{"id":10814,"date":"2019-05-14T13:55:32","date_gmt":"2019-05-14T17:55:32","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=10814"},"modified":"2019-05-14T14:14:54","modified_gmt":"2019-05-14T18:14:54","slug":"spearphishing-compromises-two-florida-counties-voter-databases","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/spearphishing-compromises-two-florida-counties-voter-databases\/","title":{"rendered":"Spearphishing Compromised two Florida Counties\u2019 Voter Databases in 2016"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Governor Ron DeSantis announced today that Russian hackers accessed\ndatabases in two Florida counties<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">While, at least so far, Russian election interference didn\u2019t rise to the same level in the 2018 US midterm elections as it did in the Presidential race two years earlier \u2013 we are still learning about the breadth of their efforts to disrupt that 2016 election.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Case in point, today Florida Governor Ron DeSantis announced that a pair of Florida counties had their voter databases compromised by Russian hackers before the 2016 US President Elections. The attackers gained access to these databases with spearphishing emails that fooled county officials into clicking a malicious link. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">DeSantis said that no data was altered and that the election results were not compromised, but he wasn\u2019t allowed to disclose the counties by virtue of an agreement with the FBI, which is investigating the matter. They have been notified and are now aware of the matter though.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is of particular interest to us at The SSL Store&#x2122;\nbecause we both reside in Florida \u2013 our offices are in sunny St. Petersburg (in\nPinellas county) \u2013 and we deal with email security and phishing quite a bit. In\nfact, we quite literally just wrote a book on it. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, today we\u2019re going to talk a little bit about\nspearphishing and how you don\u2019t have to be a county election official to be\ntargeted by it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n\n\n<h2 class=\"wp-block-heading\">What is Spearphishing?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Spearphishing is a type of phishing attack that leverages\nsocial engineering to target a specific individual. There\u2019s a specific variant\ncalled whaling, which targets high-level executives. This appears \u2013 with the\nlimited information available \u2013 to be more run-of-the-mill spearphishing where\nthey tried to create a believable scenario where the target would take the\ndesired action \u2013 opening an attachment or, in this case, clicking a link. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Again, without more information it\u2019s difficult to know\nexactly how this all played out. We\u2019re not even sure if DeSantis used the\ncorrect terminology and was actually describing a different variant of phishing\nall together. And it\u2019s not as if there\u2019s a consensus on nomenclature in the\nfirst place.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What we can do is go over some of the more common tactics\nassociated with his kind of phishing. In a true spearphishing scenario the\nattackers often build dossiers of information on the target using publicly\navailable data from social media sites like LinkedIn. This helps them if they\u2019re\ntrying to go a more personal route. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the context of phishing election officials it\u2019s more\nlikely they were focused on less on the individual and more on the role they\nwere targeting, this can be done by mimicking popular brands and companies, or\neven other employees (when high-level employees are imitated this is sometimes\nreferred to as CEO Fraud). The idea is to create a situation that either causes\na sense of urgency and requires immediate action, or \u2013 as the recent data\nindicates \u2013 to play to your vanity and get you to click on something without\nthinking.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"893\" height=\"548\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Emotional-Motivators.png\" alt=\"Top motivators for successful phishing emails\" class=\"wp-image-10815\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Emotional-Motivators.png 893w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Emotional-Motivators-300x184.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Emotional-Motivators-768x471.png 768w\" sizes=\"auto, (max-width: 893px) 100vw, 893px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">There are certain words and phrases, as well as certain flavors\nof email that come up more often, too. Here are some of the most popular from a\nrecent study.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"648\" height=\"241\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Popular-Words-in-Phish.png\" alt=\"\" class=\"wp-image-10817\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Popular-Words-in-Phish.png 648w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Popular-Words-in-Phish-300x112.png 300w\" sizes=\"auto, (max-width: 648px) 100vw, 648px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"909\" height=\"354\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Corporate-Phish.png\" alt=\"Most Successful Corporate Phish\" class=\"wp-image-10816\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Corporate-Phish.png 909w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Corporate-Phish-300x117.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Corporate-Phish-768x299.png 768w\" sizes=\"auto, (max-width: 909px) 100vw, 909px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">How do you fight Spearphishing?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Education is the best tool when it comes to stopping phishing\nand improving email security in general. Technology isn\u2019t what\u2019s being defeated\nwhen you get phished \u2013 people are. So making sure that you train your employees\n\u2013 in addition to implementing the correct safeguards \u2013 is tantamount to a\nstrong security posture.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And the good news is that evidence shows this really does\nwork.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"900\" height=\"525\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2014\/02\/Click-Rate-year.png\" alt=\"Phishing simulation click rates go down each year of training\" class=\"wp-image-10095\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2014\/02\/Click-Rate-year.png 900w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2014\/02\/Click-Rate-year-300x175.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2014\/02\/Click-Rate-year-768x448.png 768w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Over time, and across multiple training campaigns, a recent\nstudy found that employees in the healthcare industry showed decided\nimprovement in identifying phish. <\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"900\" height=\"525\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2014\/02\/Click-Rate-Campaign.png\" alt=\"Phishing click rates go down as employees go through more phishing simulations\" class=\"wp-image-10094\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2014\/02\/Click-Rate-Campaign.png 900w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2014\/02\/Click-Rate-Campaign-300x175.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2014\/02\/Click-Rate-Campaign-768x448.png 768w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">But this is only possible if you take an active approach to\nemail security \u2013 something that many, government organizations included, have\nyet to make a priority. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>We may update this story as more information becomes available.<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"267\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg\" alt=\"Hashed Out by The SSL Store is the voice of record in the SSL\/TLS industry.\" class=\"wp-image-7276\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-300x78.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-768x200.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568.jpg 1559w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Two Florida counties had their voter databases compromised by Russian hackers thanks to a spearphishing email. Find out how your organization can stop spearphishing,<\/p>\n","protected":false},"author":6,"featured_media":10823,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16],"tags":[166,9164],"class_list":["post-10814","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","tag-phishing","tag-spearphishing","post-with-tags"],"views":7574,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Spearphishing-Feature-2.png","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/10814","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=10814"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/10814\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/10823"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=10814"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=10814"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=10814"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}