Phishing

In a perfect world, your email inbox would only contain emails from friends and companies you do business with. Unfortunately, your email inbox is a virtual playground for people looking to do more harm than good.

There has long been a problem with hackers trying to get your financial info and passwords by pretending to be someone you do business with — often a bank, a credit card company, or a retailer you've made purchases from. But there's also a growing problem with scammers pretending to be someone you interact with in a work context — either a work colleague or someone from a company your employer does business with. These scammers can then trick you into either downloading malware onto your computer or divulging confidential information about your work.

These types of email scams are known as phishing. A 2019 report by PhishLabs, a company that monitors and mitigates hacking threats, found that phishing attempts in 2018 increased by more than 40%  compared to the previous year. And with more people working from home, phishing attempts are on the rise2 for 2020.

But what is phishing exactly, and how can you protect yourself?

Did you know? Scammers try to appeal to your emotional side by spoofing the name of a person or company you know so that you feel a sense of trust.

 

Phishing, explained

Phishing is when someone sends fraudulent emails in an attempt to access your personal information — or to manipulate you into giving them your personal information directly. And these emails typically look very credible. Here are a few examples of phishing emails:

 

Why phishing works

Phishing's effectiveness relies on what cybersecurity experts call "human fallibility." In other words, it's not a weakness of a particular hardware or software configuration that makes people vulnerable; instead, it's human nature.

With phishing, scammers try to appeal to your emotional side by spoofing the name of a person or company you know so that you feel a sense of trust. Or they'll try to bring out your inner curiosity by dangling a link to a Google Doc or Dropbox file, leaving you wondering what it contains.

Another common tool for these scammers is urgency. The email you receive might say that your account has already been compromised and you need to act quickly, or that a co-worker needs something immediately before you both get fired. Whatever the context, the goal is to get you to act without thinking.

Why people who work from home are more at risk

Everyone who uses email is potentially at risk of falling victim to a phishing attempt. But people who work from home are somewhat more at risk because of the nature of their workday. In an office setting, it's easy enough to drop by your coworker's cube to ask about that unexpected file they sent — or that urgent request that required emailing some of your company's financial information. At home, you may grow accustomed to just responding to those emails from colleagues and outside vendors — and responding promptly.

Additionally, the average person's home computer and network is typically not set up as securely as it would be in the office. And this makes people vulnerable to malware and ransomware attacks if they open a malicious file or click on a malicious link.

 

5 Tips for spotting a phishing email

 

Scammers have no shortage of tricks they'll use to try to get your money, your steal information, or gain access to your email account. One set of strategies is called phishing, a clever play on words to describe the act of virtually fishing for a victim.

Unfortunately, phishing attempts are on the rise. A 2019 report by PhishLabs, a company that monitors and mitigates hacking threats, found that phishing attempts in 2018 increased by more than 40%  compared to the previous year. And with increasing numbers of people working from home, experts suggest phishing attempts will continue to rise.

While scammers are getting more creative, these tips can help you weed out a legitimate email from a phishing attempt — whether it's in your personal inbox or your professional one.

 

Did you know? Scammers try to appeal to your emotional side by spoofing the name of a person or company you know so that you feel a sense of trust.

 

1. Look at the sender's email address

If an email you receive seems suspicious, the first place to look is at the top of the page, where you'll find the sender's email address. Most scammers attempt to closely mirror a known email address to trick you into thinking you're getting that email from a trusted source. However, there will typically be subtle differences.

For example, your financial institution usually sends customer emails from “customerservice@bankname.com." A spammer may mimic an official email address by adding to the web address or by changing the name of the sender, such as “customerservice@bankname.admin.com" or "adminservice@bankname.home.com."

While you should never click on links or attachments if the email address itself is suspicious, don't assume you can always trust every email coming from a known email address — even if it's from someone you trust. Hackers can gain access to someone's email account and then send you an email from that account. That's why you need to be alert to other hints of fraud as well.

 

2. Pay attention to the greeting

The email's greeting can also be a tip off. See if it matches greetings you've received from the same company or person in the past. For example, any colleagues or companies you do business already know your name and would address an email to you by your name. Greetings like “Dear sir/madam" or “Dear valued customer" can be a giveaway that it's a scammer. If your name is misspelled, that's another red flag.

