Does phishing really work?

You’re making a big deal about phishing and spear phishing. Does anybody fall for that?

04/26/2013


Dear Control Engineering: I’ve seen two articles recently on your site about phishing, once in the Real World Engineering blog and Matt Luallen’s column. Does this really work? Does anybody fall for “free gas for a year?”

Phishing has grown as an attack method because it works. A case in point: If you were paying attention to the stock market, you know that the Dow Jones Industrial Average dropped very quickly earlier this week after there was a tweet from the Associated Press saying that bombs had gone off at the White House. This was because the Twitter account of one of the AP staffers had been hacked. The lesser known part of this story was that the AP staffer had fallen for a spear phishing scheme.

As SC Magazine reports, “…the intruders were able to glean the AP's Twitter login credentials thanks to a spear phishing email that targeted some staffers just prior to the compromise. Victims were directed to a sign-in form and asked to enter the username and password for the account.”

This is by no means an isolated incident. Read Matt Luallen’s column for advice on training your people so they know when the hook is in the water.

Peter Welander, pwelander(at)cfemedia.com



No comments
Consulting-Specifying Engineer's Product of the Year (POY) contest is the premier award for new products in the HVAC, fire, electrical, and...
Consulting-Specifying Engineer magazine is dedicated to encouraging and recognizing the most talented young individuals...
The MEP Giants program lists the top mechanical, electrical, plumbing, and fire protection engineering firms in the United States.
Water use efficiency: Diminishing water quality, escalating costs; Lowering building energy use; Power for fire pumps
Building envelope and integration; Manufacturing industrial Q&A; NFPA 99; Testing fire systems
Labs and research facilities: Q&A with the experts; Water heating systems; Smart building integration; 40 Under 40 winners
Maintaining low data center PUE; Using eco mode in UPS systems; Commissioning electrical and power systems; Exploring dc power distribution alternatives
Protecting standby generators for mission critical facilities; Selecting energy-efficient transformers; Integrating power monitoring systems; Mitigating harmonics in electrical systems
Commissioning electrical systems in mission critical facilities; Anticipating the Smart Grid; Mitigating arc flash hazards in medium-voltage switchgear; Comparing generator sizing software
As brand protection manager for Eaton’s Electrical Sector, Tom Grace oversees counterfeit awareness...
Amara Rozgus is chief editor and content manager of Consulting-Specifier Engineer magazine.
IEEE power industry experts bring their combined experience in the electrical power industry...
Michael Heinsdorf, P.E., LEED AP, CDT is an Engineering Specification Writer at ARCOM MasterSpec.