• On CBSSports.com: Watch the Championship Online Free
April 15, 2008 1:26 PM PDT

Beware the 'whaling' e-mail that includes your company info

by Elinor Mills
  • Font size
  • Print
  • Post a comment

You get an e-mail not only addressed to you, but it includes your company name and phone number and appears to come from the U.S. District Court.

It looks like a subpoena to appear in court on a civil case and it instructs you to download the document from a Web site.

What should you do?

Whatever you do, don't click on the hyperlink to the Web site, warns Web security services firm MX Logic. It's probably a malicious Web site that will download malicious software, such as a keystroke logger, to your machine.

The social engineering attack is similar to others, including phishing e-mails that purport to come from the Internal Revenue Service. But this attack goes a step further by including your company phone number, which makes it seem even more legitimate.

If you're an executive, chances are you're the intended victim of a so-called whaling attack. While phishing attacks are aimed at anyone with an e-mail address, whaling attacks target big fish at companies where knowing a top executive's password opens a back door to sensitive insider information.

Remember, courts communicate via regular mail, not e-mail. In addition to some spelling errors in a sample whaling e-mail making the rounds this week, MX Logic found that the link went to a top-level domain other than ".gov" which was registered a few days earlier to someone in the U.K.

A new phishing e-mail targeting CEOs looks like a subpoena and includes a company name and number. This shows the top part of the e-mail.

(Credit: MX Logic)
Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
Recent posts from News Blog
Nasdaq 5,000: Ten years after the dot-com peak
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
advertisement
CNET River
  • image
  • image
    mollywood: Simple task + bizarrely slow Internet + Windows 7 printer drivers + not quite enough coffee = MOLLY SMASH!
    by Molly Wood
  • image
    Josh: Paddy's Pub from "It's Always Sunny in Philadelphia" found on Google Maps: http://bit.ly/8YwGN9 (via Reddit)
    by Josh Lowensohn
  • image
  • image
    caro: Spotted in MSNBC greenroom: @williamfleitch. Despite being a sports writer, he is not here to talk about Tiger Woods.
    by Caroline McCarthy
advertisement

Viacom, Google air dirty laundry in court docs

Copyright confrontation gets fierce. Viacom says YouTube founders always intended to build video version of Napster and looked for ways to "to avoid the copyright bastards."
• Google's statement on YouTube-Viacom

Google's fast pipe to Asia almost ready

An undersea cable built by a group including Google and telecom companies is set to start carrying traffic at any point, with Google to get as much as 20 percent of the capacity.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right