Case Study: Email and Phone Phishing Incident

Cybersecurity case study phone phishing

Here’s a real example of how everyone is a potential target for phishing attacks and what you can do to reduce your risk.

What happened

Just after New years, the principal at a large retailer in Etobicoke received an email from Microsoft asking him to give them a call to fix an urgent account issue. He called the support number listed in the email and they explained the situation to him–his account needed quick update with the latest patch, and they could help him install it.

Patches are updates released to fix vulnerabilities in software. Staying up to date with them is important for protecting systems from cyber threats and ensuring data integrity. But, many critical patches are installed automatically.

Shortly after downloading and installing the files he was instructed to, the call ended abruptly. Thinking there was something off, the Principal told his colleague about the situation. She advised him to immediately log out, disconnect the computer, and contact BSC.

What really happened

The Company Principal had been phished.

Phishing is a type of email-based cyberattack where bad actors attempt to trick users into revealing sensitive information or giving them access that they should not have.

The email that the Company Principal had received was not from Microsoft. It was just designed to look that way. They number he called did not go to Microsoft, it went to a bad actor. The instructions they gave him to download a “patch” were actually instructions to download malicious software.

What happened next

Following his colleagues advice, the Principal disconnected his device and contacted BSC.

Within minutes of being contacted, BSC technicians were able to remotely access the Company Principal’s machine. With the info they had been given, they found that the “patch” was actually a Remote Access Trojan (RAT)

RATs are a type of malware that, once installed, can give bad actors the ability to control a device or to lurk in the background and view a device’s screen–which can be useful when trying to steal passwords.

The BSC tech team were able to remove the malware and reviewed the system logs to confirm that nothing else had been installed or accessed. The phishing attack had been successful, but by thinking and acting quickly the company’s data remained secure.

Key takeaways

  • Phishing attacks can be multi-faceted: When we talk about phishing attacks, we use clear examples to illustrate how dangerous they can be. But in the real world, phishing attempts can be messier and harder to spot. They can extend beyond an email into other forms of communication that we may not instantly associate with phishing.
  • Be skeptical: The bad actors use social engineering to build and exploit trust. When you’re being asked to do something you don’t understand or when something does not seem right, it’s worth slowing things down and taking a second to question what is going on.
  • Don’t wait to ask for help: With cybersecurity incidents, a lot of damage can be done in a short time. If you suspect something is wrong, don’t hesitate to get in contact with IT.
  • Senior staff are prime targets: Principals, Owners, and Executives are prime targets for phishing. They tend to have access to everything and they’re usually the highest-profile (i.e. easiest for bad actors to research) online. When you’re training staff on cybersecurity, don’t forget to include the entire team.

At BSC Solutions Group we view every situation through a cybersecurity lens and have tools in place to detect and stop attacks before they become breaches. If you would like more information about how our cybersecurity services can help your business reduce risk, contact us today.