{"id":348,"date":"2012-11-21T20:34:49","date_gmt":"2012-11-21T20:34:49","guid":{"rendered":"http:\/\/fraudtoday.net\/?p=348"},"modified":"2012-11-21T20:34:49","modified_gmt":"2012-11-21T20:34:49","slug":"case-of-spear-phishing-in-india","status":"publish","type":"post","link":"https:\/\/indiaforensic.com\/certifications\/case-of-spear-phishing-in-india\/","title":{"rendered":"Case of spear phishing in India"},"content":{"rendered":"<p><a href=\"https:\/\/indiaforensic.com\/certifications\/wp-content\/uploads\/2012\/11\/spearphishing.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-thumbnail wp-image-3442\" src=\"https:\/\/indiaforensic.com\/certifications\/wp-content\/uploads\/2012\/11\/spearphishing-300x300.jpg\" alt=\"spear phishing india\" width=\"150\" height=\"150\" \/><\/a>Fraudsters are evolving with the technology. Couple of years ago, Phishing was replaced by Vishing and now SpearPhishing is the new baby on the blocks. Spear Phishing in India is not very common. Phishing was a generic attack without having any information about the victims, Vishing was voice based phishing but the frauds are now getting personal. SpearPhishing attack is committed with a specific person in mind.<\/p>\n<h2>Spear phishing in India<\/h2>\n<p>Certified Forensic Accounting Professionals are emerging as a powerful community, across the world. One such CFAP was engaged by a pharmaceutical company with a request to conduct a routine assessment of its system security. During his analysis, he discovered that some of the client\u2019s PCs were infected by certain malware. This malware was transferring research data to a location which was based out of Indore. Head office of one of the competitor\u2019s of the pharmaceutical company was based in Indore too.<\/p>\n<p>Business faced a cyber attack,\u00a0 when a junior research scientist unwittingly helped infect the PC of a senior scientist. In India, generally the corporate networks are affected by the employees who, though unintentionally, use a company owned computer to visit porn sites. In this case, however, the junior scientist was not even watching any objectionable content but was simply trying to do his job.<\/p>\n<p>The trouble began when he received an email from an apparently known, legitimate source. Attached to the actually phony message was a malicious PDF attachment purporting to be the document of the kind the junior scientist and his supervisor were working to complete a very important research project. Because neither its apparent source nor content appeared suspicious, the junior scientist opened the attachment. When its contents turned out to be unfamiliar, he sought guidance by forwarding the message to the senior scientist who also opened the attachment.<\/p>\n<p>The attachment apparently came from some vendor who was part of the research work too. Junior scientist had no way of knowing that his email account was compromised. When the attachment was opened, it executed malware that infected their PCs and spread to sensitive system modules that the senior scientist had access to. Once the hackers were able to scan through the entire system they could simply take out the information they wanted to access. Some very important research \u00a0and the business plans. To get the valuable information competitor never entered the premises of the victim pharmaceutical company. The total damage was calculated at Rs. 7.6 crores. In various countries the Certified Forensic Accounting Professionals are called in to assess the damages caused to the companieI because of the frauds.<\/p>\n<p>This was an attack that involved advance planning and research that had nothing to do with technology. These hackers were skilled\u00a0<i>spearphishers<\/i>, whose precisely aimed attack sought a particular type of information accessible only to certain senior staff members of this pharmaceutical company.<\/p>\n<p>The hackers were anxious to not draw attention of their attempt, so they sent only one message to one carefully selected user \u2014 the junior Scientist. How did they know to whom to send it? These fraudsters used a very simple technique. When the competitor company hosted a conference related to the subject, an email was sent to the senior scientist. It was an invite to be a speaker. The mail reached him when senior scientist was on vacation and his email sent an auto-responder email. This email also requested to contact the junior scientist in case of emergency. Every fraudster is not however, as lucky as this. In most of the cases of spear phishing they have to do extensive research and reconnaissance \u2014 much of it offline \u2014 on who worked with whom in the target firms and each employee\u2019s nature of work.<\/p>\n<p>Sometimes, hackers explore the firm\u2019s email address-naming convention. So, when the technological part of their scheme \u2014 a virus \u2013 gets ready , the hackers know to whom to send it.<\/p>\n<p>Certified Forensic Accounting Professionals are investigating some of the most challenging assignments of investigation of the frauds and aspirants can get into the right network of professionals by obtaining the most valuable certification in India.