When it comes to phishing, email scams often dominate the conversation. Yet, attackers are increasingly turning to a host of lesser-known but highly effective phishing techniques that can catch even the most cautious internet users off guard. Let’s explore some of these overlooked methods:
1. SEO Poisoning
Thousands of phishing websites are launched each month, many of which are SEO-optimised to appear in top search results. If you search for “download Photoshop” or “PayPal account,” you may encounter a deceptive lookalike site designed to steal information. Some attackers even hijack Google business listings, replacing legitimate contact details with their own to trick unsuspecting users into reaching out.
2. Paid Ad Scams
Attackers often use paid advertising on social media and search engines to drive traffic to malicious sites. Victims may unknowingly click on these ads, downloading malware or sharing sensitive information. Known as “malvertising,” this approach can even embed trojans or viruses within ads.
3. Social Media Phishing
Scammers impersonate friends, celebrities, or public figures on social media to gain trust and lure victims. They may comment on legitimate posts or send messages that direct users to phishing sites, or create apps like quizzes and surveys to collect private information. Some attackers even use deepfakes to spread disinformation.
4. QR Code Phishing
With QR codes more prevalent than ever, attackers are turning to “quishing,” or QR code phishing. They place malicious QR codes on posters, menus, and even parking meters. When scanned, these codes can direct users to harmful websites or prompt fraudulent payments. A recent report found a 587% increase in quishing attacks over the past year!
5. Mobile App Phishing
Mobile app phishing targets users through malicious apps on app stores. These apps, disguised as legitimate, can steal financial data or conduct illegal surveillance. Recently, over 90 malicious apps on Google Play were discovered with more than 5.5 million downloads.
6. Callback Phishing
Callback phishing involves attackers luring users into calling fake customer service numbers. These scams may start with an email, text message, or even a voicemail urging the victim to call back. Attackers have even used Google Forms to bypass phishing filters, displaying a fraudulent phone number to call.
7. Cloud-based Phishing
As more companies rely on cloud services, attackers are targeting platforms like Microsoft Teams and SharePoint. By hosting phishing content on trusted cloud services like Google Drive, Amazon, and Microsoft Sway, they can bypass security filters and make malicious links look more credible.
8. Content Injection Attacks
By exploiting vulnerabilities in websites or devices, attackers can insert malicious content or links directly into webpages or app messages. For instance, they may alter a “Contact Us” page to display harmful links or a phone number that leads to a scam.
Protecting Against Phishing in All Forms
The rise of AI has made phishing more sophisticated, and these tactics will likely continue to evolve. By educating employees through ongoing security training and regular awareness programs, organisations can build a strong defense against these social engineering attacks and protect sensitive information, financial assets, and their reputation.
Speak to us to find out how we can help protect your employees and your business.