Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Business Intelligence Security | Main | Capturing Keystrokes in Internet Explorer 6 »

You Are Being Targeted: Common Ground of Phishers and Polticial Strategists

It was a bit strange reading F-Secure's latest IT Threat Summary and having a feeling that I've heard part of this story before. I had, sort of.

Part of the threat summary deals with targeted attacks and spear phishing, like a series of attacks on executives with bogus claims of Better Business Bureau complaints. To make the scam as realistic as possible the attackers researched the company and found the names of real employees. In the case of spear phishing, the attackers send specific messages to people that match a particular profile. Scammers are turning to demographics, a lot like political strategists.

A recent article in Campaigns and Elections entitled "Microwizards: These innovators are taking microtargeting in startling new directions" says it all. Rather than send generic messages, start with some survey data, add commercially available demographics and mix in a bit of data from political organizations and you have enough information to get someone to pay attention to your pitch. See the latest issue of Wired for more on the art of political data analysis.

While there are similarities between how political strategists and phishers are targeting you there is one big difference. Phishers will still be targeting you on Wednesday, November 5, 2008.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/771

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net