Slashdot Mirror


RSA: Phish Me If You Can (Video)

Spearphishing. The deluxe (but easy) way to get unwary employees to put malware on your network. It's basically the same as phishing, except more targeted. That is, a plain phishing scam might offer an unwary web-browsing employee a chance to see a famous starlet naked, while a spearphishing attack might purport to be an urgent request from your Bizzaro County office for 200 Kg of Unobtainium Oxide. Open that email, and... ZAP! So this is social hacking (cracking for the old-timers), and cannot necessarily be fought entirely by technical means. So how about setting up fake spearphishing attempts and immediately sending employees who fall for them to an IT security class with an emphasis on how to avoid phishing scams? You can do this yourself, possibly with help from a bright person or two from a nearby University. Or you can contact PhishMe or another anti-phish training company and have them help you teach spearphishing awareness to your people. Either way, every computer-using person in your company should know about phishing -- and should know how to avoid getting hooked by phishers.

1 of 171 comments (clear)

  1. Advertising and nothing more ... by Anonymous Coward · · Score: 0, Troll

    Slashdot is my home page -- I read the content for information and ignore the advertising. This pure advertising play is nothing more than a bid for greater income for this unethical fraud of a business. PhishMe should discontinue attempting to publish advertising as information, and pay Slashdot for the space, and Slashdot should moderate the content to prevent this sort of corporate fraud.