Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Phishing in the Workplace
Articles

Phishing in the Workplace

Suzan MustafaBy Suzan MustafaSeptember 22, 2014Updated:January 7, 20223 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

One of the most common methods cyber-attackers use to target workplaces are phishing emails. The bad news is that these malicious actors are becoming increasingly more sophisticated in their attacks. Today, not even the “spam” folder can protect you!

What is Phishing?

Phishing emails appear to the receiver as if they were sent by a genuine sender, but they are not. Attackers use these emails to trick the victim into believing that there is a problem with one of their online accounts. For example, posing as a person’s financial institution, an attacker could send a user an email explaining that they need to resolve some suspicious activity associated with their account. The email includes a link that directs the user to a fake website. There, they are required to enter their log-in credentials. This would, in turn, grant the attackers access to the user’s accounts.

Other Ways to Spot a Phishing Email

Immediate Action – The email urges that you take urgent action on one of your accounts claiming that it will be closed as a result of no action.

Fake Prizes – The email claims that you have won a prize for a competition that you never actually entered.

Suspicious Attachments – The email asks you to download a suspicious attachment. This can sometimes be a “tracking advice attachment” from a supposed courier company that you or your company have never previously used.

Fake URLS – The hyperlink in the email can suggest that it’s from a legitimate company, but if you move your mouse over the link, you will realise that the actual URL is different from the one shown in the email.

What are the Risks of Phishing in the Workplace?

As businesses implement more stringent cyber security measures to ensure they filter out spam emails from employees’ inboxes, a growing, less-addressed issue is employees accessing their social media accounts at work. For example, an employee might access their Facebook account and click on a phishing message that was sent to them by a friend’s compromised account. Such an attack would place the organization’s information at the same level of risk as email-based phishing schemes.

Free Download: Is An Outright Ban On Workplace Social Networking A Good Idea?

The victim is likely to click on a link such as “Hey! Check out this video, I can’t believe they did this”. Although many organizations’ internet security programs might flag the link as a high-risk alert, this assumes that existing software and protections are up-to-date.

What Can You Do to Prevent Phishing in the Workplace?

It is difficult to prevent phishing emails from being sent to your workplace inbox. However, there are measures your organization can implement to protect itself from such attacks. These include the following:

Update Your Internet Security Program – New AV software versions are released frequently. If updated regularly, this will help protect against intrusion.

Report Suspicious Links to Your IT Help Desk – Report any suspicious links to your IT Support team, who can investigate the matter and keep a record of any and all phishing attempts.

Encourage Anti-Phishing Training in the Workplace – It’s best to hold security awareness training on issues such as phishing. This will help clarify to each and every employee the part they play in protecting their employer’s data.

Suzan Mustafa

Suzan completed her Bachelor of Professional Communication (Journalism) at one of Australia’s top universities – Monash University. Since completing her degree, she has been studying for her Masters in Policing, Counter Terrorism and Intelligence with a specialisation in Cyber Security. Her work has been published in The Age, Film International Magazine, Canva and more.

  • Suzan Mustafa
    Counter Attacks in Cyber Space
  • Suzan Mustafa
    How You Can Protect Yourself Against Mobile Fraud
  • Suzan Mustafa
    On Two-Factor Authentication

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}