On Nov. 17 the FBI issued its latest e-scam and warning alert titled "SPEAR PHISHING E-MAILS TARGET U.S. LAW FIRMS AND PUBLIC RELATIONS FIRMS." From the dire warning:
The FBI assesses with high confidence that hackers are using spear phishing e-mails with malicious payloads to exploit U.S. law firms and public relations firms. During the course of ongoing investigations, the FBI identified noticeable increases in computer exploitation attempts against these entities...Hackers exploit the ability of end users to launch the malicious payloads from within the network by attaching a file to the message or including a link to the domain housing the file and enticing users to click the attachment or link...In addition to appearing to originate from a trusted source based on the relevance of the subject line, the attachment name and message body are also crafted to associate with the same specific business interests.
Directly targeting PR firms? Interesting.
Got me thinking about what would entice me (or any savvy tech PR rep) to click a link even from a trusted source with same business interests in an otherwise sketchy looking email. Maybe these?
- (from a journalist) Rich - I want to review your client's web enabled printer, but first want a full briefing, oh and I will accept a full fact check and run the copy by you and your client for input, review and approval, just click here to fill out the scheduling form.
- (from an industry analyst) Good morning Rich - we're beginning research on the latest report, your client made the upper right corner, can you review here and let us know your thoughts?
- (from the client) Hey Rich - our product was panned in eWEEK this morning, check it out here, can you craft the response?
- (from an account servicer) Hi Rich! Please vote for my client's widget here, it will only take 4 seconds!
- (from the boss) Rich - just got this inbound lead, can you look at it and tell me what you know of them?
- (from HR) Rich - you can download a copy of your raise letter here. Congratulations!
My IT department is sweating bullets right now. Relax guys, I'm not that gullible...



Ha - yeah, like you'd get a raise letter Rich ;)
Posted by: Morgan McLintic | November 19, 2009 at 06:11 PM