{"id":3418,"date":"2017-01-25T00:01:51","date_gmt":"2017-01-25T05:01:51","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=3418"},"modified":"2017-07-08T12:54:20","modified_gmt":"2017-07-08T16:54:20","slug":"2017-year-of-the-phish","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/2017-year-of-the-phish\/","title":{"rendered":"Here&#8217;s Why 2017 Will be the Year of the Phish"},"content":{"rendered":"<h2>Phishing attacks will become more prevalent than ever in 2017!<\/h2>\n<p>January 28<sup>th<\/sup> marks the Chinese New Year. It will be another &#8216;Year of the Rooster&#8217; per the traditional Chinese lunisolar calendar. Here\u2019s wishing everyone a Happy Chinese New Year!<\/p>\n<p>Respectfully, we at The SSL Store\u2122 have decided to dub 2017 as \u2018The Year of the Phish.\u2019<\/p>\n<p>That\u2019s because with all the industry changes that this year has in store, along with the rapid proliferation of free DV SSL, phishing attacks are going to increase exponentially in the coming months.<\/p>\n<p>So let\u2019s talk about phishing\u2014what it is and why it\u2019s about to become a much bigger problem. Then we\u2019ll talk about ways to protect yourself and your business.<\/p>\n<h2>What is Phishing?<\/h2>\n<p><a href=\"https:\/\/www.thesslstore.com\/blog\/gone-phishing\/\">Vince has discussed phishing in previous blog posts<\/a>. But if you\u2019re just looking for the abridged version, here\u2019s a quick summary:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3420\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Phishing.png\" alt=\"year of the phish, phishing, 2017\" width=\"2750\" height=\"954\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Phishing.png 2750w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Phishing-300x104.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Phishing-768x266.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Phishing-1024x355.png 1024w\" sizes=\"auto, (max-width: 2750px) 100vw, 2750px\" \/><\/p>\n<p>As the definition states, phishing is an attempt to obtain sensitive information such as usernames, passwords, and credit card details, often for malicious reasons, by disguising as a trustworthy entity. Many times you see phishing defined in a way that makes it seem like the threat is entirely email-based.<\/p>\n<p>This is inaccurate.<\/p>\n<p>While many phishing attacks do involve the use of email, the practice itself is much more complicated and oftentimes involves the creation of fake websites, fake social accounts and lots of <strong>social engineering<\/strong>. Without going too deep into the weeds, social engineering involves creating a believable scenario by which to deceive someone into divulging sensitive or personal information.<\/p>\n<p>So now let\u2019s look at how it all fits together.<\/p>\n<h2>How a Phishing Attack Works<\/h2>\n<p>As we\u2019ve covered, the whole point of phishing is to trick someone into handing over desirable information \u2013 personal info, banking data, login credentials \u2013 that can then be used for personal gain.<\/p>\n<p>But, there are two kinds of phishing. There\u2019s the type where a cybercriminal attacks with a specific outcome in mind. This is called <strong>spear-phishing<\/strong> and it typically affects larger companies or organizations (though it can still be used against SMBs and private citizens as well). If a group of cybercriminals were to attack a specific company for the purpose of gaining access to its internal network, that would be an example of spear-phishing.<\/p>\n<p>[su_pullquote]&#8221;We\u2019ve come a long way since those Nigerian Prince emails.&#8221;[\/su_pullquote]<\/p>\n<p>Then there\u2019s the type of phishing where cybercriminals are just looking to steal as much information as possible, from as many people as possible. It\u2019s not unlike when you cast a net off a boat while fishing in real life, you\u2019re just looking to pull up whatever the net grabs. There really is no agreed-upon name for this type of phishing, but it\u2019s the variety which is about to see the greatest increase in the next year.<\/p>\n<p>Let\u2019s look at an example of how a well-executed phishing attack might work.