6 Ways to Defend Against Social Phishing Attacks

NB Technology, LLC.

June 21, 2022

Phishing is the number one method of attack delivery for everything from ransomware to credential theft. We are very aware of it coming by email, but other types of phishing have been growing rapidly. No matter where you are, social phishing makes you vulnerable.

In recent years, phishing over social media has skyrocketed by 500%. There has also been a 100% increase in fraudulent social media accounts.


Phishing over social media often tricks the victims because people tend to let their guard down when on social platforms like Facebook, Instagram, Twitter, and LinkedIn. They’re socializing and not looking for phishing scams.

 

However, phishing scammers are out there looking for you and will reach out via friend requests and direct messages. Learn several ways you can secure your social media use to avoid these types of covert attacks.


STRATEGY #1. MAKE YOUR PROFILE PRIVATE ON SOCIAL PLATFORMS

Phishing scammers love public profiles on social media because not only can they gather intel on you to strike up a conversation, but they can also clone your profile and put up a fake page for phishing your connections.


Criminals do this in order to try to connect with those on your friends or connections list to send social phishing links that those targets will be more likely to click because they believe it’s from someone they know.


You can limit your risk by going into your profile and making it private to your connections only. This means that only someone that you’ve connected with can see your posts and images, not the general public.


For sites like LinkedIn where many people network for business, you might still want to keep your profile public, but you can follow the other tips below to reduce your risk.


STRATEGY #2. HIDE YOUR CONTACTS/FRIENDS LIST

You can keep social phishing scammers from trying to use your social media profile to get to your connections by hiding your friends or connections list. Platforms like LinkedIn and Facebook both give you this privacy option.


Just be aware that this does not keep scammers from seeing you as a friend or connection on someone else’s profile unless they too have hidden their friends list.


STRATEGY #3. BE WARY OF LINKS SENT VIA DIRECT MESSAGE & IN POSTS

Links are the preferred way to deliver phishing attacks, especially over social media. Links in social posts are often shortened, making it difficult for someone to know where they are being directed until they get there. This makes it even more dangerous to click links you see on a social media platform.


A scammer might chat you up on LinkedIn to inquire about your business offerings and give you a link that they say is to their website. Unless you know the source to be legitimate, do not click links sent via direct message or in social media posts. They could be leading to a phishing site that does a drive-by download of malware onto your device.


Even if one of your connections shares a link, be sure to research where it is coming from. People often share posts in their own feeds because they like a meme or picture on the post, but they never take the time to check whether the source can be trusted.


STRATEGY #4. DON'T PARTICIPATE IN SOCIAL MEDIA SURVEYS OR QUIZZES

While it may be fun to know what Marvel superhero or Disney princess you are, stay away from quizzes on social media. They’re often designed as a ploy to gather data on you. Data that could be used for targeted phishing attacks or identity theft.


The Cambridge Analytica scandal that impacted the personal data of millions of Facebook users did not happen all that long ago. It was found that the company was using surveys and quizzes to collect information on users without their consent.


While this case was high-profile, they’re by no means the only ones that play loose and fast with user data and take advantage of social media to gather as much as they can.


It’s best to avoid any types of surveys or quizzes on any social media platform because once your personal data is out there, there is no getting it back.


STRATEGY #5. AVOID PURCHASING DIRECTLY FROM ADS ON FACEBOOK OR INSTAGRAM

Many companies advertise on social media legitimately, but unfortunately, many scammers use the platforms as well for credit card fraud and identity theft.



If you see something that catches your eye in a Facebook or Instagram ad, go to the advertiser’s website directly to check it out, do not click through the social ad.


STRATEGY #6. RESEARCH BEFORE YOU ACCEPT A FRIEND REQUEST

It can be exciting to get a connection request on a social media platform. It could mean a new business connection or connecting with someone from your Alma mater. But this is another way that phishing scammers will look to take advantage of you. They’ll try to connect to you which can be a first step before reaching out direct via DM.



Do not connect with friend requests without first checking out the person on the site and online using a search engine. If you see that their timeline only has pictures of themself and no posts, that’s a big red flag that you should decline the request.


CAN YOUR DEVICES HANDLE A PHISHING LINK OR FILE?

It’s important to safeguard your devices with things like DNS filtering, managed antivirus, email filtering, and more. This will help protect you if you happen to click on a phishing link.


If you're a local Charlotte area business and want to learn more about your vulnerabilities, set up a 15 minute chat today to find out how we can help!

Article used with permission from The  Technology  Press.

zero-click malware code on a screen
By Blogger Admin December 31, 2024
Stay vigilant against zero-click malware! Discover what it is, how it works, and arm yourself with effective strategies to combat this silent digital threat.
app fatigue
By Blogger Admin December 17, 2024
If you have app fatigue, that could put the security of your devices at risk. Find out how to deal with app fatigue across your organization.
Microsoft Teams Virtual Appointments
By Blogger Admin December 3, 2024
Learn how to use Microsoft Team's Virtual Appointments to schedule meetings, collaborate and stay organized.
Windows 8.1 support
By Blogger Admin November 19, 2024
Windows 8.1 has lost all support, so here's what to do if you're still running this OS on your computer.
mobile malware code
By Blogger Admin November 5, 2024
Learn how to deal with and respond to the rise in mobile malware attacks.
Image of a technology infrastructure review
By Blogger Admin October 22, 2024
Learn what you should include in a year-end IT technology infrastructure review.
phishing scam
By Blogger Admin October 8, 2024
Find out more about how to detect whether that message you got from your CEO is actually from them, or just a phishing scam.
cyber insurance letter
By Blogger Admin September 24, 2024
Here are 4 of the latest trends in cybersecurity insurance that you should know about.
data breach
By Blogger Admin September 10, 2024
These are some of the most famous data breaches in history - check to see if your data has been breached here.
Image of someone using Google to perform a search online
August 27, 2024
Find out about these Google search tips that can help save you time and enhance your productivity.
Show More
Share by: