requests that seem out of the ordinary or raise suspicion. Contact the individual or organization through known and verified channels to confirm their requests. By incorporating these practices, you can better protect yourself against holiday scams and make informed decisions when faced with potentially fraudulent situations.
Welcome to the Social-Engineer Podcast: The SE Etc. Series. This series will be hosted by Chris Hadnagy, CEO of Social-Engineer LLC, and The Innocent Lives Foundation, as well as Social-Engineer.Org and The Institute for Social Engineering. Chris will be joined by his co-host Patrick Laverty as they discuss topics pertaining to the world of Social Engineering. [Nov 27, 2023]