Accessibility Statement Skip Navigation
  • Why PRWeb
  • How It Works
  • Who Uses It
  • Pricing
  • Login
  • GDPR
  • Create a Free Account
Return to PRWeb homepage
  • News
  • Resources
  • Contact
When typing in this field, a list of search results will appear and be automatically updated as you type.

Searching for your content...

No results found. Please change your search terms and try again.
  • News in Focus
      • Browse News Releases

      • All News Releases
      • Multimedia Gallery

      • All Multimedia
      • All Photos
      • All Videos
  • Business & Money
      • Auto & Transportation

      • Aerospace, Defense
      • Air Freight
      • Airlines & Aviation
      • Automotive
      • Maritime & Shipbuilding
      • Railroads and Intermodal Transportation
      • Supply Chain/Logistics
      • Transportation, Trucking & Railroad
      • Travel
      • Trucking and Road Transportation
      • View All Auto & Transportation

      • Business Technology

      • Blockchain
      • Broadcast Tech
      • Computer & Electronics
      • Computer Hardware
      • Computer Software
      • Data Analytics
      • Electronic Commerce
      • Electronic Components
      • Electronic Design Automation
      • Financial Technology
      • High Tech Security
      • Internet Technology
      • Nanotechnology
      • Networks
      • Peripherals
      • Semiconductors
      • View All Business Technology

      • Entertain­ment & Media

      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Financial Services & Investing

      • Accounting News & Issues
      • Acquisitions, Mergers and Takeovers
      • Banking & Financial Services
      • Bankruptcy
      • Bond & Stock Ratings
      • Conference Call Announcements
      • Contracts
      • Cryptocurrency
      • Dividends
      • Earnings
      • Earnings Forecasts & Projections
      • Financing Agreements
      • Insurance
      • Investments Opinions
      • Joint Ventures
      • Mutual Funds
      • Private Placement
      • Real Estate
      • Restructuring & Recapitalization
      • Sales Reports
      • Shareholder Activism
      • Shareholder Meetings
      • Stock Offering
      • Stock Split
      • Venture Capital
      • View All Financial Services & Investing

      • General Business

      • Awards
      • Commercial Real Estate
      • Corporate Expansion
      • Earnings
      • Environmental, Social and Governance (ESG)
      • Human Resource & Workforce Management
      • Licensing
      • New Products & Services
      • Obituaries
      • Outsourcing Businesses
      • Overseas Real Estate (non-US)
      • Personnel Announcements
      • Real Estate Transactions
      • Residential Real Estate
      • Small Business Services
      • Socially Responsible Investing
      • Surveys, Polls and Research
      • Trade Show News
      • View All General Business

  • Science & Tech
      • Consumer Technology

      • Artificial Intelligence
      • Blockchain
      • Cloud Computing/Internet of Things
      • Computer Electronics
      • Computer Hardware
      • Computer Software
      • Consumer Electronics
      • Cryptocurrency
      • Data Analytics
      • Electronic Commerce
      • Electronic Gaming
      • Financial Technology
      • Mobile Entertainment
      • Multimedia & Internet
      • Peripherals
      • Social Media
      • STEM (Science, Tech, Engineering, Math)
      • Supply Chain/Logistics
      • Wireless Communications
      • View All Consumer Technology

      • Energy & Natural Resources

      • Alternative Energies
      • Chemical
      • Electrical Utilities
      • Gas
      • General Manufacturing
      • Mining
      • Mining & Metals
      • Oil & Energy
      • Oil and Gas Discoveries
      • Utilities
      • Water Utilities
      • View All Energy & Natural Resources

      • Environ­ment

      • Conservation & Recycling
      • Environmental Issues
      • Environmental Policy
      • Environmental Products & Services
      • Green Technology
      • Natural Disasters
      • View All Environ­ment

      • Heavy Industry & Manufacturing

      • Aerospace & Defense
      • Agriculture
      • Chemical
      • Construction & Building
      • General Manufacturing
      • HVAC (Heating, Ventilation and Air-Conditioning)
      • Machinery
      • Machine Tools, Metalworking and Metallurgy
      • Mining
      • Mining & Metals
      • Paper, Forest Products & Containers
      • Precious Metals
      • Textiles
      • Tobacco
      • View All Heavy Industry & Manufacturing

      • Telecomm­unications

      • Carriers and Services
      • Mobile Entertainment
      • Networks
      • Peripherals
      • Telecommunications Equipment
      • Telecommunications Industry
      • VoIP (Voice over Internet Protocol)
      • Wireless Communications
      • View All Telecomm­unications

