ETFOptimize | High-performance ETF-based Investment Strategies

Quantitative strategies, Wall Street-caliber research, and insightful market analysis since 1998.


ETFOptimize | HOME
Close Window

What Is Email Spoofing?

Email spoofing is a specific type of cyber-attack where hackers manipulate and send emails to accounts, making them appear to be from legitimate sources. It falls under the umbrella of phishing or spam because hackers know that people are more likely to open an email if it comes from a trusted source. Occasionally these spoofed emails will ask recipients to provide sensitive data, such as passwords or financial information. Or the email may contain links that install malware on the recipient’s computer if clicked.

Hackers use email spoofing because it is an effective way to get around spam filters and blocked sender lists. By assuming the identity of a trusted sender, they are more likely to be successful in collecting sensitive information.

How Email Spoofing Works

Email spoofing is generally achieved using a Simple Mail Transfer Protocol (SMTP) on a generic email platform. The hacker composes an email in the usual way and then forges fields within the message header and address bars. When the recipient receives the email, it appears to come from the forged address. This works because the SMTP has no inbuilt way of authenticating addresses, and attempts to do so have not been widely adopted.

Hackers generally use addresses that are widely trusted. Spoofed messages will usually encourage recipients to take some action, such as clicking a link to prevent account suspension or changing a compromised password. This allows hackers the chance to harvest sensitive information. Other more sophisticated email spoofing tactics include targeting staff at financial institutions. In many cases, email spoofers will even use branding elements from official websites to make the emails seem more legitimate.

Why Businesses Need to Know About Email Spoofing

It is estimated that more than 3 billion spoofing emails are sent daily, with nine out of ten cyber-attacks starting with an email. Email spoofing is thought to have cost businesses worldwide around $26 billion since 2016. Many spoofing attacks purport to be from senior staff within the organization, which should be of particular concern for businesses due to the high levels of potential risk involved.

How To Tell If an Email Has Been Spoofed

Most legitimate organizations will not ask people to provide sensitive information via email. So, if an email is received asking to change a password or confirm account information, exercising caution is always a good idea. Recipients can open and use the email source code which will contain the original IP of the sender. It is also possible to use the Sender Policy Framework (SPF) included in many email providers’ security products. This authentication protocol may flag emails that have the potential to have been spoofed.

Best Ways to Protect Against Email Spoofing 

Businesses can prevent email spoofing in several ways, including:

  • Email security gateways

These block emails containing suspicious elements or ones that do not meet security protocols put in place by users.

  • Encryption

Businesses can set up encryption keys to ensure messages are only received from valid senders.

  • Anti-malware software

Some software programs can detect and block emails from suspicious senders or identify fraudulent attacks.

  • Better training

Effective security awareness training can help employees exercise caution and recognize suspicious elements. Training can use email spoofing examples and teach effective handling tactics – such as not clicking links or looking for the tell-tale signs of spoofing attacks. Training should ideally be held on a semi-regular basis to keep up to date with the latest spoofing methods and trends.

Contact Information:

Name: Michael Bertini
Email:michael.bertini@iquanti.com
Job Title: Consultant

Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the following
Privacy Policy and Terms Of Service.


 

IntelligentValue Home
Close Window

DISCLAIMER

All content herein is issued solely for informational purposes and is not to be construed as an offer to sell or the solicitation of an offer to buy, nor should it be interpreted as a recommendation to buy, hold or sell (short or otherwise) any security.  All opinions, analyses, and information included herein are based on sources believed to be reliable, but no representation or warranty of any kind, expressed or implied, is made including but not limited to any representation or warranty concerning accuracy, completeness, correctness, timeliness or appropriateness. We undertake no obligation to update such opinions, analysis or information. You should independently verify all information contained on this website. Some information is based on analysis of past performance or hypothetical performance results, which have inherent limitations. We make no representation that any particular equity or strategy will or is likely to achieve profits or losses similar to those shown. Shareholders, employees, writers, contractors, and affiliates associated with ETFOptimize.com may have ownership positions in the securities that are mentioned. If you are not sure if ETFs, algorithmic investing, or a particular investment is right for you, you are urged to consult with a Registered Investment Advisor (RIA). Neither this website nor anyone associated with producing its content are Registered Investment Advisors, and no attempt is made herein to substitute for personalized, professional investment advice. Neither ETFOptimize.com, Global Alpha Investments, Inc., nor its employees, service providers, associates, or affiliates are responsible for any investment losses you may incur as a result of using the information provided herein. Remember that past investment returns may not be indicative of future returns.

Copyright © 1998-2017 ETFOptimize.com, a publication of Optimized Investments, Inc. All rights reserved.