Email: how spam, phishing and BEC continue to threaten your inbox (and what you can do about it)
As time went by, and although at the beginning most people did not pay much attention to the issue of security, or rather**“cybersecurity**”, it became clear that email was not free of problems: *malware, phishing, spear-phishing, *BEC(Business Email Compromise) and spam (also called “junk mail”).
In case you didn’t know, spam accounts for almost 85% of all emails sent worldwide.
Thanks to the GDPR*(General Data Protection Regulation*), many companies that used to bombard us with unwanted advertising have had to reduce, or even stop, their activity for fear of being penalized.
However, spam that comes from illicit or disreputable sources is not stopped by regulations, but by anti-spam techniques that help minimize its reach.
Where do they get your email address?
Many people will ask, “Where do they get my email address to send me so much advertising from so many sites and for topics I’m not even interested in?”
The answer lies in several scenarios:
- Sometimes, your email is included in messages addressed to hundreds of people (or viral emails) without placing it in the Bcc (blind carbon copy) field.
- Certain companies with which you had some kind of service or contact sell their customer database to third parties -although this happens less nowadays-.
- Spammers collect millions of addresses by obtaining them from social networks, websites or forums, using tools known as “spiders” or web scraping that automatically scan the web for emails and phone numbers.
- There are also information leaks after security breaches in which our email and other private data are exposed and accessible to be used against us.
Large leaks fueling the problem
As an example, we can mention the huge leak that occurred in April 2021 that affected Facebook users, with 533 million records of all kinds.
Among the leaked data were: full name, telephone, city, email and even job title.
A couple of weeks later, something similar happened with 500 million LinkedIn accounts, exposing information such as: user ID, full name, phone numbers, emails, gender, links to other profiles and social networks, work history, etc.
Given that LinkedIn is a platform where users go so far as to post even their resume online, we can imagine how much valuable data was exposed.
Both leaks are just a couple of examples of the numerous leaks that occur every year on different platforms.
Not all of these leaks, which end up in the public eye in Internet repositories, are due to hacks but to the massive collection of publicly exposed data using * web scraping techniques*.
As these types of leaks are beyond our control, it is important to always keep in mind that, sooner or later, one or more of the companies to which we entrust our data will be compromised, so it is advisable to prevent this dangerous and inevitable situation by taking measures such as:
-
Use strong passwords -more than 17 characters composed of uppercase letters, lowercase letters, numbers and special characters-, and that are unique -never repeat them, ideally a different password for each service orplatform-.
-
(this can only be achieved by using password managers such as Bitwarden or KeePass).
-
Enabling two-factor authentication (2FA)
-
(this is the best measure, no doubt).
-
Be careful when sharing your address in public forums or networks.
-
(in a future post I will show you how you can even create email aliases so that you have a different email for each platform, so it will be easier to identify which platform has exposed your data if you start receiving spam through their email).
-
Use anti-spam filters
-
(in case cybercriminals start using them against you).
-
Regularly review the privacy settings on the online services you use.
It is extremely important to protect emails as much as possible because, if it is stolen, attackers will find it very easy to steal other accounts after resetting the password that will be sent to our compromised email.
Using a weak password and reusing it across multiple services is the dumbest thing you can do. Hackers will thank you for it, that’s for sure.
Keeping the inbox clean
Keeping the inbox clean involves following a certain discipline, for example, not subscribing to newsletters (that is why this blog does not support this type of subscription, if you want to follow us, you can do it through RR. SS. from where you also receive notifications of new publications).
Make sure to uncheck this option -which is sometimes activated by default-, and do not provide your email address to all those businesses, even those in your neighborhood, who think they have the right to ask for it like someone who asks for the time.
The latter is really outrageous: no matter if you join a gym, go to the masseur or have your car serviced, they always want your email address.
And it is not to establish communication with you, but to send you constant advertising or sell it to third parties.
When you are asked for your email address in one of these physical stores, refuse!
They will tell you that this information is mandatory because it is required by their registration form for new customers. But that shouldn’t worry you: it’s not your fault that someone decided to mark it as “mandatory” just because you wanted to get a massage.
So just don’t give it if you don’t think it’s necessary. Chances are they don’t really need it to provide you with good service… unless you don’t mind receiving constant promotions and messages about their products afterwards.
And if you decide to share it, you can only pray that their database is not hacked and your data -along with many others- does not end up exposed on the Internet.
Beware of the “Unsubscribe” link trap.
Although most of these sites offer the possibility of “unsubscribing” through a link, this carries several risks:
- Confirmation of active account: If you want to unsubscribe, you have to click on a link that usually says Unsubscribe or “Unsubscribe”. Clicking on that supposed unsubscribe link may not cancel anything and, in reality, only confirms that the email address is still in use by someone. In addition, a clever attacker could send spam to encourage boredom and, at some point, cause the person to resort to that unsubscribe link by clicking on a malicious link.
Give it a try!*Open a new email account and do not use it for anything yet. Wait until you receive spam on one of your frequent accounts and then click on the “Unsubscribe” link. Sometimes it will ask you to enter the email address you want to unsubscribe from. If instead of entering the email address you received the spam to, enter this new “virgin” address that you have never used yet, you will see how, in a few days, you will also start receiving spam through the new address. 2. Forcing you to log in. Some “companies” do not even allow you to unsubscribe with a simple click, but force you to “log in”. Beware when this happens, as this could be a phishing technique used by an attacker who wants to steal your credentials. 3. Non-compliance with the GDPR. It may happen that, even if you click on the unsubscribe link, the advertisement still arrives. In such a case, the only option left is to contact the company directly or to report the breach of the GDPR for unwanted advertising.
Robinson List: a partial shield
Although it does not always work - or rather, it only works with reputable companies - there is the possibility of registering telephone numbers, emails and even physical addresses on the so-called Robinson List.
If, after registering, you continue to receive commercial communications, it is most likely a scam.
In any case, it is sufficient to mention that you are on the Robinson List and that you are going to report it for the call or email to stop immediately.
You can join the Robinson List here.
Poor email management, especially in businesses, can result in significant productivity loss due to the time spent each day cleaning out the inbox.
In addition, corporate resources such as bandwidth, server performance and maintenance costs are consumed.
Phishing and spear-phishing: the favorite means of entry
For an attacker, the easiest way to hack a person is to send an email containing malicious Microsoft Office documents with macros, or a link that redirects to a fraudulent page to download malware.
The mail is also used to collect data before launching a spear-phishing campaign.
For example, by looking at the autoresponders that many employees put in their email when they go on vacation, you can find out who is out of the office, how long they will be away, what their email signature footer looks like (to spoof it) or how much spam filtering the organization uses to hone in on upcoming malicious emails.
The value of your email to cybercriminals
Hackers know very well that, with someone else’s email, you can do a lot of things.
A cybercriminal could:
- Spamming or extorting third parties from your account.
- Placing orders for material prohibited on the Dark Web.
- Access other platforms where this email is a means of password recovery and, from there, impersonate the legitimate user.
Proving later to the social network that the stolen profile is yours is not easy; it often involves sending original documents and even reporting it to the police in order to be cleared of any crime the attacker might commit with your profile.
Data breaches and 2FA as a lifesaver
As I mentioned earlier, attackers have other ways to get our credentials without hacking us directly.
If an online service is breached, the criminal could get hold of the user database and, therefore, our username and password.