  • Lifestyle & Health
      • Consumer Products & Retail

      • Animals & Pets
      • Beers, Wines and Spirits
      • Beverages
      • Bridal Services
      • Cannabis
      • Cosmetics and Personal Care
      • Fashion
      • Food & Beverages
      • Furniture and Furnishings
      • Home Improvement
      • Household, Consumer & Cosmetics
      • Household Products
      • Jewelry
      • Non-Alcoholic Beverages
      • Office Products
      • Organic Food
      • Product Recalls
      • Restaurants
      • Retail
      • Supermarkets
      • Toys
      • View All Consumer Products & Retail

      • Entertain­ment & Media

      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Health

      • Biometrics
      • Biotechnology
      • Clinical Trials & Medical Discoveries
      • Dentistry
      • FDA Approval
      • Fitness/Wellness
      • Health Care & Hospitals
      • Health Insurance
      • Infection Control
      • International Medical Approval
      • Medical Equipment
      • Medical Pharmaceuticals
      • Mental Health
      • Pharmaceuticals
      • Supplementary Medicine
      • View All Health

      • Sports

      • General Sports
      • Outdoors, Camping & Hiking
      • Sporting Events
      • Sports Equipment & Accessories
      • View All Sports

      • Travel

      • Amusement Parks and Tourist Attractions
      • Gambling & Casinos
      • Hotels and Resorts
      • Leisure & Tourism
      • Outdoors, Camping & Hiking
      • Passenger Aviation
      • Travel Industry
      • View All Travel

  • Policy & Public Interest
      • Policy & Public Interest

      • Advocacy Group Opinion
      • Animal Welfare
      • Congressional & Presidential Campaigns
      • Corporate Social Responsibility
      • Domestic Policy
      • Economic News, Trends, Analysis
      • Education
      • Environmental
      • European Government
      • FDA Approval
      • Federal and State Legislation
      • Federal Executive Branch & Agency
      • Foreign Policy & International Affairs
      • Homeland Security
      • Labor & Union
      • Legal Issues
      • Natural Disasters
      • Not For Profit
      • Patent Law
      • Public Safety
      • Trade Policy
      • U.S. State Policy
      • View All Policy & Public Interest

  • People & Culture
      • People & Culture

      • Aboriginal, First Nations & Native American
      • African American
      • Asian American
      • Children
      • Diversity, Equity & Inclusion
      • Hispanic
      • Lesbian, Gay & Bisexual
      • Men's Interest
      • People with Disabilities
      • Religion
      • Senior Citizens
      • Veterans
      • Women
      • View All People & Culture

  • Hamburger menu
  • Cision PRWeb provides efficient communication tools to continuously engage with target audiences across multiple online channels
  • Create a Free Account
    • ALL CONTACT INFO
    • Contact Us


      11AM ET Sunday – 8PM ET Friday

  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • News in Focus
    • Browse All News
    • Multimedia Gallery
  • Business & Money
    • Auto & Transportation
    • Business Technology
    • Entertain­ment & Media
    • Financial Services & Investing
    • General Business
  • Science & Tech
    • Consumer Technology
    • Energy & Natural Resources
    • Environ­ment
    • Heavy Industry & Manufacturing
    • Telecomm­unications
  • Lifestyle & Health
    • Consumer Products & Retail
    • Entertain­ment & Media
    • Health
    • Sports
    • Travel
  • Policy & Public Interest
  • People & Culture
    • People & Culture
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR

Hacking Whales of the Retail World Can Start With Just One Little Phish
  • USA - English


News provided by

Global Digital Forensics

Sep 13, 2014, 04:00 ET

Share this article

Share toX

Share this article

Share toX

All that's needed for a major data breach is one little phish to take the bait
All that's needed for a major data breach is one little phish to take the bait

Hackers do enjoy the path of least resistance, and the weakest link in any security chain is almost always the human element.

Post this

New York, NY (PRWEB) September 13, 2014 -- The number of retail customers estimated to have been affected by massive retailer breaches over the last year is staggering, just look at some of the big names in this article published on September 8th in The New York Times, with Target and Home Dept alone tallying an estimated 100 million cardholders compromised. “If the current pace of these huge retailer data breaches continues to surge like it has over the last year, how long can it really be before every consumer in America finds themselves under the “credit protection” umbrella of a major retailer trying to hide a black eye because their customers’ private payment information was stolen by hackers,” says Joe Caruso, founder and CEO/CTO of Global Digital Forensics (GDF), a premier provider of cyber security solutions and 24/7 emergency incident response, “but the real stomach turner is that the attacks that have been so very successful over the last year are not even on the high end of advanced or complex, just hackers using basic techniques and malware. They only need to find a way to get one foot in the door to make it all work.”

