What is Spear Phishing
Most everyone knows that phishing is the practice of using fraudulent emails to gain access to personal information by an identity thief. As with most schemes an identity thief uses, occasionally there is a call for updates to the scheme. The update to the scheme phishing is called spear phishing.
In regular phishing, the identity thieves would cast out a bunch of bait in the form of fraudulent emails. Once these fraudulent emails were sent out, the identity thieves would just wait to see how many would “bite” Spear phishing is more targeted.
When an identity thief uses spear phishing they are targeting one individual instead of a couple of hundred thousand people. The spear phishing emails are customized by containing personal information such as a name or some tidbit about employment and sent only to the person that the email was customized for.
A spear phishing email will usually include a link that leads to a fake, or spoofed, web site that requests personal information. Sometimes it looks so legitimate that even the experts are fooled. The recipient of the message clicks through the link and taken to a page on the web that looks legitimate. Again, it can be hard for even seasoned security professionals to tell that this website is a set up.
Some spear phishing emails may contain a downloadable like that may appear to come from an employer or someone that equally legitimate. Unfortunately, the file contains malware and once it is downloaded to your computer, the malware will collect your personal information and transmit it to the identity thief.
This is a difficult scam to catch because of all the extra time and effort that is put into this effort by the identity thieves. It requires the identity thief to do enough research to gain access to enough information to make the victim believe that email is real. It also takes time to put the web sites together plus it takes time to get the messages right that are going to be used as bait. For all this extra hard work, there is a much greater reward for spear phishing.
When it comes to spear phishing, there is no guarantee that you can protect yourself. These identity thieves are intent on gaining access to your identity, and will put in the effort and hard work to reach the ultimate pay-off, which will be getting your personal information. Spear phishing emails are very difficult to tell from any other email so just practice caution.
