Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

Spam Can Be Tricky, So Keep an Eye Out for These Warning Signs

Spam Can Be Tricky, So Keep an Eye Out for These Warning Signs

Sometimes, I kind of miss the oh-too-obvious spam emails that were once the norm. You know, the kind that were supposedly from some usurped royal who needed your assistance to reclaim their rightful place on the throne, or from some absurdly attractive individual who seemed to be coming on to you. Sure, at the time it was annoying, but compared to today’s spam…

Well, it was a simpler time.

Unfortunately, the reason those old scams were common enough to become semi-fond memories is that, on occasion, they worked.

People fell for these kinds of scams all the time, sending money out with the expectation that huge sums would come flowing back. Hopeful singles would reach out in the hope that they’d stumbled across true love (and all the perks that implied).

Success is what makes spammers continue today. For them, it’s all a big numbers game: some percentage of users will fall for different types of spam campaigns, and scammers now know the tricks to improve their conversion rates. Spam is a formula: x-number of emails equals y percent of successful victims—they just need to solve for x.

If you’re going to protect your business from these attacks and scams, you need to know the kind of tactics to keep an eye out for.

Email Spoofing

Some unknown sender is one thing, but surely a dangerous email wouldn’t come from Amazon, PayPal, Google, your mother, the bank, your employer, or someone like that…would it?

Unfortunately, spam can now be spread that is designed to mimic what you’d expect to see from a trusted email address. Posing as a legitimate business has been part of the spam and phishing playbook for quite some time, as they are highly scalable and applicable to most people. Chances are pretty good that any given person will have an Amazon or Google account nowadays, after all.

Otherwise, these attacks can be far more targeted. Let’s say your bank had its member contact list stolen in a data breach. That list gives a scammer all they need to target your bank’s members with a convincing and effective scam, customized to them.

Social media is also a useful tool. A scammer could find a potential target, their contact information, the people in their life whom the target would be most likely to help, and their contact information. At that point, a little technical knowledge is all that a scammer needs to run extremely personalized campaigns.

Homograph and Punycode Attacks

“Tear.”

Now, what did you read that word as? Did you read “tear,” as in the act of ripping something, or “tear,” the thing that comes out of your eyes when you’re hurt or sad?

This is what is known as a homograph, the phenomenon where two different words are spelled the same but have different meanings. In terms of scams, homograph attacks are used to trick a user into trusting an email or website URL by making it look like a different one. Basically, non-traditional keyboard characters are translated to look like familiar ones, which makes it easier for an attacker to spoof a well-known domain or legitimate-looking email address without actually owning it.

Homograph and Punycode attacks aren’t exclusive to email, as we alluded to above. Fake websites that look legitimate can be built to steal information, and links can be shared through messaging apps and social media. Unfortunately, this means you effectively need to be on your guard when it comes to any activity or correspondence.

Email Compromise

An entire email inbox can be leveraged by a cybercriminal as a weapon—and it’s actually one of the oldest means used to distribute malware and spam, even to this day. If your password is stolen or too weak, or malware happens to sneak in, your email can be compromised and used to propagate the threat by sending emails out to your contact lists.

Since these emails come from your account, most recipients will see them to be legitimate and open them. Once they do, the process repeats, exponentially spreading.

If someone isn’t as focused on their cybersecurity hygiene as they should be, a hacker can have a very easy time accessing their email.

For instance, let’s say that Jason uses the same password on his work email and his Amazon Prime account. His kids use his password to access Amazon Video to watch The Boys and The Rings of Power, but one day, malware infects his son’s tablet and steals the password. As a result, Jason’s user credentials are up for sale on the Dark Web, along with the tens of thousands of other credentials this malware has stolen. On sale for pennies on the dollar, scammers and cybercriminals from all over are able to access and utilize it. It doesn’t take long for them to start trying these username and password combinations in other places, and before long, Jason’s work email is breached.

From there, an attacker can email contacts, of course, read messages, change any passwords to the accounts that tie to that email address, reset passwords, and more. Jason’s friends, family, coworkers, and clients are all scammed, expanding the attacker’s web of influence.

This goes the other way, too—your friends, family, and colleagues could cut corners with their cybersecurity, resulting in you being victimized as a result.

Skepticism and Awareness are Key to Preventing Cyberattacks and Scams

This should all go to show that scams and phishing attacks are increasingly difficult to spot, meaning that the most effective defense is an abundance of caution. We recommend what is called a zero-trust approach—if you didn’t specifically request an email attachment and did not expect one to accompany a message, don’t click on it or download it.

If your bank messages you regarding an unauthorized purchase, don’t panic. Instead, log into your bank account separately to check, not using any link received through the message.

Make sure you cultivate this kind of cautious culture in your business, too. If you send someone an email with an attachment, shoot them a quick phone call or instant message to let them know it’s on its way. Even internally, acting with security coming first in your correspondence is a wise policy.

