Orange Team: Phishing

  • Phishing is a computer scam carried out by sending an email with the counterfeit logo of a credit institution or an e-commerce company, in which the recipient is invited to provide confidential data (credit card number, password to access the home banking, etc.), justifying this request with technical reasons.

    European Union agency for cybersecurity deals with Phishing and helps European citizens to recognize scams.

    Everyone is susceptible to phishing, which can take many different forms of targeting Internet users and extracting valuable information from them. Although we know a lot  about phishing, we know little about its relationship to demographic variables (such as age and gender). Some studies, however, that some age groups are more susceptible than others and how to remedy the situation.
    Young adults are one of the demographic groups with the highest presence on social networks and are more likely to be exposed and become easy targets for online phishers.

    A 2010 study also found that "younger people in the 18 – 25 age group are more frequently falling for phishing” than other sections of the population.

    Do you know anybody who had to face something related to phishing? What do you think you can do to stop this phenomenon?

    Please discuss this problem with your team mates here and come up with up to 10 questions for a survey to understand what we can do to fight this phenomenon and raise awareness about it.

  • Hints and suggestions about the team topic

    Phishing hints by Italian national team

    We attended a webinar organized by our local Education Office and we learned some interesting information that we like to share with the team.
    In Phishing:
    - The language used in the messages is overly formal
    - The language used in the messages is full of spelling errors
    - The messages have the appearance and characteristics very similar to those found on authoritative and particularly popular websites (banking institutions, postal institutions, and online payment services)
    - The message contains the information about the expiration of a specific password
    . The message contains information about the acceptance of changes in contractual conditions
    - The message contains request of information about Google, Facebook or Twitter accounts
    - The message speaks about particularly attractive job offers, which perhaps invite you to enter your bank details to ensure that you are among the first to benefit from them