The Cure For Phishing May Be More Phishing!
Phishing scams, one of the oldest forms of cyber attacks, continue to threaten internet users worldwide. According to a recent report by the Anti-Phishing Working Group (APWG), there were 1,270,883 phishing attacks in the third quarter of 2022 alone, which they stated as being “a new record and the worst quarter for phishing that APWG has ever observed”.
These scams are designed to trick people into giving away sensitive information such as passwords, credit card details, and other personal data by posing as trustworthy sources such as banks, social media platforms, and government agencies.
With the recent boom in artificial intelligence, phishing campaigns are becoming more sophisticated and harder to detect. Despite the increasing awareness of these scams, people and end users continue to fall victim to them, leading to significant financial losses, business email compromise (BEC) and even identity theft.
But what if the solution to phishing was more phishing? Subjecting people to more controlled phishing scams that promote awareness and build resilience without the harsh consequences of actual phishing attacks could be the key to minimising the success rate of these malicious activities.
Just as Operation Mindfuck and subvertisements used the same form as the things they were warning against, synthetic media could also be used to combat phishing. By creating fake phishing emails or websites, people can learn to spot the signs of a phishing attempt and avoid falling for it in the future. This certainly isn’t a new practice; many organisations today already employ this method of ‘harmless phishing’ under the premise of security awareness training. Your organisation is only as secure as your weakest link.
This is especially important in today's world of infinite misinformation, where traditional methods of combatting cyber attacks are becoming obsolete. Censorship and attempts to quarantine misinformation will not achieve anything, as deceit is a fundamental part of nature. Instead, we need to teach people to see through the lies and be able to identify when they are being targeted by phishing attacks regardless of the platform, email, websites, text messages, etc.
We can educate people on the signs of an actual phishing attempt by subjecting them to more phishing scams in a controlled environment. They can become better equipped to protect themselves against future attacks. This approach can also be applied to other forms of cyber attacks, such as malware and social engineering.
In conclusion, the cure for phishing may just be more phishing in a controlled and educational environment. By using synthetic media to teach people how to identify and avoid phishing attempts, we won’t be able to stop phishing for everyone. However, we will make everyone safer and better prepared when phishing attempts happen.