6 ms·
> “However, you are still not convinced, so you call your manager to ensure that the email is legit. He confirms, so you transfer the money.” I feel like it’s
by bluetidepro 3y ago
> “However, you are still not convinced, so you call your manager to ensure that the email is legit. He confirms, so you transfer the money.”
I feel like it’s a HUGE (silly) assumption you’d ask generically “did you send this email” instead of something more specific like “do you REALLY want me to transfer you money like this?” to which the manager would obviously be confused and the attack would likely be killed in that conversation.
This is an interesting attack vector but I am questioning how likely it is to succeed. The article paints a very specific and narrow window of events for this attack to really work. I don’t buy it, personally.
EDIT: I know phishing happens and works. I am not saying it doesn't. I just mean the people that fall for phishing don't need this sophisticated of an attack to fall for. In fact, the attacker probably narrows the chance of success by putting this much extra (very specific) effort into the attack. They are likely to just succeed with their typical phishing email.
- Macha 3y agoWorked for a 10,000 person company, 50% engineers. There'd be several cases a year of someone using the company credit card to buy gift cards for "the CEO" or other senior execs whose details are available on linkedin or corporate sites, despite that exact case being the example in the anti-phishing training. So you'd be surprised.
- bluetidepro 3y agoI don't doubt phishing happens. I just think this specific scenario/technique is one that is probably extremely rare. The attacker likely wouldn't put this much extra effort/thought in when their basic attacks already work, like you're describing.
- fkyoureadthedoc 3y agoSecurity at my job pumps their numbers by pretending you fell for a phish if you click the link in their obvious phishing test emails. I clicked one to see how good of a job they did at the other end of the link trying to extract whatever they want from me, but there's nothing there! So lazy.
- hk1337 3y agoI got dinged once for using curl (in a VM) on the link get the details to pass one when I reported it.
- npongratz 3y agoI once got dinged for forwarding an obvious gotcha email, without ever opening it, to our security team's phish notification address, as our employee handbook instructed. I learned my lesson.
- testudovictoria 3y agoI once got dinged for not reporting. I saw an email that was clearly an internal security campaign. I deleted it. I received an email a day or two later stating that I failed to take action on a phishing attempt. Damned if you do; damned if you don't.
- Macha 3y agoFor a while I had a thunderbird filter to automate forwarding based on our provider's email header. They disabled SMTP and the Gmail web client has no such ability to filter on arbitrary email headers.
- ohthatsnotright 3y agoYou can setup a Google app automation to do this for you. I did for e.g. knowbe4 since all their test emails have the same header information. It made it quite easy to never see any of their attempts, though I did have to check every once in a while to see if I'd been signed up for any random learning and it removed those emails as well..
- Macha 3y agoiirc, the same company had locked down the allowed oauth apps, so you would have needed an exception from security to run one. I doubt they'd have granted an exception to stop getting annoyed by their own training.
- raptor99 3y agoMaybe it's just good to be aware.
- tomhallett 3y agoWhile I’m not saying the specific scenario will work 100% of the time, it doesn’t need to - by the email getting forwarded at all, there is some element of trust in “my manager forwarded me this email and typed ‘complete this for me’”. If this css technique increases the attackers odds, then it’s an issue. Or for your specific example, imagine the recipient is passing their manager in the hallway: “hey, can we chat about the Acme Corp email, I’ve got some questions about it”. Response: “sorry, super busy. It’s a fairly common ask, just get it done!”
- mmsc 3y agoYou’re right. They wouldn’t ask any questions at all, and just send the money.
- bluetidepro 3y agoAgreed, the people falling for this would already fall for a much more basic phishing attempt. Thus, the attacker has no need to put this much extra effort/thought into it.
- themoonisachees 3y agoThis doesn't even need to be a hypothetical. We know that the attacked currently do not need to do this, because they don't. Darwin's law is very much in effect for scams of all types.
- croes 3y agoCould be a link to some kind of portal. You ask your boss if he sent the link to the portal, he confirms, they change the link to a phishing site.