<\/p>\n<p>It starts with the cybercriminal contriving a way to contact you that seems believable enough to get you to take the desired action. This is the social engineering element at work and cybercriminals have gotten extremely sophisticated in the ways that they try to trick you. If it\u2019s a spear-phishing attack they could attempt to impersonate your boss or co-worker via email or a messenger service. If the cybercriminals are trying to cast a wider net, they may disguise themselves as an entity, such as a company or organization, that is widely trusted. We\u2019ve come a long way since those Nigerian Prince emails. Nowadays, a phishing email may look more like this:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3421\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Podesta.png\" alt=\"year of the phish, phishing, 2007\" width=\"975\" height=\"839\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Podesta.png 975w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Podesta-300x258.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Podesta-768x661.png 768w\" sizes=\"auto, (max-width: 975px) 100vw, 975px\" \/><\/p>\n<p>This is a screenshot of the email that was used to <a href=\"https:\/\/www.thesslstore.com\/blog\/dnc-hacking-scandal-happened-typo\/\">successfully phish John Podesta<\/a>, the chairman of Hillary Clinton\u2019s presidential campaign. It looks authentic. It worked. And keep in mind, the first contact is not limited to emails, it could come in any number of other forms.<\/p>\n<p>Usually, the first contact isn\u2019t what steals the information, though. It can be, but typically it includes a link to a website that is designed to trick you. Once again, cybercriminals have gotten very sophisticated and are capable of creating fake websites that look like carbon copies of the real thing.<\/p>\n<p>Here\u2019s a real example of a phishing website, in this case, the cybercriminals are attempting to trick you into believing they\u2019re PayPal:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3422\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170123_8.png\" alt=\"year of the phish, phishing, 2007\" width=\"1380\" height=\"933\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170123_8.png 1380w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170123_8-300x203.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170123_8-768x519.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170123_8-1024x692.png 1024w\" sizes=\"auto, (max-width: 1380px) 100vw, 1380px\" \/><\/p>\n<p>And here\u2019s what the real PayPal login screen looks like:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3423\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_11.png\" alt=\"year of the phish, phishing, 2007\" width=\"1352\" height=\"905\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_11.png 1352w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_11-300x200.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_11-768x514.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_11-1024x685.png 1024w\" sizes=\"auto, (max-width: 1352px) 100vw, 1352px\" \/><\/p>\n<p>Could you tell the difference? If you know about Extended Validation SSL and the green address bar, then maybe you could. But that\u2019s assuming that you remember PayPal even has EV SSL in the first place. If you don\u2019t, you\u2019ll notice the fake website does have encryption.<\/p>\n<p>By the point this screenshot was taken, Google had flagged the site as malicious and was issuing an interstitial warning as well as marking the site &#8220;Dangerous&#8221; in Chrome&#8217;s address bar.<\/p>\n<p><strong>But here\u2019s the problem. <\/strong>Google didn\u2019t catch that website right away. That means that for a period of time \u2013 in this case a few days \u2013 people came to this fake website, saw it was being served over HTTPS and had a green padlock, assumed it was safe\u00a0and had their information stolen.<\/p>\n<p>Here\u2019s a breakdown of the traffic that went to this website, courtesy of bit.ly:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3424\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_10.png\" alt=\"year of the phish, phishing, 2007\" width=\"1243\" height=\"558\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_10.png 1243w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_10-300x135.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_10-768x345.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_10-1024x460.png 1024w\" sizes=\"auto, (max-width: 1243px) 100vw, 1243px\" \/><\/p>\n<p>When we say that cybercriminals cast a wide net when phishing this way\u2014we mean it. These sites are a dime a dozen (more on that later). It\u2019s now easier than ever to slap a Domain Validated SSL Certificate on them and make them appear safe (we&#8217;ll get to that later too). And then, it\u2019s just a matter of how many people they can dupe before Google flags the domain and they have to move on to the next one. This one got at least 180 clicks, and that&#8217;s just from one shortened link. There could be dozens of others.