Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - The Grinch Loves Email – Don’t Get Lured This Holiday Season
News & Analysis

The Grinch Loves Email – Don’t Get Lured This Holiday Season

ISBuzz TeamBy ISBuzz TeamDecember 9, 2014Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
phish
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

It’s that time of year again! No, not just for spending time with loved ones, putting up holiday decorations, or even digging out that ugly sweater to wear to your hipster friend’s party. It’s also time for EMAIL PHISHING CAMPAIGNS!!

That’s right. This is the time of year where most of us will be so busy with holiday planning, gift buying, blowing up air mattresses, etc. that we might forget to be diligent about how we access the web. Even the most savvy of users might not be paying attention when clicking a malicious link or opening a virus-laden file. Unfortunately, those that wish to steal our information are counting on just that.

Cyber criminals are getting sneakier and changing tactics away from malicious attachments to “watering hole” style attacks that lure victims to a trusted (but compromised) URL destination. So, that email you just received from your favourite online boutique promising 75% off may not be the deal it is cracked up to be.

Featured Download: Social media access at work. Do your employees know the rules?

They also prey on the proclivity of lowering your guard when dealing with something or someone familiar. The email might look to be from a reputable source like your bank, doctor’s office, or from someone you know. The message might even be related to your favourite hobby.

In the spirit of the holiday season, my gift to you is a set of measures you can take to help protect yourself against the myriad of looming threats out in the wild.

If in doubt, don’t open the email attachment – Go to the website from your browser and look for the promotion. While not perfect, going directly to a website is preferable to clicking on links in emails.

Pay attention – This may seem obvious, but your best defence is to pay attention when surfing the web. This includes knowing what sites you are accessing and what files you are opening.

Verify the contents of suspicious emails – If you get an email from your bank, doctor, house/auto lender, etc. that is asking you to supply personal information, take steps to verify the origin of the email. Contact the purported sender directly (don’t click on the ‘customer support’ link as it may redirect you to a malicious site) and see if they actually sent out that email. Doctor’s offices, banks, and other financial institutions are actually pretty good about not sending or soliciting information over email, so chances are someone is trying to take you for a ride.

Don’t click on untrusted URLs – Is there a link in the email that the sender wants you to click? Read the URL a couple of times and make sure you are going to “paypal.com” and not “peypal.com.” You can also hover over the link or right-click copy/paste the URL into a text file to make sure that the “link” isn’t just a text label disguised as the URL. If the link is using URL shortening links, such as bitly, use extra caution.

Be careful when opening attachments – While today’s malware and anti-virus scanners can usually catch the majority of malicious executables, it’s really easy to alter the makeup of an existing file to the point where it can evade detection. Over the busy shopping period, you will probably get an array of “delivery” or “shipping” notices as normal. One technique attackers use is to disguise these as malicious attachments. Most online retailers will send these as the body of the email, so think carefully before opening an attachment.

Really, though, the “dangerous attachment” threat isn’t as prevalent these days. More often than not, malicious software is hosted on remote servers and victims are tricked into downloading and executing them via the nefarious methods described above.

Keep a close guard on your information – Cybercriminals are well aware that this is the time of year when people make more online transactions than usual. Try to be extra careful when sending financial and/or personal information, even to sources you think are reputable. While you may think you are saving time having a website save your details or registering with a website, make sure you think about how many new ways you are opening yourself up to having those details stolen should those sources become compromised by attackers.

Not taking these steps to protect yourself could turn a morning of building your sweet new Lego Millennium Falcon into months of picking up the pieces of your now-stolen identity.

By Garrett Gross, Senior Technical Manager, AlienVault

About AlienVault

AlienVaultAlienVault is the leading provider of Unified Security Management and crowd-sourced threat intelligence. Its products are designed and priced to ensure that mid-market organizations can effectively defend themselves against today’s advanced threats. By building the best open source security tools into one Unified Security Management platform, and then powering the platform with up-to-the-minute threat intelligence from AlienVault Labs and its Open Threat Exchange—the world’s largest crowd-sourced collaborative threat exchange—AlienVault provides its customers with a unified, simple and affordable solution for threat detection and compliance management.

While the perfect threat deflector shield has yet to be invented, AlienVault is able to provide its customers with an out-of-this-world threat detection product that ensures even the smallest ‘planets’ in the galaxy can fend off attackers.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}