Suspicious minds reduce cyber crimes

Phishing attacks are not new; they play on our complacency in believing that we can always spot one in the wild. Becoming ever more sophisticated sometimes the simplicity of the attempt can catch even the most seasoned employees by surprise.

Alerts to a potential phishing attempt by our monitoring systems highlighted two emails that were being sent from an internal email address at our customer’s office to hundreds of recipience.

Both emails contained the same phishing link which prompted users to enter their email address to download a document, followed by a convincing credentials phishing page.

Our investigations showed that the compromised account showed suspicious sign-ins from multiple locations, indicating unauthorised access.

We recommended that our customer implement a training solution to help staff learn about phishing campaigns, as well as implementing geo-based conditional access policies, deploying a SIEM solution to monitor and alert on suspicious activities and conducting monthly phishing simulations to improve user awareness and response.

Following on from this attack, out team monitored another set of suspicious phishing emails, this was investigated and the customer confirmed they had run a test internally to assist with training staff on phishing emails.

Employee training is key to preventing these phishing attempts from being successful. As a managed cybersecurity provider, we provide learning and simulation services to train staff to be on the lookout for even the most sophisticated social engineering attempts, as well as managed cyber services such as phishing defence, threat management and incident response.

Under attack? Get help from THE Cyber team.

Cyber Files.

Cyber Solutions.

Managed Endpoint Detection and Response.

Protect your business against the latest cyberthreats with our Managed Endpoint Detection and Response (M-EDR) service.

Managed Phising Defence.

Our managed service tackles the challenges faced by IT teams in educating and maintaining cyber security awareness within organisations.

Managed Disaster Recovery.

Our Managed Disaster Recovery solution provides positive reassurance for business operations.