<\/p>\n<p>Now let\u2019s look at why phishing attacks are about to increase exponentially.<\/p>\n<h2>The Browser Community is Mandating Encryption<\/h2>\n<p>This is a good thing, right? Of course! In 2017, the browser community, led by Google and Mozilla, will <a href=\"https:\/\/www.thesslstore.com\/blog\/browser-community-pushing-towards-https\/\">make a number of moves that all but mandate SSL encryption<\/a>. Now, Google isn\u2019t going to put a gun to anyone\u2019s head and force them to migrate to HTTPS, but it will penalize websites that don\u2019t encrypt in a severe enough way that it will tip the scales of competitive balance and put them at a severe disadvantage.<\/p>\n<p>Here are some of the ways the browsers are pushing you to encrypt:<\/p>\n<ul>\n<li>Advanced browser features are exclusive to sites served over HTTPS<\/li>\n<li>Only encrypted websites can use HTTP\/2<\/li>\n<li>Pages served over HTTPS receive up to a 5% SEO boost<\/li>\n<li>Emails sent from unencrypted servers will be flagged<\/li>\n<li><strong>Websites served over unencrypted HTTP will be marked \u201cNot Secure\u201d<\/strong><strong>\u00a0<\/strong><\/li>\n<\/ul>\n<p>It\u2019s that last bullet-point, that unencrypted websites will be marked \u201cNot Secure,\u201d that is going to be the most disruptive. That\u2019s what\u2019s going to more or less force a lot of site-owners to purchase SSL.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-3425\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Quick_Note-300x245.png\" alt=\"year of the phish, phishing, 2007\" width=\"300\" height=\"245\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Quick_Note-300x245.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Quick_Note-768x627.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Quick_Note.png 1005w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>As you could probably imagine, having a browser drop \u201cNot Secure\u201d next to your URL in the address bar is hardly the best way for a website to ingratiate itself to its visitors. For any e-commerce website, that kind of negative visual indicator is inevitably going to hurt the bottom line and ultimately the health of the business.<\/p>\n<p>In this day and age, where people are hyper-aware of online threats and ultra-vigilant about avoiding them, having Google declare your site \u201cNot Secure\u201d is akin to a death sentence.<\/p>\n<p>Here\u2019s what Google\u2019s \u201cNot Secure\u201d indicator looks:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-3428 size-full\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Not_Secure_URL-Bar.png\" alt=\"year of the phish, phishing, 2007\" width=\"3270\" height=\"452\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Not_Secure_URL-Bar.png 3270w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Not_Secure_URL-Bar-300x41.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Not_Secure_URL-Bar-768x106.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Not_Secure_URL-Bar-1024x142.png 1024w\" sizes=\"auto, (max-width: 3270px) 100vw, 3270px\" \/><\/p>\n<p>In a few more updates, that indicator will turn red. Mozilla has already announced plans to make similar changes to its security indicators in Firefox, and it&#8217;s likely that Apple\u2019s Safari and Microsoft\u2019s Edge browsers will also follow suit.<\/p>\n<p><strong>So here\u2019s the million dollar question<\/strong>: why would this contribute to an increase in phishing?<\/p>\n<p>We\u2019ll get to that in a moment, but first, we need to discuss the other way the browsers\u2019 security indicators are changing.<\/p>\n<h2>Sites Served Over HTTPS Will Be Marked \u201cSecure\u201d<\/h2>\n<p>On the opposite side of the \u201cNot Secure\u201d indicator, will be the \u201cSecure\u201d label that the browsers will place on sites with encryption. The \u201cSecure\u201d indicator will look like this:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-3429 size-full\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Secure_URL-Bar.png\" alt=\"year of the phish, phishing, 2007\" width=\"3270\" height=\"453\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Secure_URL-Bar.png 3270w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Secure_URL-Bar-300x42.