Encourage your team to act safely concerning their email, and it will pay off—period.
Our technicians are here to help your team members, including with your email security. If a team member receives a suspicious email, we can check it out for you. Give us a call today at 800.618.9844.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Friday, 25 April 2025

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Business Computing Data Productivity Business Software Innovation Hackers Cloud Network Security User Tips Internet Hardware Efficiency IT Support Malware Privacy Google Email Workplace Tips Phishing Computer IT Services Hosted Solutions Users Collaboration Mobile Device Ransomware Quick Tips Workplace Strategy Microsoft Cybersecurity Small Business Passwords Data Backup Communication Smartphone Backup Saving Money VoIP Smartphones Android Business Management Managed Service Mobile Devices communications Upgrade Disaster Recovery Data Recovery Browser Social Media Managed IT Services Microsoft Office Windows Network Tech Term Remote Current Events Internet of Things Automation Productivity Artificial Intelligence Facebook Gadgets Cloud Computing Covid-19 Miscellaneous Server Managed Service Provider AI Remote Work Outsourced IT Information Holiday Employee/Employer Relationship Encryption Spam Windows 10 Office Compliance Training Government Data Management Business Continuity Business Technology Wi-Fi Windows 10 Blockchain Bandwidth Virtualization Apps Two-factor Authentication Mobile Office Data Security App Employer-Employee Relationship Managed Services Voice over Internet Protocol Networking Mobile Device Management Chrome Gmail Budget BYOD Vendor Apple Access Control Tip of the week Conferencing Computing Hacker Information Technology Avoiding Downtime Marketing How To Office 365 BDR IT Support WiFi Applications Health Help Desk Operating System Computers Retail Healthcare Risk Management Website Managed IT Services Analytics Office Tips Augmented Reality Storage Password HIPAA Router Bring Your Own Device Virtual Private Network Big Data Social Printer Windows 11 Paperless Office Infrastructure Monitoring Going Green 2FA Excel Document Management Customer Service Cybercrime Remote Workers Telephone Scam Data loss Cooperation Free Resource Project Management Windows 7 Firewall Patch Management Save Money Microsoft 365 Remote Monitoring End of Support Vulnerability Vendor Management Solutions The Internet of Things Physical Security Display Computer Repair Mobile Security Processor Holidays Data Storage Smart Technology Supply Chain Customer Relationship Management Video Conferencing Settings Wireless Printing Machine Learning Managed Services Provider Virtual Machines Professional Services Content Filtering Saving Time Hacking Presentation YouTube Managed IT Service Maintenance Cryptocurrency Downloads Antivirus Wireless Technology iPhone Licensing Virtual Desktop Data storage LiFi Vulnerabilities Entertainment Data Privacy Word Outlook Images 101 Robot Mobility Telephone System Money Multi-Factor Authentication Humor Cost Management Safety IT Management Sports VPN Employees Mouse Meetings Integration Administration User Tip Modem Database Surveillance Application Best Practice Virtual Assistant Outsource IT Network Management Tech Support IT Technicians Virtual Machine Environment Buisness Media IT solutions Monitors Cyber Monday Medical IT Proxy Server Reviews IBM Legal Cookies Tactics Development Business Growth Hotspot Transportation Small Businesses Websites Mirgation Hypervisor Displays PowerPoint Cortana Shopping Nanotechnology Optimization SharePoint Addiction Alt Codes Electronic Medical Records Language Employer/Employee Relationships Outsourcing Management PCI DSS Competition Chatbots Downtime Navigation Screen Reader Hosted Solution Writing Distributed Denial of Service Workplace Lenovo Gig Economy Service Level Agreement Internet Service Provider Typing Virtual Reality Computing Infrastructure Teamwork Hiring/Firing Evernote Paperless Server Management Regulations Compliance Private Cloud Identity Identity Theft Smart Tech Memes User Co-managed IT Knowledge Superfish Bookmark Google Drive Download Net Neutrality Twitter Alerts SQL Server Technology Care Business Communications 5G Financial Data Error History Google Docs Connectivity IT Unified Communications Social Engineering Break Fix Scams Experience Browsers Smartwatch IP Address Upload Procurement Bitcoin Remote Computing Azure Hybrid Work Running Cable Multi-Factor Security Tech Human Resources Social Network Telework Google Wallet Cyber security Tablet IoT Communitications Recovery Dark Web Cables CES Trends Supply Chain Management Hard Drives Windows 8 Alert Laptop Dark Data Google Calendar Term Google Apps Managed IT Customer Resource management FinTech Domains Drones File Sharing Regulations Star Wars IT Assessment How To Microsoft Excel IT Maintenance Data Analysis Gamification Flexibility Refrigeration Notifications Staff Value Business Intelligence Halloween Legislation Shortcuts Organization Public Speaking Travel Social Networking Lithium-ion battery Google Maps Smart Devices Ransmoware Techology Fileless Malware Digital Security Cameras Content Remote Working Hacks Wearable Technology Memory Vendors Entrepreneur Scary Stories Comparison Google Play Be Proactive Fun Health IT Unified Threat Management Motherboard Data Breach Assessment Electronic Health Records Deep Learning Permissions Workforce Unified Threat Management Directions Videos Undo Wasting Time Threats Education Network Congestion Specifications Security Cameras Workplace Strategies Trend Micro Internet Exlporer Software as a Service Fraud Meta User Error Microchip Username Mobile Computing Managing Costs Amazon Black Friday SSID Search Point of Sale eCommerce

Blog Archive