Cybercrime Prevention Guide

Cybercrime Prevention Guide

Phishing Attacks

In our current modern world, there exists a wide range of cyber-attacks that can be used to infiltrate an organization. However, the most commonly utilized attack method is Phishing. According to a research study conducted by Statista (2023), it is estimated that approximately 27% of organizations around the world experience four to six successful phishing attacks every year. It is also estimated that there has been a 345% increase in unique phishing sites in the last few years. Phishing is a type of cybercrime where the attackers pretend to be a legitimate entity to trick employees in an organization into revealing sensitive information. The sensitive information may include passwords or credit card numbers that may have a negative impact on the running of an organization when they fall into the hands of the wrong person (Statista, 2023).

On this, it’s also important to point out that Phishing attacks come in various forms. And each attack comes with its unique characteristics and targets. Here are a few types of phishing cyber-attacks: Spear Phishing. This is a phishing attack targeting a specific group of individuals—employees, and organizations operating in a particular line of business. Therefore, instead of casting a wide net, cyber attackers focus their attention on a few high-value targets through the use of a uniquely configured email or website link. Whaling, on the other hand, is an advanced form of spear-phishing attack that specifically targets senior executives within an organization (Rashid, 2020).

The third form of Phishing is the clone phishing. Research studies have shown that this type of Phishing involves attackers cloning a legitimate message from a trusted entity but, in the process, replacing the link or attachment with a malicious one that is aimed towards obtaining a target set of data from an individual or institution. The last form of Phishing is vishing. Phishing is very common with telecommunication companies and involves using voice, where attackers use phone calls to trick victims into giving out sensitive information. This type of Phishing has been very common in the last few years, where callers from overseas countries such as India have been tricking unsuspecting Americans disguised as customer service agents from some of the leading American organizations such as Amazon and Microsoft (Rashid, 2020).

In many instances, the stolen data can be used for malicious purposes, such as unauthorized access to an organization’s systems or to commit various forms of fraud. As highlighted by Lavorgna (2020), recorded cases of Phishing attacks often begin with an unexpected email or message that, in a way, creates a sense of urgency or fear, thus convincing the recipient to click on a link op, an attachment, or fill in the requested information. In most cases, phishing emails or messages contain links to websites that look similar to legitimate sites which are meant to convince the target that they are on a legitimate site but are actually controlled by the attackers. In advanced phishing, attackers may send attachments that contain malware such as the Ransomware that can infect the recipient’s device. This malware in many instance are used in the collection of private data that should only be accessible to an organization and the assigned employee (Lavorgna, 2020), and time used to control the systems of that nation to the advantage of the attacker.

Signs of Phishing Attacks

In cybersecurity, the first step in preventing any cyber threat is recognizing its signs. Research studies have revealed that in most cases, phishing attacks launched at a specific target have distinct signs that can alert an individual or an organization to their occurrence. For instance, one of the primary indicators of a phishing attack is when one or an organization starts to receive unexpected emails or messages that create a sense of urgency or fear. As stated earlier, these messages have the ability to convince the recipient to click on a link or open the sent attachment, thus stealing sensitive data. Another sign of Phishing is the presence of suspicious links or attachments that have been sent to an organization or an individual through email or message. In many instances, the links often lead to websites that closely resemble legitimate sites but are, in fact, controlled by attackers with the aim of retrieving private data that can be used to sabotage the running of an organization. The attachments may contain malware such as ransom malware that is designed to infect the recipient’s device and, in the process, grant the attacker access to the network systems of an organization.

Another important sign is that phishing emails often request the target individuals or firms to either confirm or update sensitive information in their systems. This includes sensitive information such as such as private passwords or an organization’s financial details. In carrying out the updates, the attackers gain access to the confidential data which can be used at their own will for their own benefit. Moreover, spelling or grammatical errors in very import emails or websites and unreasonable threats are some of the major signs of phishing attack. In a study on cybersecurity by Alkhalil et al. (2021), it is clearly highlighted that victims of Phishing generally found it difficult to detect emerging modern phishing tactics that have been in use in the last few years. However, they were alert to the spelling mistakes of older phishing email attacks, sensitive information being requested from them, and any slight change to what they were normally used to from an email. Therefore, recognizing these signs of Phishing and preventing cyberattacks will be easier for an organization or an individual (Alkhalil et al., 2021).

