<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>spearphishing &#8211; EFR Technology Group</title>
	<atom:link href="https://www.efrtechgroup.com/category/spearphishing/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.efrtechgroup.com</link>
	<description>We maintain technology so you don't have to!</description>
	<lastBuildDate>Sun, 19 May 2019 00:09:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://www.efrtechgroup.com/wp-content/uploads/2019/02/cropped-EFRTG-color-2-32x32.jpg</url>
	<title>spearphishing &#8211; EFR Technology Group</title>
	<link>https://www.efrtechgroup.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Google stats show how much a recovery number prevents phishing</title>
		<link>https://www.efrtechgroup.com/tech/google-stats-show-how-much-a-recovery-number-prevents-phishing/</link>
		
		<dc:creator><![CDATA[Randall]]></dc:creator>
		<pubDate>Sun, 19 May 2019 00:09:00 +0000</pubDate>
				<category><![CDATA[advanced protection program]]></category>
		<category><![CDATA[gear]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[multifactor]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[security key]]></category>
		<category><![CDATA[sms]]></category>
		<category><![CDATA[spearphishing]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[two-factor authentication]]></category>
		<guid isPermaLink="false">https://www.efrtechgroup.com/google-stats-show-how-much-a-recovery-number-prevents-phishing/</guid>

					<description><![CDATA[[ad_1] While SMS verification can be defeated by a targeted attack, Google&#8217;s ability to do things like send a prompt to a connected phone or have users verify where they last log in also help block sign-ins it thinks are suspicious. If you&#8217;re logging in on a brand new device or from a new location, [&#8230;]]]></description>
										<content:encoded><![CDATA[<p> [ad_1]<br />
</p>
<div>
<p style="text-align: center;"><img decoding="async" alt="Google Security" data-caption="Google Security" data-credit="Engadget" src="https://www.efrtechgroup.com/wp-content/uploads/2019/05/Google-stats-show-how-much-a-recovery-number-prevents-phishing.jpeg" data-mep="3037790"/></p>
<p>While <a href="https://www.engadget.com/2016/06/10/hacker-hijacks-deray-by-redirecting-his-verizon-phone-number/">SMS verification can be defeated by a targeted attack</a>, Google&#8217;s ability to do things like <a href="https://www.engadget.com/2017/07/14/google-will-nudge-sms-two-factor-users-to-try-its-way-instead/">send a prompt to a connected phone</a> or have users verify where they last log in also help block sign-ins it thinks are suspicious. If you&#8217;re logging in on a brand new device or from a new location, then you should expect a little more scrutiny, however because 38 percent of users didn&#8217;t have access to their phone, and 34 percent couldn&#8217;t get to a secondary email address, the worry is that requiring challenges all the time will increase account lockouts.</p>
<p style="text-align: center;"><img decoding="async" alt="Google" data-caption="Google" data-credit="" data-credit-link-back="" data-dam-provider="" data-local-id="local-2-1022086-1558161368435" data-media-id="83bbbde8-1e6b-4258-9471-408a71dd5a70" data-original-url="https://s.yimg.com/os/creatr-uploaded-images/2019-05/35163200-7937-11e9-bfbd-853d0aef6f60" data-title="Google" src="https://www.efrtechgroup.com/wp-content/uploads/2019/05/1558228616_876_Google-stats-show-how-much-a-recovery-number-prevents-phishing.jpeg"/></p>
<p>According to the Google data, &#8220;hack for hire&#8221; attacks that impersonate familiar people or Google itself are incredibly rare, but can include multiple attempts even after an initial message is rebuffed. That&#8217;s where steps like its <a href="https://www.engadget.com/2017/10/17/google-advanced-protection/">Advanced Protection Program</a> &#8212; that requires a user to setup two hardware keys and use one of them to login all the time &#8212; come in handy.</p>
<p>Mirroring the <a href="https://www.engadget.com/2018/07/24/security-keys-google-phishing/">results Google has seen since requiring employees to use hardware keys</a>, researchers said zero users who exclusively use security keys &#8212; despite the <a href="https://www.engadget.com/2019/05/15/google-recalls-some-titan-bluetooth-security-keys/">presence of a flaw that&#8217;s caused a recall</a> of Google&#8217;s Bluetooth Titan Key &#8212; had fallen victim to targeted phishing. Limiting the attack surface based on physical proximity, and <a href="https://medium.com/@mrisher_2499/phishing-and-security-keys-b5c8e8e26931?sk=1c1d4ec63df28f4da3971b6508e04d6d">because a site has to verify itself to the security key</a>, keeps phishing attacks at bay, even for people who are being targeted specifically.</p>
</p></div>
<p>[ad_2]<br />
<br /><a href="https://www.engadget.com/2019/05/18/phishing-google-advanced-security-2fa/">Source link </a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>EU approves cyber-attack sanctions ahead of election</title>
		<link>https://www.efrtechgroup.com/tech/eu-approves-cyber-attack-sanctions-ahead-of-election/</link>
		
		<dc:creator><![CDATA[Randall]]></dc:creator>
		<pubDate>Fri, 17 May 2019 21:58:00 +0000</pubDate>
				<category><![CDATA[China]]></category>
		<category><![CDATA[cyber attacks]]></category>
		<category><![CDATA[elections]]></category>
		<category><![CDATA[Entertainment]]></category>
		<category><![CDATA[eu]]></category>
		<category><![CDATA[european parliament]]></category>
		<category><![CDATA[european union]]></category>
		<category><![CDATA[jeremy hunt]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[Russia]]></category>
		<category><![CDATA[russian hackers]]></category>
		<category><![CDATA[sanctions]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[spearphishing]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[tomorrow]]></category>
		<guid isPermaLink="false">https://www.efrtechgroup.com/eu-approves-cyber-attack-sanctions-ahead-of-election/</guid>

