{"id":10996,"date":"2023-10-02T19:52:48","date_gmt":"2023-10-02T06:52:48","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=10996"},"modified":"2023-10-02T19:52:48","modified_gmt":"2023-10-02T06:52:48","slug":"would-your-cyber-security-have-saved-you-from-this-hack-attempt","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=10996","title":{"rendered":"Would your cyber-security have saved you from this hack attempt?"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<h2>This is a real and very clever &#8216;spear-phishing&#8217; attempt that one of our legal clients in Auckland received today.<\/h2>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row disabled_on=&#8221;on|off|off&#8221; _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_image src=&#8221;http:\/\/kinetics.co.nz\/wp-content\/uploads\/2023\/10\/emailimage2.png&#8221; title_text=&#8221;emailimage2&#8243; _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][\/et_pb_image][et_pb_text _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<h2>Would you have opened it?\u00a0\u00a0Would your IT have protected you?<\/h2>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row disabled_on=&#8221;off|on|on&#8221; _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;5px|5px|5px|5px|false|false&#8221; border_width_all=&#8221;1px&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p><strong>To: Me<\/strong><\/p>\n<p><strong>From : new customer<\/strong><\/p>\n<p><i>Hello,<\/i><\/p>\n<p><i>My Husband and I are looking to buy a property (First-time buyer).<\/i><\/p>\n<p><i>We have agreed on a price with the buyer but need a solicitor to see us through the process of exchange and closing.<\/i><\/p>\n<p><i>We were referred to you, hence we decided to send you a message.<\/i><\/p>\n<p><i>Kindly contact us by return email.<\/i><\/p>\n<p><i>Best Regards,<\/i><\/p>\n<p><i><\/i><\/p>\n<h2><\/h2>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p>&nbsp;<\/p>\n<p><i><\/i><\/p>\n<h2>Would you have opened it?\u00a0\u00a0Would your IT have protected you?<\/h2>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;1_2,1_2&#8243; _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; background_image=&#8221;http:\/\/kinetics.co.nz\/wp-content\/uploads\/2023\/10\/Phisher.png&#8221; background_size=&#8221;initial&#8221; background_position=&#8221;center_right&#8221; background_horizontal_offset=&#8221;-10%&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;rgba(34,34,34,0.8)&#8221; custom_padding=&#8221;20px|20px|20px|20px|false|false&#8221; border_radii=&#8221;on|20px|20px|20px|20px&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p><span style=\"color: #ffffff;\">They are a busy lawyer, and this email looks sufficiently legitimate that, understandably, they opened it.<\/span><\/p>\n<p><span style=\"color: #ffffff;\">&#8220;Spear-phishing&#8221; (also known as &#8216;whaling&#8217;) &#8211; is the art of carefully writing a fake email to target specific users.<\/span><\/p>\n<p><span style=\"color: #ffffff;\">In this case, the subsequent follow up email included a malicious file.\u00a0 \u00a0It was so well written that it got past the email filters, and past the 365 protections.\u00a0 <\/span><\/p>\n<p><span style=\"color: #ffffff;\"><strong>But security is all about layers, and in this case, it got caught at the device.\u00a0 \u00a0The &#8216;zero trust&#8217; approach worked.\u00a0 In line with our Kinetics technical standards, the user only had limited &#8216;UAC&#8217; (user access control) and that defeated the malware.\u00a0 \u00a0<\/strong><\/span><\/p>\n<p><span style=\"color: #ffffff;\"><strong>It stands out to me that it also even got past the anti-virus!<\/strong><\/span><\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;rgba(22,18,18,0.09)&#8221; custom_padding=&#8221;20px|20px|20px|20px|false|false&#8221; border_radii=&#8221;on|20px|20px|20px|20px&#8221; border_width_all=&#8221;1px&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p><strong>This is a perfect example of why anti-virus isn&#8217;t good enough anymore.\u00a0 We tested with EDR, the EDR caught it immediately.<\/strong><\/p>\n<p><strong>It is why we are <a href=\"http:\/\/kinetics.co.nz\/kare-will-your-support-plan-need-to-change\/\">retiring our old KARE support plans and replacing them with new ones<\/a>.\u00a0 We know these new plans have more protections in them, and therefore cost more, but unfortunately that is what we now need.\u00a0 We are continually reviewing our plans to make sure they are relevant and appropriate.<\/strong><\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<h3>Cyber-security is all about layers, and we need more protective layers now than ever before.<\/h3>\n<p>(postscript &#8211; the smart email filters updated quickly and were correctly blocking it later in the day &#8211; but that wouldn&#8217;t have been soon enough.\u00a0<\/p>\n<p>Thankfully our KARE configuration worked and blocked it successfully first time!)<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is a real and very clever &#8216;spear-phishing&#8217; attempt that one of our legal clients in Auckland received today.Would you have opened it?\u00a0\u00a0Would your IT have protected you?To: Me From : new customer Hello, My Husband and I are looking to buy a property (First-time buyer). We have agreed on a price with the buyer [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":11004,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4,5],"tags":[],"class_list":["post-10996","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-security"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/10996","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10996"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/10996\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10996"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=10996"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=10996"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}