Protecting Against Phishing Attacks

As stated earlier, phishing attacks pose a huge problem to individuals and organizations whose confidential data ends up in the hands of an authorized individuals. Some of the most known problems associated with Phishing attacks specifically towards and individual or an organization are as follows. In many instances that have been recorded around the world Phishing attacks have resulted to monetary losses. This is becouse, when employees fall victim to Phishing, they unknowingly give out secretive information that have been used out to transfer funds to fraudulent accounts. A good example of this is the financial loss that took place at an office in Hongkong that lost HK$200 million following a phishing attempt, when an employee in the finance department of the company’s Hong Kong branch received what seemed to be a phishing message, purportedly from the company’s UK-based chief financial officer, instructing them to execute a secret transaction (Edwards, 2024).

On this, it is also important to add that a successful phishing attack has the ability to tarnish the good reputation of an organization. These may come from the loss of sensitive data, which compromises or erodes customers’ trust. A good example of this, is the incidence that took place at RSA Security which is a cybersecurity company. The breach led to questions about the company’s ability to protect its own network, let alone its customers’ network. Lastly, successful Phishing incidents may result in legal repercussions. As a result of phishing, an organization could face lawsuits, regulatory fines, or penalties if they fail to adequately protect against phishing attacks. A good example of this is the hefty fines companies like Facebook have had to pay because of data bleaching from phishing attacks (Roller, 2023).

However, a study conducted by Suzuki and Monroy (2021) reveals that various strategies can be employed to protect individuals and organizations against this type of cybercrime. To begin with, there is the strategy of education and training on phishing. Cyber security experts believe that the first line of defense against phishing attacks is educating those that are at a higher risk of Phishing. Regular training can help individuals and organizations recognize the signs of phishing attacks, and as a result are able to protect them from Phishing cyber-attack. This will help in the understanding of the importance of not clicking on suspicious links or revealing sensitive information to online strategies. The next strategy is the use of the emerging Security Software. These include the use of modern antivirus and anti-phishing software that is aimed at identifying and preventing phishing threats.  A good example of this software’s includes: Guardz, Trustifit, and Abnormal Securirty. This software also acts as effective spam filters, which have the ability to screen out different phishing techniques. Machine learning approaches are also utilized. A good example of machine learning techniques includes; Supervised Learning Unsupervised Learning and Reinforcement Learning. Research shows that this approach has been found to have the highest accuracy in preventing and detecting phishing attacks. Regular system Updates are another important strategy. This is because it Keeps the operating systems and browsers of an organization up to date, which can help in the protection against known places of weakness in the old systems that attackers might exploit (Alkhalil et al., 2021). This entails keeping up to date with current emerging trends, as they might use current events or popular trends to make their phishing emails seem more legitimate. Staying informed about these tactics can help in identifying phishing attempts (Alkhalil et al., 2021).

References

Alkhalil, Z., Hewage, C., Nawaf, L., & Khan, I. (2021). Phishing Attacks: a recent comprehensive study and a new anatomy. Frontiers in Computer Science, 3. https://doi.org/10.3389/fcomp.2021.563060

Lavorgna, A. (2020). Organized crime and cybercrime. In Springer eBooks (pp. 117–134). https://doi.org/10.1007/978-3-319-78440-3_14

Rashid, F. (2020, November 24). 8 types of phishing attacks and how to identify them. CSO Online. https://www.csoonline.com/article/563353/8-types-of-phishing-attacks-and-how-to-identify-them.html

Roller, J. (2023, May 13). 6 Common phishing attacks and their impact on organizations. IEEE Computer Society. https://www.computer.org/publications/tech-news/trends/6-common-phishing-attacks/

Statista. (2023, March 31). Phishing attack rate among businesses worldwide 2021. https://www.statista.com/statistics/1149241/share-organizations-worldwide-phishing-attack/

Suzuki, Y., & Monroy, S. a. S. (2021). Prevention and mitigation measures against phishing emails: a sequential schema model. Security Journal, 35(4), 1162–1182. https://doi.org/10.1057/s41284-021-00318-x

CLICK HERE TO ORDER A PLAGIARISM-FREE PAPER

Cybercrime Prevention Guide

You are a detective on the city’s Cybercrime Task Force. The chief has tasked you with creating a
Cybercrime Prevention Guide that can be placed on the city’s social media site that will educate the
citizens on the many types of cyberthreats and cybercrimes that the Cybercrime Task Force is
battling on a daily basis.

Using paragraph headings for each of the following four bullet-points, Write a 1,400-
word Cybercrime Prevention Guide. Complete the following in your guide:
 Address one cybercrime that may compromise an organization.
 Discuss the signs or incidents that might alert someone that this type of crime is taking place.
 Provide a thorough analysis of how a person or organization can protect itself from this type of
crime.
 Discuss preventative measures, including security precautions, that could be put into place.

In all assignments in this course, use APA style in-text citations associated with your
References page to cite your information sources. The reader should be able to visit the
source you cited to find the information from your work.

0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply

Your email address will not be published. Required fields are marked *