ANTenna Blog -- Security

CEO Spam Scam: Phishing For Big Fish

Posted by Keith Ferrell Wednesday, Apr 16, 2008, 12:19 PM ET

A new targeted spam campaign uses fake federal subpoenas to trick CEOs into clicking on a malware link. One source indicates that 15-20,000 spams went out. And amazingly, about 10 percent of the recipients responded!

This latest spear phishing con -- targeted mal-mails that include personalized information -- included one sent to the CEO of security company Cyveillance

Oops.

Cyveillance's CEO, Panos Anastassiadis, sprang into action, among other things posting a copy of the spear phish letter.

Unfortunately, not all of the CEOs were as sharp as Anastassiadis, nor, evidently, were their IT teams: the malware involved in the campaign exploits known vulnerabilities that could -- and, dammit, should -- have been patched.

And that's the heart of this particular lesson -- along with the "No, d'uh!" reminder that federal courts do not send subpoenas by e-mail; you'd think a CEO would know these things!

Or maybe not. (Obviously not.)

This one reminded me of a recent bMighty contribution from Cisco that points out the security flaws that management both creates and represents.

And clearly that's a flaw the spear phishers understand all too well.


Security
Business & E-Business | Government | IT | Management | bMighty




This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.



Explore ANTenna Blog
Most Recent Posts
ANTenna Blog Topics
     
     
ANTenna Bloggers
ANTenna Blog Roll



Browse by Category

bMighty Tech
Term Of Day:

Boost your tech
vocabulary!
bMighty's SMB
TechEncyclopedia
defines more than
20,000 IT terms.


FREE Technology Services Locator!

Search our database of 200,000 solution- provider locations by business activity, technology, vertical market, and customer size. Find a technology partner NOW.

go

Techweb
Informationweek Business Technology Network
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek MagazineGlobal CIOIWK Government ITbMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. DobbsContentinople
space
TechWeb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoNoJitter
Black HatGTECEnergy CampCloud ConnectGov 2.0 ExpoGov 2.0 Summit
space
Light Reading Communications Network
Light ReadingLight Reading AsiaUnstrungCable Digital NewsInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev ProNET Total Dev Pro CommunitySQL Total Dev Pro Community
space