Does phishing really work?

You’re making a big deal about phishing and spear phishing. Does anybody fall for that?

04/26/2013


Dear Control Engineering: I’ve seen two articles recently on your site about phishing, once in the Real World Engineering blog and Matt Luallen’s column. Does this really work? Does anybody fall for “free gas for a year?”

Phishing has grown as an attack method because it works. A case in point: If you were paying attention to the stock market, you know that the Dow Jones Industrial Average dropped very quickly earlier this week after there was a tweet from the Associated Press saying that bombs had gone off at the White House. This was because the Twitter account of one of the AP staffers had been hacked. The lesser known part of this story was that the AP staffer had fallen for a spear phishing scheme.

As SC Magazine reports, “…the intruders were able to glean the AP's Twitter login credentials thanks to a spear phishing email that targeted some staffers just prior to the compromise. Victims were directed to a sign-in form and asked to enter the username and password for the account.”

This is by no means an isolated incident. Read Matt Luallen’s column for advice on training your people so they know when the hook is in the water.

Peter Welander, pwelander@cfemedia.com



No comments
Consulting-Specifying Engineer's Product of the Year (POY) contest is the premier award for new products in the HVAC, fire, electrical, and...
Consulting-Specifying Engineer magazine is dedicated to encouraging and recognizing the most talented young individuals...
The MEP Giants program lists the top mechanical, electrical, plumbing, and fire protection engineering firms in the United States.
integrated building networks, NFPA 99, recover waste heat, chilled water systems, Internet of Things, BAS controls
40 Under 40; Performance-based design; Clean agent fire suppression; NFPA 92; Future of commissioning; Successful project management principles
BIM coordination; MEP projects; NFPA 13; Data center Q&A; Networked lighting controls; 2017 Product of the Year finalists
Transformers; Electrical system design; Selecting and sizing transformers; Grounded and ungrounded system design, Paralleling generator systems
Commissioning electrical systems; Designing emergency and standby generator systems; VFDs in high-performance buildings
Tying a microgrid to the smart grid; Paralleling generator systems; Previewing NEC 2017 changes
As brand protection manager for Eaton’s Electrical Sector, Tom Grace oversees counterfeit awareness...
Amara Rozgus is chief editor and content manager of Consulting-Specifier Engineer magazine.
IEEE power industry experts bring their combined experience in the electrical power industry...
Michael Heinsdorf, P.E., LEED AP, CDT is an Engineering Specification Writer at ARCOM MasterSpec.
Automation Engineer; Wood Group
System Integrator; Cross Integrated Systems Group
Fire & Life Safety Engineer; Technip USA Inc.
This course focuses on climate analysis, appropriateness of cooling system selection, and combining cooling systems.
This course will help identify and reveal electrical hazards and identify the solutions to implementing and maintaining a safe work environment.
This course explains how maintaining power and communication systems through emergency power-generation systems is critical.
click me