Skip to main content
Phishing

Social Engineering News: Phishing 2022

By February 23, 2022August 23rd, 2025No Comments

Phishing continues to be one of the biggest cybersecurity threats facing enterprises today. According to the 2021 Data Breach Investigations Report (DBIR), phishing is the top data breach tactic, accounting for 36% (up from 25% last year) of reported breaches. The consequences can be crippling. There may be regulatory fines, loss of company value and reputation, and a disruption of business workflow. And of course, there is also the monetary loss. The FBI’s 2020 Internet Crime Complaint Incident Report notes that companies lost $54,241,075 because of social attacks, including phishing.

What is Phishing?

At Social-Engineer LLC, we define phishing as “the practice of sending emails appearing to be from reputable sources with the goal of influencing or gaining personal information.”
Phishing: Social Engineering News
Image: https://cybernews.com/security/how-phishing-attacks-are-evolving-and-why-you-should-care/

The top 3 types of data compromised in a phishing attack according to the 2021 DBIR are:

    1. Credentials, such as passwords, usernames, and pin numbers;
    2. Medical data, such as treatment information, insurance claims;
    3. Personal data, such as name, address, and email address.

The following news stories show how criminals are successfully carrying out phishing attacks

Attackers steal Microsoft Outlook credentials via Zoom invites

Armorblox detailed a clever phishing attack that targeted a major North American online mortgage brokerage company. The email was titled “[External]Zoom Meetings 11:00 AM Eastern Time [US and Canada]” and the body contained the message, “Your participants have joined you in a meeting.” When the end user clicks on the “Start Meeting” button, they are taken to a spoofed Microsoft Outlook login page where they are asked to enter their email address and password.

Phishing attacks spoof the US Department of Labor (DOL) to steal account credentials

As reported by Inky, these phishing emails invited recipients to submit bids for “ongoing government projects” and claimed to be from a senior DOL employee responsible for procurement.  Each phishing email also had a 3-page PDF attachment. On page 2, recipients were instructed to click on the “BID” button to access the DOL’s procurement portal. However, the BID button was a malicious link that led to a spoofed DOL website. On the fake DOL website victims were instructed to click the “Click here to bid” button and to sign in and bid entering their Microsoft or other business email account.

Multi-phase phishing attack first steals credentials then distributes phishing emails

Attackers begin this multi-phase attack by sending phishing emails to steal credentials. In the next phase, Microsoft reports that the attackers use the stolen credentials to register devices onto the target organization’s corporate network for further phishing attacks.

Phishing attack on Children’s Hospital of The King’s Daughters exposes protected health information (PHI)

Several employees of Children’s Hospital of The King’s Daughters had their email accounts compromised in a phishing attack. As reported by HIPAA Journal, the email accounts contained the following types of protected health information: full name, date of birth, patient account number, health insurance number, and/or other health related information and, for a limited number of individuals, their Social Security number.

Social-Engineer Phishing Service —Test, Educate, and Protect

How can you protect your company from the crippling effects of a successful phishing attack? Social-Engineer’s Phishing Service (SEPS) is a fully managed program that measures and tracks how employees respond to email phishing attacks. The SEPS provides the following:

      • Levelized emails
      • Custom templates
      • Tailored training based on failures
      • Comprehensive reporting
      • Phish notification feature

Employees who understand the threat posed by phishing attacks are less likely to click malicious links and more likely to report suspicious activity. Please contact our team today for a quote.

Security Assessment Case Study
Learn more about the importance of a Social Engineering Risk Assessment.
Security Assessment Case Study
Learn more about the importance of a Social Engineering Risk Assessment.
What Makes Us Different
At Social-Engineer, we pride ourselves on what we do and how we do it. We are a security services provider, focusing on four primary attack vectors. This case study will go through how we can protect your company and what makes us different.
What Makes Us Different
At Social-Engineer, we pride ourselves on what we do and how we do it. We are a security services provider, focusing on four primary attack vectors. This case study will go through how we can protect your company and what makes us different.
Woman vs Machine
Technology is providing new, more innovative ways to enhance our world. Scientists are constantly developing smarter, faster and more intelligent machines, systems and robots. There is no doubt that each of these has evolved beyond their clockwork origins.
Woman vs Machine
Technology is providing new, more innovative ways to enhance our world. Scientists are constantly developing smarter, faster and more intelligent machines, systems and robots. There is no doubt that each of these has evolved beyond their clockwork origins.
Vishing and Phishing Must Be Ongoing to Be Effective
Most companies have a security awareness program in one form or another. If they don’t, it should be on the short list of programs to start as soon as possible. In our experience, many of these programs take the form of computer-based training.
Vishing and Phishing Must Be Ongoing to Be Effective
Most companies have a security awareness program in one form or another. If they don’t, it should be on the short list of programs to start as soon as possible. In our experience, many of these programs take the form of computer-based training.
A Case Study in Vishing
Vishing (voice-based phishing) has been a problem for quite a long time. There are many vendors in the marketplace that offer vishing services. However they tend to use robo-callers or call centers for large volume engagements. If they are using trained humans to make calls, it is likely in very low numbers.
A Case Study in Vishing
Vishing (voice-based phishing) has been a problem for quite a long time. There are many vendors in the marketplace that offer vishing services. However they tend to use robo-callers or call centers for large volume engagements. If they are using trained humans to make calls, it is likely in very low numbers.
Benefits of a Social-Engineering Risk Assessment Engagement
Your company is important. Indeed, the data you hold for your clients or employees is very valuable and attackers seek to capitalize on that data any way they can. This is where a Social Engineering Risk Assessment (SERA) engagement can help uncover possible vulnerability to attackers.
Benefits of a Social-Engineering Risk Assessment Engagement
Your company is important. Indeed, the data you hold for your clients or employees is very valuable and attackers seek to capitalize on that data any way they can. This is where a Social Engineering Risk Assessment (SERA) engagement can help uncover possible vulnerability to attackers.
The Business Value of the Social-Engineer Phishing Service
Cybercriminals are targeting the human element of organizations. Additionally, they are developing techniques to use an organization’s employees as the first point of entry. According to the 2021 Verizon DBIR report, of the 3,841 security breaches reported using social engineering, phishing was the key vector for over 80% of them.
The Business Value of the Social-Engineer Phishing Service
Cybercriminals are targeting the human element of organizations. Additionally, they are developing techniques to use an organization’s employees as the first point of entry. According to the 2021 Verizon DBIR report, of the 3,841 security breaches reported using social engineering, phishing was the key vector for over 80% of them.