- nkrisc 3y agoMy gut says this could be more effective. After all, the initial “phish” (the innocent looking email the manager receives) isn’t fishy at all, and unlikely to trigger any concern. Once the stakes are raised and the scam is revealed, the email has already been granted some amount of legitimacy. Sure, it can easily fail (“did you really want me to wire money to Cyprus?”), just as any phishing email can. But by bypassing the initial phishing filters of the recipient’s awareness, I could see it having a higher success rate than a cold phish that leads immediately with the scam. No evidence or knowledge either way, just a hunch.
- duxup 3y agoI agree that his seems so specific that while it is very interesting from a technical perspective, it is also much less likely compared to most phishing.
- dimask 3y agoI think that, in theory, it could allow for more sophisticated and targeted attacks, like changing the intended recipient of a money transfer. That would be much harder to detect.
- chromanoid 3y agoIt depends on the people I guess. Some managers will be annoyed of such conversations when they have to approve payments like that on multiple occasions a day - so employees might want to avoid such conversations. The attacker could even add something like that: "I am currently on a trip. If you are unsure call me on my private mobile phone number..." and then respond with a faked voice. I think a good way of reaching targets would be a "double" forward. So the sender assumes the role of an employee forwarding the email of a manager to an administration adjacent employee. This employee unsuspectingly forwards the seemingly harmless mail (that seems to be forwarded from the manager) again for a reason like birthday wishes or sick notice. This will make it hard for the actual target to understand where the email originally comes from. Beside that one can easily think up more creative ways to use this "feature". E.g. letting unsuspecting persons forward problematic content and then blackmail them etc.
- bambax 3y ago> I just mean the people that fall for phishing don't need this sophisticated of an attack to fall for Yes. It's more of the opposite. It's a well documented fact that the most obvious/ridiculous scams work the best, because they help select the most gullible potential victims. https://www.microsoft.com/en-us/research/publication/why-do-nigerian-scammers-say-they-are-from-nigeria/ https://www.microsoft.com/en-us/research/publication/why-do-...
- n2d4 3y agoThis is only true for high throughput spam e-mails, such as those sent to literally every e-mail address in a large data breach. Corporate phishing attacks are much, much more advanced.
- comicjk 3y agoThat analysis is from the perspective of the scammer. The scammer has limited time to write to each victim once the responses come back from the initial mass-email, so the scammer is better off if only the most gullible people reply. From the perspective of the person being attacked, the counterintuitive result based on selection bias goes away, and a more convincing scheme is more of a risk to you personally. (The assumption that scammers have limited time to write to each victim may itself become less true because of LLMs.)
- izacus 3y agoThat doesn't mean those scams are actually commonly successful.
- nebulous1 3y agoI agree, but actually it's just a really bad example that takes the reader to the wrong place because it has the participants acting so irrationally. The underlying issue is still there, they've just distracted from it by putting this in and having the reader go "hang on a second". They should have used a situation that was more believable, but also concentrated more on requests where the target likely wouldn't even seek confirmation.
- salesynerd 3y agoOne scenario where this night not be far-fetched is when such mails are sent to the accounts payable department of large companies. The people are not going to call a line manager everytime a payment request comes through email, especially if the dollar amount is small and didn't require pre-approval. I remember even Google had fallen prey to such a scam where they were paying somebody even though no work was done. Admittedly, that case involved fictitious invoices. However, the principle remains the same.
- sonicanatidae 3y agoThis attack works like normal Sales calls. Hit enough of them and you'll find someone that's new, or in a rush, or distracted or ancient or challenged or a Republican idiot, or, or. That's why it's still in use today. It works, but takes a lot of "cold calling" via phishing to find targets.
- michaelmrose 3y agoA more trivial gambit is logging into an attacker controlled site leaking credentials or installing malware. Also office drones are probable targets. They won't want to waste important peoples time asking for confirmation.
- willd13 3y agoStill pretty cool trick though
- mikeiz404 3y agoI agree the example they give seems a bit unlikely especially since the subject line is not changing (though admittedly I do not have experience in this area). However something a little more subtle such as swapping out a routing number from a legitimate to an illegitimate one could be done and that seems harder to catch especially if the person who forwarded it to you is supposed to verify it first.