Hackers make themselves at home

“Any time an intrusion occurs, it’s definitely not a good thing,” says Caruso. “But if you can identify the attack and stop it quickly, the long term damage to an organization is likely going to be negligible, like the annoyance of an unwanted houseguest. But when the intruder gets to set up camp right in the bedroom closet, takes control of the TV remote and the car keys, empties out the fridge, steals money from your wallet and ogles your significant other every chance they get, for months on end, the annoyance factor eventually bubbles up into a full-blown family crisis. That’s what these major data breaches are like, not a one night inconvenience, but a methodical disintegration of everything you worked so hard to achieve and maintain. And true to form, the breaches Home Depot, Target and even financial institutions like JPMorgan Chase suffered didn’t happen overnight, they lingered on for months before their “guests” were finally confronted and kicked out of the house, but the car and cash were already gone, the snapshots from the bedroom closet were already taken and a packet of ketchup was all that was left in the fridge. That’s why regular professional vulnerability assessments and penetration testing are so important, we’ll check all the closets, look under every bed, find your keys, make sure your fridge stays well stocked, and you’ll finally be able to change the channel to something enjoyable again.”

Gone phishing

“Hackers do enjoy the path of least resistance, and the weakest link in any security chain is almost always the human element. So it shouldn’t come as a surprise that the top tool in their arsenal is often social engineering,” warns Caruso, “and phishing and spear phishing emails are generally the weapons of choice, especially when they are hunting whales. National retail chains, financial institutions, the healthcare industry, they all spend enormous resources on cyber security, yet every time you look up another massive data breach is making headlines. So how do hackers keep on having such great success, seemingly at will? It’s simple, they focus on that crucial first step, getting that first foot in the door, and that’s where social engineering comes in. When we do penetration testing for clients, which is us putting on the black hat of a hacker to test an organization’s cyber security posture, we’ll run phishing and/or spear phishing campaigns just like real world hackers would. We’ll research the company online, we’ll craft an email that maximizes any publically available information to make it look legitimate, sometimes even with a signature of someone high up in the organization if we can find documents, memos or marketing materials which display it online, and we’ll even create a dummy website that looks like the real thing using links and images from their own real sites, eventually calling for the target to take action, like clicking on a link, or divulging their access credentials. We’ve done it many times, and to date we have never failed to get at least a small percentage of users in the targeted organization to take the bait. And since it only takes one set of credentials to get that initial toehold into a client’s network, which would basically give us free reign to introduce malware, exfiltrate sensitive ESI (Electronically Stored Information), or set up a stealth presence to observe everything happening and continue to escalate privileges by moving sideways across the network once inside, it becomes easy to see how even the best laid security plans are rendered moot when every single user is not fully up to speed when it comes to social engineering awareness. But they will be when we get done with our assessment and testing, we’ll have the proof in hand. Believe me, nothing has a more long lasting and powerful impact than being caught and called out, and nobody is nodding off when we present our findings and remediation suggestions. Phishing can basically turn anyone in an organization into an insider threat, even if they never meant to be, and we help clients arm their employees with the knowledge they need to avoid being caught in that position, and by extension, significantly improve their cyber security posture.”

Trusting luck is not a sound security policy, so don’t wait until it’s too late

*Global Digital Forensics is a recognized industry leader in the fields of computer forensics, cyber security and emergency incident response, with years of experience assisting clients in the government, banking, healthcare, education and corporate arenas. For a free consultation with a Global Digital Forensics specialist, call 1-800-868-8189 about tailoring a cost-effective plan which will meet your unique needs, without wasting resources on solutions you simply don’t need. Emergency responders are also standing by 24/7 to handle intrusion and data breach emergencies whenever and wherever they arise. Time is critical if a cyber incident has occurred, so don’t hesitate to get help. For more information, visit http://www.evestigate.com.

Aris Demos, Global Digital Forensics, http://www.evestigate.com, +1 800-868-8189, [email protected]

Modal title

Contact PRWeb

  • 11AM ET Sunday – 8PM ET Friday
  • Contact Us

About PRWeb

  • About PRWeb
  • Partners
  • Partnership Programs
  • Editorial Guidelines
  • Resources

Why PRWeb

  • Why PRWeb
  • How It Works
  • Who Uses It
  • Pricing

Accounts

  • Create a Free Account
  • Log in
  • Contact Us

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921

Contact Cision

Products

About

My Services
  • All News Releases
  • Online Member Center
  • ProfNet
Cision Distribution Helpline
888-776-0942
  • Legal
  • Site Map
  • RSS
  • Cookie Settings
Copyright © 2025 Cision US Inc.