There’s no mortification quite like the feeling one gets after realizing that they have been taken in by a phishing email. It’s just so embarrassing! If you’ve ever been a victim though, you should let yourself off the hook. Phishing scams are surprisingly successful even when targeting victims who are highly technologically sophisticated.
For the average busy information worker, it may be too much to expect them to spot tiny hints that an email is fake. In some cases, the success of a phishing attack depends upon impersonating a trusted individual. Other times, the success of a phishing attack is the result of simple emotional manipulation.
The main psychological weakness exploited by phishing is our basic need to be kind to people we consider friends. A study at the State University of New York at Buffalo (SUNY Buffalo) showed that students who use Facebook more are at increased risk of sharing their personal information in a phishing attack. The study suggests that people who do more social networking are more likely to click on a link in an email from someone they think is a friend, even if that person has a completely invented identity.
Pop culture can help us understand the phenomenon. In the superb 1987 con-man movie, “House of Games,” screenwriter David Mamet illustrates the effectiveness of the con through a snippet of dialogue between Mike, a confidence man played by Joe Mantegna, and Dr. Margaret Ford, played by Lindsay Crouse. Ford wants to understand how con artists work. He tells her, “It's called a confidence game. Why? Because you give me your confidence? No. Because I give you mine.”
Don’t dismiss the psychology of phishing. The emotions involved affect everyone. Even the White House got hacked using this technique.
A successful phishing attack against one of your employees could mean that your entire network eventually becomes compromised or it could “just” mean the loss of more specific IP or data. This can broadly impact:
Understanding the psychology of phishing is a step toward building better awareness and training employees to spot phishing emails. At the same time, it’s essential to be vigilant at a systemic level with effective anti-phishing technology. This is easier said than done.
Standard countermeasures such as anti-spam filters and anti-malware protections don’t work with phishing. Well-crafted phishing emails may not look like spam to software that’s designed to detect junk mail. Anti-virus software won’t do much good, either, because most phishing messages don’t contain any actual malware.
Vade anti-phishing solution offers specific anti-phishing protections that can be layered on top of existing anti-spam solutions to provide better overall email protection for your employees. Our proprietary processes spot both one-off spear phishing attacks and mass phishing attacks before they can impact your employees and your bottom line.
Give us a call at 415-745-3630 or contact us, if you want to discuss how you can quickly add anti-phishing measures to your current email setup.