Things To Know About Malicious Email Links

Submitted by abshaver on

Cyber Security Awareness Month

Cybercriminals have started launching phishing attacks by hijacking legitimate email threads to deliver malicious links. By hacking legitimate email conversations, cybercriminals are hoping to trick people into believing the link is part of the email conversation and clicking on it. Here are some tips from our Information Risk Management team and Proofpoint, one of our email security vendors.

Things To Watch For

  • Phishing links may appear as responses to previous, legitimate email conversations.
  • The phishing links use spoofed URLs that are made to look like legitimate URLs.
  • The URLs redirect the recipient to download an executable (.exe) file. Running the file installs malicious software (malware).

What To Do If You Receive a Suspicious Email

  • Report any suspicious emails you receive at work using the Report Phish button in your email menu bar.
    Report Phish button in Outlook
  • Occasionally we send phishing simulations that are used to evaluate the potential impact of a real phishing attack. Report any emails that match the tactics described above.
  • If the email you reported is a simulation, you will see a notification alerting you to that. No further action is needed on your part.
  • If the email you reported is not a simulation, and you are concerned about a time-sensitive request, contact the person who sent the email by phone to verify they actually sent you the email request.
  • IF you accidentally clicked on a link within a suspected phish, call the Technology Service Center at 540-224-1599 (71599) right away to report it.  

Tips to Remember (at Work and at Home)

  • Go beyond surface clues when evaluating an email. Familiar logos, branding and names don't automatically mean that an email or website is safe. Cybercriminals often spoof well-known organizations.
  • Verify URLs, even if they’re sent through or posted to an internal cloud system or email platform. If a colleague's email account was compromised, the cybercriminal could be using a legitimate email address to send a phishing attack. These are very hard to spot, but your attention to detail can help.
  • Some phishing attacks use compromised email accounts to respond to email threads to appear more believable. Always be sure to verify unexpected URLs from people or businesses you know through a different means of communication, like a phone call or in-person conversation.

Questions?

Contact our Information Risk Management team at Information_Risk_Management@carilionclinic.org.

Publish date / time
News Type
Users that Liked
6499
18426
23735
14180
32311
9764
13742
Views
0
Thumbnail Image
warning icon
Unlisted
Off
Banner Image
malware warning icon
Sidebar
Body

National Cyber Security Awareness Month is observed each year in October. Started in 2004 by the National Cyber Security Division within the U.S. Department of Homeland Security and the non-profit organization National Cyber Security Alliance, the month is dedicated to raising awareness about the importance of cybersecurity and helping individuals and organizations protect themselves online as threats to technology and confidential data increase. 

During the month of October, the Information Risk Management Team will update the TSG Hub weekly with articles, quizzes, tips, and best practices to help you keep your information and our patients' information secure. Visit the Announcements page each week for more information, and the Resources page for additional resources.

Title
National Cyber Security Awareness Month Activities
Designated Comment Contact
emjefferson
Key Points HTML

Cybercriminals sometimes hack and hijack legitimate email threads to send phishing attempts to people on the email chain.

Always remain vigilant when clicking on links, even if they come from someone you know. If a link seems suspicious, report it.

October is National Cybers Security Awareness Month. We will have a number of activities available on the TSG hub throughout the month.