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fraudsters are evolving with the technology. Couple of years ago, Phishing was replaced by Vishing and now SpearPhishing is the new baby on the blocks. Spear Phishing in India is not very common. Phishing was a generic attack without having any information about the victims, Vishing was voice based phishing but the frauds are now [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3442,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10,45],"tags":[266,297],"class_list":["post-348","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cfap-experiences","category-internet-banking-frauds","tag-mayur-joshi","tag-phishing"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Case of spear phishing in India<\/title>\n<meta name=\"description\" content=\"Case of spear phishing in India investigated by a Certified Forensic Accounting Professional\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/indiaforensic.com\/certifications\/case-of-spear-phishing-in-india\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Case of spear phishing in India\" \/>\n<meta property=\"og:description\" content=\"Case of spear phishing in India investigated by a Certified Forensic Accounting Professional\" \/>\n<meta property=\"og:url\" content=\"https:\/\/indiaforensic.com\/certifications\/case-of-spear-phishing-in-india\/\" \/>\n<meta property=\"og:site_name\" content=\"Indiaforensic\" \/>\n<meta property=\"article:published_time\" content=\"2012-11-21T20:34:49+00:00\" \/>\n<meta name=\"author\" content=\"Mayur Joshi\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@AtIndiaforensic\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Mayur Joshi\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/case-of-spear-phishing-in-india\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/case-of-spear-phishing-in-india\\\/\"},\"author\":{\"name\":\"Mayur Joshi\",\"@id\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/#\\\/schema\\\/person\\\/f6e7b567c8a01699b2a47a6d4d29ca07\"},\"headline\":\"Case of spear phishing in India\",\"datePublished\":\"2012-11-21T20:34:49+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/case-of-spear-phishing-in-india\\\/\"},\"wordCount\":690,\"publisher\":{\"@id\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/#\\\/schema\\\/person\\\/c98570a8400cc0abd4339dedcb280534\"},\"image\":{\"@id\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/case-of-spear-phishing-in-india\\\/#primaryimage\"},\"thumbnailUrl\":\"\",\"keywords\":[\"Mayur Joshi\",\"Phishing\"],\"articleSection\":[\"CFAP Experiences\",\"Internet Banking Frauds\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/case-of-spear-phishing-in-india\\\/\",\"url\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/case-of-spear-phishing-in-india\\\/\",\"name\":\"Case of spear phishing in India\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/case-of-spear-phishing-in-india\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/case-of-spear-phishing-in-india\\\/#primaryimage\"},\"thumbnailUrl\":\"\",\"datePublished\":\"2012-11-21T20:34:49+00:00\",\"description\":\"Case of spear phishing in India investigated by a Certified Forensic Accounting Professional\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/case-of-spear-phishing-in-india\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/case-of-spear-phishing-in-india\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/case-of-spear-phishing-in-india\\\/#primaryimage\",\"url\":\"\",\"contentUrl\":\"\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/case-of-spear-phishing-in-india\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Media\",\"item\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Case of spear phishing in India\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/#website\",\"url\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/\",\"name\":\"Indiaforensic\",\"description\":\"Anti Money Laundering in India\",\"publisher\":{\"@id\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/#\\\/schema\\\/person\\\/c98570a8400cc0abd4339dedcb280534\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/indiaforensic.com\\\/certifications\\\/#\\\/schema\\\/person\\\/f6e7b567c8a01699b2a47a6d4d29ca07\",\"name\":\"Mayur Joshi\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f3d06a924c534864b02051de157737854f467e09e724d407e6485bf10b472293?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f3d06a924c534864b02051de157737854f467e09e724d407e6485bf10b472293?