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Secure_URL-Bar-768x106.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Secure_URL-Bar-1024x142.png 1024w\" sizes=\"auto, (max-width: 3270px) 100vw, 3270px\" \/><\/p>\n<p>The logic behind this change is debatable because this indicator could actually create a lot of problems. That\u2019s because people tend to associate the word \u201csecure\u201d with safety. And safety is not what the \u201cSecure\u201d indicator is supposed to connote. In the mind of the browser community, it simply indicates that your connection with this site is secure \u2013 that it is encrypted and nobody can eavesdrop on it \u2013 not that a website is indeed safe.<\/p>\n<p>[su_pullquote align=&#8221;right&#8221;]&#8221;But, what the indicator intends to communicate and how it is perceived differ wildly.&#8221;[\/su_pullquote]<\/p>\n<p>But, what the indicator <a href=\"https:\/\/www.thesslstore.com\/blog\/google-chrome-security-indicators\/\">intends to communicate and how it is perceived differ wildly<\/a>. The vast majority of people don\u2019t know to click the security indicator and look at the SSL certificate details, they will simply see the word \u201cSecure\u201d and make the risky assumption that they\u2019re safe. Now, let\u2019s go back to the previous point. More sites than ever will be encrypted, and all of those encrypted sites will be labeled \u201cSecure\u201d by the browsers. This is going to desensitize a lot of people to potential threats.<\/p>\n<p>When every site says either \u201cSecure\u201d or \u201cNot Secure,\u201d many people will function by a simple binary. Sites are either \u201cSecure\u201d and by extension safe, or \u201cNot Secure.\u201d It becomes a quick eye check of the security indicator and then it\u2019s business as usual.<\/p>\n<p>This is dangerous, because it\u2019s now easier than ever to obtain a DV SSL certificate.<\/p>\n<h2>Cybercriminals Encrypt Too<\/h2>\n<p>Universal encryption is a truly noble initiative, but some of the free SSL services that the initiative has given birth to are creating some unintended outcomes. One of which, is that cybercriminals can now make their phishing websites look even more convincing by adding Domain Validated SSL encryption and turning on the visual indicators that come along with them.<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\">\n<p dir=\"ltr\" lang=\"en\">I&#8217;m heartened to see a huge increase in adoption of HTTPS by phishermen. <a href=\"https:\/\/t.co\/DEiAUTDlAA\">pic.twitter.com\/DEiAUTDlAA<\/a><\/p>\n<p>\u2014 Eric Lawrence (@ericlaw) <a href=\"https:\/\/twitter.com\/ericlaw\/status\/823646414412673033\">January 23, 2017<\/a><\/p><\/blockquote>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Or to put it another way, it\u2019s now easier than ever for cybercriminals to get their malicious websites labeled \u201cSecure.\u201d Then it\u2019s just a matter of how long they can phish before Google catches their site and labels it as malicious. And as we established earlier, that can take days\u2014tricking hundreds of people in the meantime.<\/p>\n<p>Here\u2019s an example. The CA <strong>Let\u2019s Encrypt<\/strong> offers free, DV SSL Certificates. Now, this isn&#8217;t meant to pick on Let&#8217;s Encrypt, it&#8217;s a non-profit organization that relies entirely on donations. Its ability to implement security mechanisms to protect against issuing to negative actors is extremely limited, as such it only checks on the Google blacklist before issuing.<\/p>\n<p>That means any site that isn\u2019t blacklisted by Google can get SSL from Let\u2019s Encrypt.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-3430 size-full\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_13.png\" alt=\"year of the phish, phishing, 2007\" width=\"1352\" height=\"905\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_13.png 1352w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_13-300x200.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_13-768x514.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_13-1024x685.png 1024w\" sizes=\"auto, (max-width: 1352px) 100vw, 1352px\" \/><\/p>\n<p>According to Censys.io, as of January 24, 2017 Let\u2019s Encrypt had issued 792 certificates to websites with the word \u201cPayPal\u201d included in the domain name. <a href=\"https:\/\/www.thesslstore.com\/blog\/lets-encrypt-phishing\/\">A deeper dive into the numbers showed that it was actually closer to 15,000<\/a>. That\u2019s potentially <strong>15,000<\/strong><strong>\u00a0fake PayPal sites<\/strong> that are labeled \u201cSecure\u201d just waiting to phish people until Google finally catches them.