The bMighty Blog -- Security

CEO Spam Scam: Phishing For Big Fish

Posted by Keith Ferrell Wednesday, Apr 16, 2008, 12:19 PM ET

A new targeted spam campaign uses fake federal subpoenas to trick CEOs into clicking on a malware link. One source indicates that 15-20,000 spams went out. And amazingly, about 10 percent of the recipients responded!

This latest spear phishing con -- targeted mal-mails that include personalized information -- included one sent to the CEO of security company Cyveillance

Oops.

Cyveillance's CEO, Panos Anastassiadis, sprang into action, among other things posting a copy of the spear phish letter.

Unfortunately, not all of the CEOs were as sharp as Anastassiadis, nor, evidently, were their IT teams: the malware involved in the campaign exploits known vulnerabilities that could -- and, dammit, should -- have been patched.

And that's the heart of this particular lesson -- along with the "No, d'uh!" reminder that federal courts do not send subpoenas by e-mail; you'd think a CEO would know these things!

Or maybe not. (Obviously not.)

This one reminded me of a recent bMighty contribution from Cisco that points out the security flaws that management both creates and represents.

And clearly that's a flaw the spear phishers understand all too well.


Business & E-Business | Government | IT | Management | Security | bMighty




This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.


Spotlight on Solutions
(Sponsored By Cisco)


Explore the bMighty Blog
Most Recent Posts
bMighty Blog Topics
     
bMighty Bloggers
bMighty Blog Roll



Browse by Category
Imaging How-To Center

Document imaging basics, plus how to select a solution

go

FREE Technology Services Locator!

Search our database of 200,000 solution- provider locations by business activity, technology, vertical market, and customer size. Find a technology partner NOW.

go

Tech Term of the Day: AV

TechEncyclopedia gives you the meaning of today's word, plus more than 20,000 additional IT terms and definitions.


techweb
Online Communities TechWebInformationWeekLight ReadingIntelligent EnterprisebMightyNetwork ComputingDark ReadingDigital LibraryWall Street & Technology
Byte & SwitchNo JitterInternet EvolutionLight Reading's Cable Digital NewsContentinopleUnStrungBank Systems & TechnologyAdvanced TradingInsurance & Technology
Face-to-Face Events
InteropWeb 2.0 ExpoWeb 2.0 SummitVoiceConBlack HatCSISoftwareEntrprise 2.0 ConferenceGTEC
Mobile Business Expo
InformationWeek 500 ConferenceBuy Side Trading XchangeBuy Side Trading SummitBank Executive SummitInsurance Executive SummitTelcoTVEthernet ExpoOptical Expo
Magazines  
InformationWeekWall Street & TechnologyInsurance & TechnologyBank Systems & TechnologyAdvanced TradingMSDNTechNetSmart EnterpriseThe Architecture JournalDatabase Magazine
 
Research & Analyst Services  
Heavy ReadingInformationWeek ReportsInformationWeek Analytics