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f3d06a924c534864b02051de157737854f467e09e724d407e6485bf10b472293?s=96&d=mm&r=g\",\"caption\":\"Mayur Joshi\"},\"logo\":{\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f3d06a924c534864b02051de157737854f467e09e724d407e6485bf10b472293?s=96&d=mm&r=g\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Case of spear phishing in India","description":"Case of spear phishing in India investigated by a Certified Forensic Accounting Professional","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/indiaforensic.com\/certifications\/case-of-spear-phishing-in-india\/","og_locale":"en_US","og_type":"article","og_title":"Case of spear phishing in India","og_description":"Case of spear phishing in India investigated by a Certified Forensic Accounting Professional","og_url":"https:\/\/indiaforensic.com\/certifications\/case-of-spear-phishing-in-india\/","og_site_name":"Indiaforensic","article_published_time":"2012-11-21T20:34:49+00:00","author":"Mayur Joshi","twitter_card":"summary_large_image","twitter_site":"@AtIndiaforensic","twitter_misc":{"Written by":"Mayur Joshi","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/indiaforensic.com\/certifications\/case-of-spear-phishing-in-india\/#article","isPartOf":{"@id":"https:\/\/indiaforensic.com\/certifications\/case-of-spear-phishing-in-india\/"},"author":{"name":"Mayur Joshi","@id":"https:\/\/indiaforensic.com\/certifications\/#\/schema\/person\/f6e7b567c8a01699b2a47a6d4d29ca07"},"headline":"Case of spear phishing in India","datePublished":"2012-11-21T20:34:49+00:00","mainEntityOfPage":{"@id":"https:\/\/indiaforensic.com\/certifications\/case-of-spear-phishing-in-india\/"},"wordCount":690,"publisher":{"@id":"https:\/\/indiaforensic.com\/certifications\/#\/schema\/person\/c98570a8400cc0abd4339dedcb280534"},"image":{"@id":"https:\/\/indiaforensic.com\/certifications\/case-of-spear-phishing-in-india\/#primaryimage"},"thumbnailUrl":"","keywords":["Mayur Joshi","Phishing"],"articleSection":["CFAP Experiences","Internet Banking Frauds"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/indiaforensic.com\/certifications\/case-of-spear-phishing-in-india\/","url":"https:\/\/indiaforensic.com\/certifications\/case-of-spear-phishing-in-india\/","name":"Case of spear phishing in India","isPartOf":{"@id":"https:\/\/indiaforensic.com\/certifications\/#website"},"primaryImageOfPage":{"@id":"https:\/\/indiaforensic.com\/certifications\/case-of-spear-phishing-in-india\/#primaryimage"},"image":{"@id":"https:\/\/indiaforensic.com\/certifications\/case-of-spear-phishing-in-india\/#primaryimage"},"thumbnailUrl":"","datePublished":"2012-11-21T20:34:49+00:00","description":"Case of spear phishing in India investigated by a Certified Forensic Accounting Professional","breadcrumb":{"@id":"https:\/\/indiaforensic.com\/certifications\/case-of-spear-phishing-in-india\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/indiaforensic.com\/certifications\/case-of-spear-phishing-in-india\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/indiaforensic.com\/certifications\/case-of-spear-phishing-in-india\/#primaryimage","url":"","contentUrl":""},{"@type":"BreadcrumbList","@id":"https:\/\/indiaforensic.com\/certifications\/case-of-spear-phishing-in-india\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Media","item":"https:\/\/indiaforensic.com\/certifications\/"},{"@type":"ListItem","position":2,"name":"Case of spear phishing in India"}]},{"@type":"WebSite","@id":"https:\/\/indiaforensic.com\/certifications\/#website","url":"https:\/\/indiaforensic.com\/certifications\/","name":"Indiaforensic","description":"Anti Money Laundering in India","publisher":{"@id":"https:\/\/indiaforensic.com\/certifications\/#\/schema\/person\/c98570a8400cc0abd4339dedcb280534"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/indiaforensic.com\/certifications\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/indiaforensic.com\/certifications\/#\/schema\/person\/f6e7b567c8a01699b2a47a6d4d29ca07","name":"Mayur Joshi","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f3d06a924c534864b02051de157737854f467e09e724d407e6485bf10b472293?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f3d06a924c534864b02051de157737854f467e09e724d407e6485bf10b472293?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f3d06a924c534864b02051de157737854f467e09e724d407e6485bf10b472293?s=96&d=mm&r=g","caption":"Mayur Joshi"},"logo":{"@id":"https:\/\/secure.gravatar.com\/avatar\/f3d06a924c534864b02051de157737854f467e09e724d407e6485bf10b472293?s=96&d=mm&r=g"}}]}},"_links":{"self":[{"href":"https:\/\/indiaforensic.com\/certifications\/wp-json\/wp\/v2\/posts\/348","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/indiaforensic.com\/certifications\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/indiaforensic.com\/certifications\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/indiaforensic.com\/certifications\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/indiaforensic.com\/certifications\/wp-json\/wp\/v2\/comments?post=348"}],"version-history":[{"count":0,"href":"https:\/\/indiaforensic.com\/certifications\/wp-json\/wp\/v2\/posts\/348\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/indiaforensic.com\/certifications\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/indiaforensic.com\/certifications\/wp-json\/wp\/v2\/media?parent=348"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/indiaforensic.com\/certifications\/wp-json\/wp\/v2\/categories?post=348"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/indiaforensic.com\/certifications\/wp-json\/wp\/v2\/tags?post=348"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}