 

3. Dust off your proofreading skills

Typically, phishing emails contain at least one — and sometimes several — spelling and grammar mistakes. In some cases, those errors could be intentional, as a way to get past your email server's spam filter. In some cases, the email may have been translated from another language, leading to errors in common terms and sentence structure. Whatever the case may be, catching those errors — and not clicking on anything in the email — can keep you and your inbox safe.

 

4. Hover before you click

As a rule, make a point to never click on hyperlinks in any email without examining them first. Simply hover your mouse pointer over the hyperlink to reveal what web address the link is directing to. Often, this can be an easy way to spot a phishing attempt since scammers rely on fake websites. Look for these clues:

For example, “yourbankname.com" is more trustworthy than “your1bank2name3.com," but you should also be on the look out for more subtle differences like "yourbankname.com.net."

With more people working from home and phishing on the rise, be careful too if you receive a link that seems to be coming from a colleague's email address. It's not impossible that their email was hacked. If you weren't expecting the link and there's no specific context about why they sent it, confirm with the supposed sender that they intended to send you the link.

 

5. Be wary of attachments

Attachments are a common phishing tool. They're designed to pique your curiosity and make you rush to open them. Be careful with any attachments you receive, including ones to cloud storage sites like Dropbox and Google Docs. Before clicking any attachment, ask yourself if the sender would likely send that to you. For example, if you suddenly receive an email from a colleague who never emails you and the email asks you to download an attachment, that's a red flag.

Another potential read flag: You receive an unexpected attachment from a colleague or a person you do business with — but it's lacking specific context that explains why they are sending it to you. If you have any doubts, call, text, or email the supposed sender to confirm that they did, in fact, send the attachment.

If you think an email you received might be a phishing attempt, don't click any links, don't download any attachments, and don't reply. Instead, call the company or person who sent you the email directly. If you find that the email isn't legit, report it as a phishing attempt to your email provider. Most providers give you the option to report phishing attempts directly from the suspicious email. If you're not familiar with your provider's protocol, an Internet search for your email provider plus "report phishing" is a good way to find instructions.

 

What to expect from your bank

It's important to know that your bank will never ask you to share personal or private information by email. For example, while Synovus does send emails occasionally with content about our products and services, we never ask our customers to share any sensitive information by email.

If you receive an email from your bank that asks you to share any confidential information, such as your bank account number or Social Security number — or if the email provides a link where you should update your bank account number or Social Security number — don't click on it. It's likely a phishing attempt. Instead, call your bank directly or access your account online through your bank's secure website. And be sure to report that phishing attempt to your bank.


 

Smishing

Smishing isn't a new dance craze or cooking technique — it's a type of cyberattack. But with so many similar-sounding scam names floating around, it's hard to keep up with what each one means.

Here we'll explain what smishing is and how it works. More importantly, we'll outline how you can protect yourself from smishing attacks — and what to do if you think you've been targeted.

What is smishing?

The term smishing is a mashup of the acronym SMS, which stands for short message service (the industry lingo for text messaging), and phishing, a type of internet fraudthat involves tricking you into responding to a fake email.

So, smishing is a type of phishing that uses text messages to try to dupe you into sharing personal financial information like your password, bank account, or credit card number.

 

Did you know? Smishing scammers play on your fears and your trust.

How smishing works

You get a text message that looks like it's coming from some sort of official source. For example:

Smishing scammers play on fear  — whether it's fear of losing money, fear of getting into trouble, or fear of missing out. They're also counting on you to trust a text message sent to your personal cell phone number and not think twice about responding.

How to recognize smishing attempts

Even if a text looks like it's coming from a trusted source, you should still be wary if it asks for passwords, authentication codes, or other personal information. The reason: spoofing. That's when a scammer makes it look like a phone call or text is coming from a number other than where it's really coming from. Again, the best course of action is to refrain from responding by text and instead call the company directly using the customer service number listed on their website.

