Phishing is a type of fraud aimed at obtaining confidential data from users or companies.
Regular phishing targets a wide audience. Fraudsters send spam to steal passwords, bank card details, or gain access to personal accounts.
Corporate phishing targets employees with access to critical data. The goal of this type of phishing is to gain access to internal systems, or disrupt infrastructure operations.
How fraudsters deceive
Research the company. Fraudsters start by examining social media, the company structure, and communication style.
Forge emails from executives or colleagues using cloned domains.
Send messages pretending to be real employees, complete with profile photos. They may also send voice messages generated by artificial intelligence.
Send malicious files. For instance, asking to update a program.
Create fake login pages to steal passwords.
How to protect against phishing
We have compiled several tips to help protect yourself and your company from fraudsters.
Don’t click on links immediately and check the sender’s address. Hover over the name in the email or the link to see the actual email and domain.
Avoid opening suspicious attachments. For example, files asking to update a program or enable macros. Files in exe, js, scr formats, or password-protected zip files may be malicious.
Don’t rush to follow instructions in emails marked "Urgent". Verify any suspicious requests for money transfers or data by calling or messaging a colleague in your work chat.
Keep your software updated. Updates fix vulnerabilities that fraudsters exploit.
Set up an email filtering system. These systems use special algorithms to check incoming emails, filter out suspicious ones, and send them to spam.
Develop and implement an information security policy. Your company should have clear rules on checking emails, using the internet and smartphones, and responding to hacking attempts.
Use antivirus software and two-step authentication.
Enable two-step authentication for Bitrix24 login
Train employees to recognize phishing. Organize lectures and webinars on cyber fraud and conduct tests to assess their knowledge.
Carefully check the domain of the site where you want to log in. For example, the Bitrix24 cloud address only contains the bitrix24 domain, not bltrix, bitrix25, or others.
Report suspicious emails or websites to your company’s security department. Stay vigilant and always double-check suspicious messages.
- Phishing is a type of fraud aimed at obtaining confidential data from users or companies.
- Regular phishing targets a wide audience. Fraudsters send spam to steal passwords, bank card details, or gain access to personal accounts.
- Corporate phishing targets employees with access to critical data. The goal is to gain access to systems, or disrupt infrastructure operations.
- To protect your company’s data from fraudsters, follow these rules: avoid opening suspicious emails and attachments, verify sender addresses, update software, use antivirus software and two-step authentication, and develop and implement an information security policy.