A curated list of phishing attacks on employees at Sitel Okta Microsoft Globant Nvidia T-Mobile Cloudflare and Twilio
Paul Walsh
Making the internet safer through a radically new, human-centric approach to anti-phishing security. Most leading security companies license my patents for mobile app security. More pending for SMS security.
This article documents a chain of Phishing-led cyberattacks on big organizations by a group called Lapsus$. It's far from an extensive list though. The technique used for every single one of these attacks, without exception, is the same old, unsophisticated social engineering technique that was first discovered on the AOL network in 1996 - where I was one of the first people hackers impersonated on the Internet. Hackers impersonated senior people like me and community admins at AOL, inside email, chatrooms, and IM. Their aim was to trick AOL members into giving up control of their account, so they could trade it for money or software.
Phishing timeline
This is NOT a timeline for all phishing-led attacks, that would require me to break everything down by the hour or minute. I don't have time to document all of that, and no person should have enough time to be able to read it. This timeline is key because it involves companies that claim to protect people from the kind of attack they fell for.
It's time to stop victim shaming employees. It's time to ask:
January 2022 - Sitel
March 2022 - Okta
March 2022
March 2022
March 2022
April 2022
May 2022 - July 2022
August 2022
August 2022
August 2022 onwards
What is phishing?
My definition of phishing seems to be different to almost everything I’ve read, including?wikipedia. So I felt it was time to write my thoughts down.
Almost every security company I’ve researched defines phishing as?a social engineering technique used to obtain sensitive information such as usernames & passwords and credit card details. PhishTank?only?permits webpages designed to steal usernames and passwords should be included in their URL blocklist. They decline submissions for phishing threats that are associated with malware or ransomware attacks.
I believe phishing is much more.
My definition of phishing
Phishing is the practice of impersonating people and organizations on the Internet
Phishing drives 90% of online fraud, data breaches, identity theft, malware and state-sponsored attacks. It’s not just about the theft of personal information.
Why phishing is not new or sophisticated
TLDR; The phishing-led attacks that we see today were first discovered on the AOL network in 1996. That was?a very long time ago. To put that into perspective, Google wasn't founded until 1998, and most of the Chrome engineers who represent Google across standards bodies today, didn't graduate from college until the 2000s. More here.