Rise of Phishing-as-a-Service (PhaaS)
Selina CoenWhy Strong Phishing Protection Matters More Than Ever with the Rise of Phishing-as-a-Service (PhaaS)
There’s a clever phishing scam doing the rounds – the potential victim receives an email claiming to be from a Mailinator account, which they dispute is related to their service.
The email reads as follows:
Once clicking "Open in Docs," victims were asked to grant access to their account to a fake Google Docs app, which takes advantage of that access to highjack the victim's contacts list and use it to send out identical phishing emails to replicate the attack.
The sophisticated scam is very believable as it worked through Google's system. Most phishing scams try to steal personal information from victims by leading them to fake versions of real websites from an email.
Google reacted swiftly to the attack by shutting down the rogue app and adding warnings to suspected phishing emails.
What to do:
Google issued a number of statements detailing what happened and how it's protecting users from such exploits explaining that fewer than 0.1% of Gmail users were affected. They were also able to stop the scam within approximately one hour.
While phishing techniques are getting more sophisticated, there are lots of things users can do to avoid being phished. IT pros need to ensure their organization deploys a powerful spam filter that scans inbound and outbound email, provides RBL blocking and pattern filtering. Spam filters vary in effectiveness and are only part of the solution to preventing intentionally malicious attacks — especially phishing emails.
Read more here
Why Strong Phishing Protection Matters More Than Ever with the Rise of Phishing-as-a-Service (PhaaS)
Deepfakes are becoming increasingly realistic and accessible, posing serious cybersecurity and reputational risks for businesses. Learn how they work, the threats they pose, and what IT teams can do to...
Explore the critical importance of robust email security in 2025. Learn how advanced threats like phishing and business email compromise are evolving, and discover strategies to protect your organization effectively.
Sign-up for email updates...
Call us on USA +1 813 304 2544 or IRL +353 91 545555
Contact Us