<\/p>\n<p>And as you saw earlier, unless you remember that the real PayPal has EV SSL \u2013 and the green address bar that comes with it \u2013 or you know to click and look at the SSL certificate information, it would be pretty easy to get fooled by any one of those 792 sites.<\/p>\n<h2>So Let\u2019s Tie This All Together<\/h2>\n<p>So how does this all tie together? It\u2019s a perfect storm, really. The browsers are enacting changes that are aimed at motivating websites \u2013 all websites \u2013 to get SSL and migrate to HTTPS. Unfortunately, the creation of the \u201cSecure\u201d visual indicator will lull people into a false sense of safety\u2014seeing \u201cSecure\u201d next to the vast majority of websites will create a mindset in many people that as long as they see that green \u201cSecure\u201d indicator, they\u2019re safe.<\/p>\n<p>Couple that with the fact that cybercriminals have easy access to DV SSL, and that their malicious sites will now feature a \u201cSecure\u201d indicator and you have the ideal climate for phishing.<\/p>\n<p>2017 will be the year of the Phish.<\/p>\n<p>So, how do you stay safe and protect yourself?<\/p>\n<h2>How to Keep Yourself Safe<\/h2>\n<p>As an individual, there are certain steps you can take to protect yourself from phishing. We\u2019ll start with the obvious stuff that you\u2019ve probably heard millions of times. Things like, don\u2019t open email attachments from unknown senders and don\u2019t click on suspicious links. Some cybercriminals are uninspired and happy to stick to the tired old staples\u2014Nigerian princes, lost relatives and frozen bank accounts.<\/p>\n<p>But most cybercriminals have evolved beyond that. As we discussed, they know how to disguise their attempts to make them look like they are from legitimate, trustworthy sources.<\/p>\n<p>That\u2019s why\u00a0you need to be ever-vigilant\u2014even when everything seems like it checks out OK. Here are three tips that you should always practice to keep you safe from phishing on the internet:<\/p>\n<p><strong>Check the URL<\/strong><\/p>\n<p>Before you ever click any link, whether it\u2019s from an email or located on a web page, make sure to inspect the URL.<\/p>\n<p>Here\u2019s the URL from the PayPal phishing site we discussed earlier:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3431\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_17.png\" alt=\"year of the phish, phishing, 2007\" width=\"702\" height=\"100\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_17.png 702w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_17-300x43.png 300w\" sizes=\"auto, (max-width: 702px) 100vw, 702px\" \/><\/p>\n<p>In this case, PayPal is a second-level sub-domain. That\u2019s a dead giveaway. The main domain is the name that appears right before the .com. In this case, the actual website you\u2019re at is \u201cgetbill-service.com\u201d and not PayPal. We won\u2019t go too in-depth into URL structures, but suffice it to say, if the site you think you\u2019re visiting is not what appears right before the TLD (.com, .org, etc.) then you\u2019re not headed where you think.<\/p>\n<p>Oftentimes cybercriminals will use a link shortening service like bit.ly to hide the actual URL. This is another tip-off. Most legitimate URLs from companies like Google and PayPal are not link-shortened, and if they are it\u2019s done using a custom URL\u2014not bit.ly.<\/p>\n<p>Always inspect the URL before clicking on it. Be sure you know exactly where you\u2019re being sent.<\/p>\n<p><strong>Check the Certificate Details<\/strong><\/p>\n<p>That \u201cSecure\u201d indicator and the green padlock accompanying it can be clicked. This should be one of the first things you do when you arrive at a page that wants you to login or provide personal information.<\/p>\n<p>[su_pullquote]&#8221;Domain Validation SSL provides the same level of encryption security as OV and EV, but you can\u2019t know for sure who is on the other end of the connection.&#8221;[\/su_pullquote]<\/p>\n<p>In addition to encryption, SSL certificates also offer different levels of authentication. The most basic, DV only requires domain validation \u2013 meaning you must only prove you own the domain \u2013 before it can be issued. This is the level of validation that cybercriminals exploit because it\u2019s easily obtainable and often free.