
By Judi Hasson
Excerpt:
"Simple phishing usually casts a wide net to steal identities by sending out a mass e-mail that claims to be from, say, eBay, PayPal, a bank or credit card company. Spear phishing, on the other hand, is much more targeted and much more personal. These e-mails are designed with you in mind, providing information that tricks you into believing that a legitimate source sent them. It could seem to be your trusted colleague, a manager from another business unit or agency office, or your boss…
"Core Security Technologies, a Boston, Mass.-based security firm, offers an e-mail program to teach workers how to avoid spear phishing. The program can be part of any defensive plan and requires workers to be tested repeatedly with fake attacks. Paul Paget, chief executive officer at Core Security, says about 15 percent of tested workers fail."
Source: GovernmentExecutive.com











