Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Data Breaches: Fodder for New Phishing Attacks
Articles

Data Breaches: Fodder for New Phishing Attacks

ISBuzz TeamBy ISBuzz TeamSeptember 2, 2014Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
phishing
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

As seen in the news earlier this month, Russian hackers stole more than 1 billion username/password combinations. This is the largest incident of credentials theft ever reported, potentially compromising 500 million email accounts. And with a cyber-attack of this scale, it’s understandable that users feel a sense of unease about the security of their own personal credentials.

FREE Ebook: A New Approach To Managing Employees’ Personal Internet Use At Work

Businesses share this unease. For them, the question is no longer simply “How can we prevent a data breach?” They’re also wondering how they can protect their customers after a data breach, incidents which are these days almost inevitable.

Swift and decisive action to close the breach and restore security is expected, of course. But unfortunately, remediation doesn’t end there. News stories that involve the large-scale theft of user credentials is music to the ears of an entirely different class of criminals, specifically phishing and identity theft experts. Through seemingly authentic emails or social media posts, which can be personalized according to an end user’s known contacts, scammers direct their intended victims to sophisticated counterfeit websites and mobile applications. These attackers prey on the end user’s fear that their key accounts have been compromised, enticing them to disclose their confidential information. The emails and mobile apps might even be branded with the company’s logo, with messages like:

We noticed some unusual credit card activity on your account and have temporarily suspended it until we can verify your identity. CLICK HERE to reset your personal security questions and restore access.

The companies most at risk from these phishing schemes tend to be those that have deployed web engagement strategies including customer logins or saved personal profiles.

What can recently breached organizations like P.F. Chang’s, SuperValu and Albertson’s do to minimize risks from these secondary threats? At BrandProtect, we strongly advocate three basic best practices that corporations should take to minimize their customer’s exposure to phishing attacks:
[wp_ad_camp_4]
First, businesses should deploy and promote a prominent abuse box process on their home page. It sounds simple, but a company’s end users are fantastic resources in the fight against identity theft attacks. When observant end users receive a suspicious email, organizations should encourage them to forward the mail to the abuse box where the business’s security team can validate the email as legitimate or flag it as a scam. When scam emails are discovered, as appropriate, the next step should be to publicize the details of the scam on the home page so that customers are alerted as soon as possible.

Second, it’s important to engage the services of anti-phishing service providers. By deploying multiple spam and phishing email capturing techniques, an anti-phishing provider can provide attack detection at a far greater scale and with greater effectiveness than an in-house security team acting on its own. For example, BrandProtect captures, processes and evaluates millions of suspicious emails daily, identifying emails that include our client’s brands and other images. These branded emails are carefully reviewed to identify scam emails that could entice unsuspecting end users into revealing their online credentials. A reputable vendor will be able to mitigate these threats quickly.

Lastly, enterprises should extend their threat monitoring services beyond just email. Companies should invest in an anti-phishing provider that offers enterprise-class brand protection, spanning both cyber-threat discovery and evaluation. Some companies are under the misconception that because they are monitoring for suspicious emails, they’re keeping the brand safe. Unfortunately, email monitoring is only part of the answer. To truly protect against risks posed by scammers, businesses must also search for the newly published web domains, counterfeit web pages, and rogue mobile applications that cyber criminals create to support their illegal schemes. Top tier service providers deliver solutions that integrate monitoring for all of these threat channels and more.

The very best providers deploy enterprise-class threat detection platforms that automate a majority of the detection and filtering processes and use deeply experienced threat analysts to validate and cross-check results. Additionally, with an enterprise-class platform, results are captured in sophisticated workflow-based portals that enable reporting, contextual analyses and auditing. APIs can connect threat information to other in-house security systems to provide a complete understanding of potential threats. The right partner will be able to detect and evaluate risks at a scale companies could never afford to achieve in-house. Further, using a threat monitoring platform allows top notch security teams to focus on only the relevant, actionable incidents that represent actual risks to a company’s reputation.

By Greg Mancusi-Ungaro, CMO, BrandProtect

greg_mancusi-ungaroBio: Greg Mancusi-Ungaro is responsible for developing and executing the BrandProtect market, marketing, and go to market strategy.  A passionate evangelist for emerging technologies, business practices, and customer-centricity, Greg has been leading and advising world-class marketing initiatives, teams and organizations for more than twenty-five years.  Prior to joining BrandProtect, Greg served in marketing leadership roles at ActiveRisk, Savi Technologies, Sepaton, Deltek, Novell, and Ximian, building breakthrough products and accelerating business growth. He is a co-founder of the openSUSE project, one of the world’s leading open source initiatives.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}