<\/p>\n<p>The other two levels of authentication, Organization Validation (OV) and Extended Validation (EV), offer what is commonly referred to as Business Authentication. This means that the issuing Certificate Authority actually vetted the business or organization that applied for the certificate and is willing to vouch for their identity.<\/p>\n<p>You can probably see where this is going. Domain Validation SSL provides the same level of encryption security as OV and EV, but you can\u2019t know for sure who is on the other end of the connection. If you see that a website has DV SSL, be extremely cautious. You can\u2019t be sure who you\u2019re sending your information to.<\/p>\n<p>On the other hand, OV and EV SSL Certificates will display verified business details about the company that runs the site. You can\u2019t fake this. If you see verified business details, you know who you\u2019re dealing with.<\/p>\n<p>To check certificate details, click the \u201cSecure\u201d indicator, that will bring up this screen:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3432 size-full\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_18.png\" alt=\"year of the phish, phishing, 2017\" width=\"354\" height=\"668\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_18.png 354w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_18-159x300.png 159w\" sizes=\"auto, (max-width: 354px) 100vw, 354px\" \/><\/p>\n<p>Click on the word \u201cDetails\u201d to open up \u201cSecurity Overview.\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-3433\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_16.png\" alt=\"year of the phish, phishing, 2017\" width=\"1352\" height=\"905\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_16.png 1352w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_16-300x200.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_16-768x514.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_16-1024x685.png 1024w\" sizes=\"auto, (max-width: 1352px) 100vw, 1352px\" \/><\/p>\n<p>Click on \u201cView Certificate\u201d to open the certificate details.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-3434 aligncenter\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_21.png\" alt=\"year of the phish, phishing, 2017\" width=\"518\" height=\"539\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_21.png 518w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_21-288x300.png 288w\" sizes=\"auto, (max-width: 518px) 100vw, 518px\" \/><\/p>\n<p>Above is an example of a Domain Validated certificate. Notice how it doesn\u2019t give you any information about who owns the site? It just says the name of the site itself. <strong>Who knows who is running it.<\/strong>\u00a0Below is an example of an Organization Validated certificate, notice the legal name of the organization is displayed? Now there\u2019s no doubt who owns this site.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-3435 aligncenter\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_19.png\" alt=\"year of the phish, phishing, 2017\" width=\"518\" height=\"540\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_19.png 518w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Snip20170124_19-288x300.png 288w\" sizes=\"auto, (max-width: 518px) 100vw, 518px\" \/><\/p>\n<p>As for EV SSL\u2026<\/p>\n<p><strong>Check for the Green Address Bar<\/strong><\/p>\n<p>The most unmistakable way to show a site is the legitimate article is with the green address bar that accompanies EV SSL. Granted, the address bar is no longer green like it used to be\u2014now it just displays the organization&#8217;s name and country of origin in green font next to the URL. But still, this visual indicator is unmistakable and un-fakeable.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3438\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Secure_EV_URL-Bar.png\" alt=\"year of the phish, phishing, 2017\" width=\"3918\" height=\"453\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Secure_EV_URL-Bar.png 3918w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Secure_EV_URL-Bar-300x35.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Secure_EV_URL-Bar-768x89.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/Secure_EV_URL-Bar-1024x118.png 1024w\" sizes=\"auto, (max-width: 3918px) 100vw, 3918px\" \/><\/p>\n<p>If you see a green address bar, you don\u2019t even need to check the certificate details because you already have verification that the site is legitimate.<\/p>\n<p>[su_pullquote align=&#8221;right&#8221;]&#8221;The best way to avoid being phished is just to pay attention. Be vigilant.