Published on Security Management (http://www.securitymanagement.com)
Business Executives are "Big Phish" to Hackers
By Matthew Harwood
Created 05/06/2008 - 17:25



    
Wrap-Up?: 
No
Weight: 
0
Lead Headline?: 
No
Date: 
05/06/2008
By Line: 
By Matthew Harwood
Teaser: 

Hackers are e-mailing phony subpoenas that, once opened, allow hackers to take control of corporate executives' computer or steal valuable information.

Hackers have devised a new phishing scam where they play Ahab to U.S. corporate executives' Moby Dick.

The scam, according to Agence France Presse [1], has a novel name.

Internet security insiders refer to the attacks as "whaling" because they use social-engineering trickery involved in "phishing" but target individual "big phish" instead of casting nets in a sea of Internet users.

In the scam, hackers send an e-mail to a targeted executive. The email looks official and carries the seal of the U.S. federal court in San Diego, California. Inside the e-mail—which contains the executive's name, address, and other individual details— is a link that allows the recipient to look at the subpoena online.

When the link is clicked, a fake but realistic document appears. At the same time, malicious code is downloaded onto the recipient's computer. The code allows hackers to take control of the computer or steal passwords and other valuable corporate information, which is then sent to a remote computer through the Internet.

The article reminds anyone receiving such an e-mail that, in the United States, subpoenas are traditionally delivered in person and not over the Internet.

 

 

Related Resources: 

Comments


Security Management is the award-winning publication of ASIS International, the preeminent international
organization for security professionals, with more than 35,000 members worldwide.

ASIS International, Inc. Worldwide Headquarters USA, 1625 Prince Street, Alexandria, Virginia 22314-2818
703-519-6200 | fax 703-519-6299 | www.asisonline.org
ASIS
Copyright © 2008, Security Management

Powered by: Phase2 Technology

Source URL: http://www.securitymanagement.com/news/business-executives-are-big-phish-hackers

Links:
[1] http://www.smh.com.au/news/security/hackers-harpoon-executives-in-whaling-attacks/2008/05/06/1209839606696.html