Skip to the content of the web site.

Spear Phishing Attacks

Security >> Vulnerabilities (2008) >> 2008/04/03

Issue: Spear Phishing Attacks
Risk: Password Disclosure
Date: 2008/04/03-2008/11/01

You should be aware of recent confidence attacks, called spear phishing, where the attackers have tried to trick users here and elsewhere into revealing their passwords. You should know that:

Support staff will never ask for your password. Be especially skeptical about email messages and web sites phishing for your password --- see Security Tip: Don't get hooked by a Phishing expedition.
Accounts which have been compromised are sometimes used for spam. But identity theft, data compromise, mischief, etc. are possible. You should be careful.

If you receive any suspicious email asking for sensitive information -- passwords should be not be revealled to anyone -- please ask for help.

See Also --

Please review these samples and the commentary on each:

Finally, if you have any questions/concerns or need help please let us know.

Jason Testart
Manager, IT Security
+1 519 888-4567 x38393