Spoofing: How it threatens your professional and personal life

Staff are receiving “spoofing” emails. Due to the publicity around our recent cyber-attack, this is unsurprising. Just like a natural disaster when scammers prey upon victims, it is the same with a cyber “disaster.” Unscrupulous people will try to make money off any sort of disaster– physical or virtual.

What is spoofing and why should you care:

Spoofing disguises communications from anunknown source as being from a known, trusted source (e.g., making an emailfrom a scammer appear to be one coming from your AIC). Spoofing can apply toemails, phone calls, web sites, etc. Finding anyone’s name or email address tospoof is ridiculously easy.

If your email has been spoofed, it DOES NOT meanyour account has been hacked. 99% of the time people say ‘my accounts have beenhacked’ (because they seem to be sending out phishing emails), they areactually being spoofed. Though, it never hurts to change your password.

Spoofing is used to

  1. identify if an emaila ddress is valid so the user can be targeted for more (and more serious)attacks. So, don’t reply to it
  2. trick you into clicking links that install malware on your computer
  3. steal your personal information for sale or blackmail you

How to recognize a spoofed email:

  1. You are not expecting the email, and it contains web links or attachments
  2. Generic subject (e.g., look at this, FW: Important, You’ll find this interesting) or generic content in the email (these go out to 1000s of people, so they have to be generic)
  3. Web address doesn’t match the web address you’d expect from the sender (see below)
  4. Includes web links or attachments (see below)
  5. You don’t recognize the email addresses of other people on the email
  6. Typos in web or email addresses
  7. Threatening email (e.g., your account has been hacked, credit cards are in default)

What to do if you receive a spoofed email:

  • Delete it and move on with your life
  • If you are unsure and know the person, call them back or email them and ask them if they sent the email. DO NOT USE THE EMAIL ADDRESS OR PHONE NUMBER IN THE EMAIL. If you have them in your address book,use that. Otherwise, Google them.

When in doubt about an email: Don’t click links or open attachments.

Spoofing is ridiculously easy to do. Basically, it is telling your email to send with a name or email address different from the actual name or email address on the account.

As of 2018, over 50% of email sent worldwide is phishing, spoofing and spam email. It is a serious problem that requires skepticism and vigilance.

The best general rule for cyber security is: Don’t click links and don’t open attachments.