&#8221;[\/su_pullquote]<\/p>\n<p>EV SSL can be cost-prohibitive for a lot of smaller businesses or organizations, but most major companies and corporations do invest in Extended Validation. So, if possible, try to keep a running tally in your head of which sites have EV. As you saw in our PayPal example from earlier, that could be the difference between getting phished and knowing when a site is fake.<\/p>\n<p>The best way to avoid being phished is just to pay attention. Be vigilant. Take a moment to click around and check where your links are taking you and who is on the other end of your encrypted connections.<\/p>\n<p>Moving forward in 2017, all connections may now be encrypted, but you know better than to think that means you\u2019re safer. Nowadays, it\u2019s all about knowing who exactly you\u2019re connected with.<\/p>\n<h2>How to Protect Your Business<\/h2>\n<p>You may not think your company or organization would be at risk of a phishing attack. You would be wrong.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3436\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/img-consider-this.png\" alt=\"year of the phish, phishing, 2017\" width=\"960\" height=\"240\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/img-consider-this.png 960w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/img-consider-this-300x75.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/img-consider-this-768x192.png 768w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" \/><\/p>\n<p>Now think about this, according to the Nation Cyber Security Alliance, <strong>60% of the small businesses that get hit by a cyber attack go under within six months of the incident<\/strong>. Getting phished does major harm to your reputation and costs you money.<\/p>\n<p>[su_pullquote]&#8221;Frankly, DV SSL might even be putting your customers at risk [of being phished].&#8221;[\/su_pullquote]<\/p>\n<p>As you can probably surmise, the best way to avoid this issue entirely is to invest in SSL that also provides business authentication. OV SSL is the more affordable route, but going with OV may also require you to educate your customers about SSL indicators and how to make sure they\u2019re at the right website. Extended Validation SSL is frankly the best option, as it provides an instantly recognizable visual indicator that offers immediate assurance to anyone who visits your site. As we discussed though, EV can be cost prohibitive.<\/p>\n<p>Just stay away from Domain Validation SSL. In 2017, with the current environment, any websites that deal in personal information or financial data need\u00a0more authentication than DV can possibly offer. Frankly, DV SSL might even be putting your customers at risk.<\/p>\n<h2>2017: The Year of the Phish<\/h2>\n<p>And there you have it, that\u2019s why 2017 will be the Year of the Phish. In a constantly evolving game of cat and mouse between cybercriminals designing fake, phishing websites and the browsers tasked with catching and blacklisting them\u2014the advantage has shifted towards the cybercriminals in 2017.<\/p>\n<p>New security indicators, the proliferation of HTTPS and the ease with which cybercriminals can get SSL and disguise their sites as \u201csecure\u201d have created the perfect climate for phishing.<\/p>\n<p>So stay vigilant\u2014don\u2019t get duped in 2017.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Phishing attacks will become more prevalent than ever in 2017! January 28th marks the Chinese New Year. It will be another &#8216;Year of the Rooster&#8217; per the traditional Chinese lunisolar&#8230;<\/p>\n","protected":false},"author":6,"featured_media":3419,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130],"tags":[366,365,145,208,166,367,364],"class_list":["post-3418","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","tag-ev-ssl","tag-green-address-bar","tag-lets-encrypt","tag-not-secure","tag-phishing","tag-secure","tag-year-of-the-phish","post-with-tags"],"views":13772,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/01\/iStock-496994567.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3418","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=3418"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3418\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/3419"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=3418"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=3418"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=3418"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}