Due to the recent increase in smishing attacks, some banks opt not to use text messages at all with their customers. Check to see if your bank has a written policy on text messaging. Even if your bank does use text messaging, it will not ask for personal financial information via text. If your bank does send text messages, make sure you find out directly from the bank itself what phone number it uses to do so.

 

What to do if you suspect smishing

If you have any doubt about whether a text message is real, contact your alleged sender's customer service department using the number listed on the company's official website or materials.

Whatever you do, don't call the number provided in the text message, and don't click on any link embedded in the message. Clicking on a link could cause your mobile phone to become infested with malicious software and allow cyber criminals to steal your personal information.

 

How to report smishing attacks

If you realize you've been on the receiving end of a smishing attack, report it to your cell phone company and file a complaint with the Federal Trade Commission.

You can also report smishing scams to any government agency, retailer, or other organization that the hacker was impersonating.

Terms like smishing may sound silly, but the financial harm that can result from smishing and other cyberattacks is quite serious. Shield yourself with a healthy dose of skepticism when seemingly official sources are sending you text messages and asking too many questions.


 

Vishing

Here's another term to add to your glossary of financial fraud: vishing. The term is a blend of voice and phishing (that is, scammers trying to get personal info from you via email). With vishing, the main tool fraudsters use is the phone.

 

What is vishing?

Vishing is a type of fraud that relies on getting you to trust the person at the other end of a phone call. The initial contact might be a phone call to you, but the scheme can also start with an email message or text asking you to call a number. Either way, the goal of vishing is to get you to reveal your personal data, account numbers, or security codes by phone so that cyber thieves can use that information to access your cash or credit.

Vishing can be hard to spot, because scammers have gotten so clever and resourceful about fooling their targets. For example, you might receive a call from a number that matches one used by a familiar organization, such as a bank, credit union, retailer, or government agency. Since the number seems to be credible, you probably answer the call and aren't suspicious.

The problem: Scammers are using readily available services that enable them to spoof (that is, fake) the number that shows up on your caller ID, while hiding the real origin of the call.

 

Scammers often "spoof" phone numbers that look like they're coming from a company you trust so that you'll answer their call.

 

Pretexts for vishing calls

Let's say you answer or return a call from a number that looks legitimate. The person on the other end, pretending to represent your bank, tells you some suspicious charges have been made using your debit card. They will cancel your card and issue you a new one, but first they need your PIN, your security code, and the answer to your security question for “verification."

Another version involves a recorded call that instructs you to enter your PIN or other information to be connected to someone regarding a problem with your account. Cybersecurity reporter Brian Krebs shared the story of a cybersecurity professional who was targeted for such an automated vishing attack with a message from someone claiming to represent AT&T. No detail was spared to make the setup seem real, right down to a sound effect mimicking the telecommunication company's four-note jingle.

Other variations of vishing bait include solicitations of charitable donations (often after natural disasters), offers of free vacations and other prizes, pitches for investments and foreign lotteries, and emailed messages for you to call the number of a service to remove a virus that's infected your computer.

 

Red flags

 

Why working from home may put you at more risk

Many people don't tend to answer their cell phone while at work — unless it's from someone they know and they suspect it might be urgent (say, a spouse, a parent, or a child's school). And it's a common practice to let all unknown numbers go right to voicemail.

But when you move to working at home, all of this changes. Some people may begin to answer every call that comes through, even if they don't recognize the phone number. And if they think the call could have any connection to work, they continue to talk, even if they don't know the person who is calling — or don't quite understand why they're getting the call.

One way to protect yourself: If it's not a phone call from someone you know — or it's not a phone call you were specifically expecting (say, someone calling from your office to help you with your work from home setup) — hang up. If you think there's even a small chance the call may be real, first get the caller's name, their company name, and their department. Then you can either call or email them back or using information you find on a website or a company directory.

 

How to report vishing

If you've been targeted with vishing, report the incident to the Federal Trade Commission. Just select a category and use the FTC's Complaint Assistant to fill out a report online. The agency doesn't resolve individual complaints, but it will share your report with law enforcement authorities and provide information you can use to seek a remedy.