					<description><![CDATA[[ad_1] UK Foreign Secretary Jeremy Hunt in a statement called the move &#8220;decisive action&#8221; to deter future cyber attacks. &#8220;For too long now, hostile actors have been threatening the EU&#8217;s security through disrupting critical infrastructure, attempts to undermine democracy and stealing commercial secrets and money running to billions of Euros,&#8221; said Hunt. Russia and China [&#8230;]]]></description>
										<content:encoded><![CDATA[<p> [ad_1]<br />
</p>
<div>
<p>UK Foreign Secretary Jeremy Hunt in a statement called the move &#8220;decisive action&#8221; to deter future cyber attacks. &#8220;For too long now, hostile actors have been threatening the EU&#8217;s security through disrupting critical infrastructure, attempts to undermine democracy and stealing commercial secrets and money running to billions of Euros,&#8221; said Hunt.</p>
<p>Russia and China regularly engage in cyber warfare against the EU and other nations, and were behind several high-profile attacks in recent months. Earlier this year, Chinese state-sponsored hackers were revealed to be behind <a href="https://www.upi.com/Top_News/World-News/2019/02/06/Report-Chinese-group-APT10-hacked-US-Norwegian-companies/1221549471498/">attacks</a> on Norwegian software firm Visma and European aerospace company<a href="https://www.upi.com/Top_News/World-News/2019/02/06/Report-Chinese-group-APT10-hacked-US-Norwegian-companies/1221549471498/"> Airbus</a>. Hackers released the <a href="https://www.wired.com/story/germany-hacking-politicians-personal-information/">private emails </a>of hundred of German politicians back in December. In September, two Russian spies were<a href="https://www.nytimes.com/2018/09/14/world/europe/russians-salisbury-swiss-lab-sabotage.html"> caught </a>deploying cyber tools in order to sabotage the Swiss defense lab tasked with analyzing the nerve agent used to poison former Russian Agent Sergei Skripal.</p>
<p>EU leaders have voiced concerns that Russia will interfere in the European Parliament elections, which is set to occur between May 23rd and May 26th. Held once every five years, this upcoming EU Parliament election will be the first since Russia&#8217;s disinformation campaign aimed at the 2016 US presidential election put other nations on high alert for similar behavior. A total of 751 <a href="https://carnegieendowment.org/2019/04/18/eu-s-looming-test-on-election-interference-pub-78938">seats </a>are up for grabs. Security firm Fireeye <a href="https://www.engadget.com/2019/03/21/russia-hackers-influence-eu-election-phishing/">reported </a>earlier this year that Russian hackers had been targeting European government agencies, as well media outlets in France and Germany.</p>
</p></div>
<p>[ad_2]<br />
<br /><a href="https://www.engadget.com/2019/05/17/eu-approves-cyber-attack-sanctions-ahead-of-election/">Source link </a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>US charges China-based hacking group for massive 2015 Anthem breach</title>
		<link>https://www.efrtechgroup.com/tech/us-charges-china-based-hacking-group-for-massive-2015-anthem-breach/</link>
		
		<dc:creator><![CDATA[Randall]]></dc:creator>
		<pubDate>Fri, 10 May 2019 14:00:00 +0000</pubDate>
				<category><![CDATA[Anthem]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[charges]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[conspiracy]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[fbi]]></category>
		<category><![CDATA[fuji wang]]></category>
		<category><![CDATA[gear]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking group]]></category>
		<category><![CDATA[indictment]]></category>
		<category><![CDATA[john doe]]></category>
		<category><![CDATA[justice department]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[spearphishing]]></category>
		<category><![CDATA[Tech]]></category>
		<guid isPermaLink="false">https://www.efrtechgroup.com/us-charges-china-based-hacking-group-for-massive-2015-anthem-breach/</guid>

					<description><![CDATA[[ad_1] Wang and Doe reportedly used &#8220;extremely sophisticated techniques,&#8221; including specially-tailored spear-phishing emails with embedded hyperlinks. When employees of the targeted businesses clicked the hyperlinks, a file downloaded and deployed malware, which created a backdoor to the computer systems. In some cases, the defendants waited months before taking further action. Then, they allegedly encrypted the [&#8230;]]]></description>
										<content:encoded><![CDATA[<p> [ad_1]<br />
</p>
<div>
<p>Wang and Doe reportedly used &#8220;extremely sophisticated techniques,&#8221; including specially-tailored spear-phishing emails with embedded hyperlinks. When employees of the targeted businesses clicked the hyperlinks, a file downloaded and deployed malware, which created a backdoor to the computer systems. In some cases, the defendants waited months before taking further action. Then, they allegedly encrypted the stolen files and sent them through multiple computers to servers in China.</p>
<p>When the Anthem attack occurred, the company was quick to detect it and to alert the FBI. That was a key factor in being able to determine who was responsible and &#8220;should serve as an example to other organizations that might find themselves in a similar situation,&#8221; said Special Agent in Charge Grant Mendenhall. The Justice Department says it will aggressively prosecute perpetrators of hacking schemes like these. However, the charges in this indictment are merely allegations, and Wang and Doe are presumed innocent until proven guilty.</p>
</p></div>
<p>[ad_2]<br />
<br /><a href="https://www.engadget.com/2019/05/10/us-indictment-china-hacking-group-data-breach/">Source link </a></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
