Comments On Phishing Websites Increase Adoption Of HTTPS
Monday, June 24, 2019
More cybercriminals are encrypting their phishing websites according to a report from Phishlabs. The report reveals that 58% of the phishing websites in the first months of 2019 were using the secure HTTP protocol. This is a 12% jump compared to the last quarter of 2018.
Ilia Kolochenko, Founder and CEO at ImmuniWeb:
“When just one employee, reportedly acting without acolytes, has an uncontrollable access to such a huge amount of confidential data and even manages to take it away, there is reason to believe that some of the internal security controls are broken. Human factor remains the largest and probably the most dangerous risk than cannot be fully remediated. Most companies considerably underestimate human risk and then face disastrous consequences.
Employee awareness and continuous education programs, as well as properly implemented internal security controls, can greatly reduce risk of human mistake and ruin even the most sophisticated phishing attacks. However, a malicious employee is a much more complicated case. First of all, security teams are already overloaded with tasks, processes and endless alerts, and therefore frequently disregard incidents caused by presumably trusted colleagues. Worse, some of the employee’s malicious activity is technically undistinguishable from the legitimate daily work. Nonetheless, major incidents akin to this one, are usually easily detectable and preventable.” Read Full Article
ValueWalk: Desjardins Breach Shows That Internal Security Controls Are Broken
FinTech Futures: Desjardins announces internal security breach