Ep. 272 - The SE ETC Series - Ransomware, Phishing and iOS - SE in the News!
Aug 26, 2024
auto_awesome
The rise of voice phishing is staggering, with a shocking 500% increase in the past year. Keytronic suffered a massive $17 million loss from ransomware, highlighting the urgency of cybersecurity. Listeners learn critical tips to verify email authenticity and avoid phishing scams. Apple's new AI email filtering faces scrutiny for failing to distinguish between legitimate and fraudulent communications. Community involvement in addressing social engineering challenges is strongly encouraged.
Voice phishing incidents have surged by 500%, necessitating engaging training solutions to empower employees against these threats.
The Instant Vishing Education System demonstrates significant improvement in employee awareness and response to voice phishing through real-time simulations.
Deep dives
Significant Rise in Voice Phishing
There has been a dramatic increase in voice phishing incidents, with reports indicating a 500% rise in the last year alone. This type of phishing, distinct from email phishing, involves deceptive phone calls aimed at extracting sensitive information such as passwords or financial details. Many companies have fallen victim to these tactics, making it imperative for organizations to find effective training solutions for their employees. Traditional computer-based training methods have proven ineffective, as employees often disengage from lengthy sessions, highlighting the need for more engaging training approaches to educate staff on recognizing and responding to these threats.
Innovative Solutions to Combat Vishing
In response to the growing threat of voice phishing, a new educational tool called the Instant Vishing Education System (IVs) has been developed to enhance user awareness. This system integrates real-time audits where human operators simulate voice phishing calls to test employees' responses. The data collected demonstrates a significant improvement in the ability of individuals to report vishing attempts and a decline in their susceptibility to actual threats. Implementing this proactive approach not only helps equip employees with the skills to handle vishing calls but is also a crucial step in safeguarding company information.
Navigating Current Cyber Threats
Recent high-profile cyber incidents underscore the urgency for enhanced security measures and user vigilance. A major ransomware attack affecting Keytronic resulted in a staggering $17 million loss, coupled with the exposure of sensitive data including employee identification documents. Additionally, a global outage linked to CrowdStrike has led to a surge in phishing emails, preying on individuals’ concerns about system integrity and prompting them to click potentially harmful links. As threats evolve, it is crucial for individuals and organizations to verify the authenticity of communications and updates to avoid falling victim to scams.
Welcome to the Social-Engineer Podcast: The SE Etc. Series. This series will be hosted by Chris Hadnagy, CEO of Social-Engineer LLC, and The Innocent Lives Foundation, as well as Social-Engineer.Org and The Institute for Social Engineering. Join Chris as he discusses topics and news pertaining to the world of Social Engineering. [Aug 26, 2024]