Question

Difficulty: MediumKey Security Concepts, Threats, Vulnerabilities, and Mitigations

An organization's Chief Financial Officer receives a highly tailored email that appears to originate from the company's primary banking institution. The message references specific details regarding a recent internal corporate transaction and directs the executive to a credential-harvesting website disguised as the bank's portal. Which security threat is demonstrated in this scenario?

  1. Spear phishingAnswer
  2. B
    Watering hole attack
  3. C
    Vishing
  4. D
    Man-in-the-middle attack

Answer

Spear phishing is the security threat demonstrated in this scenario.
Spear phishing specifically targets a specific high-value individual or organizational role by leveraging tailored contextual information, such as recent financial transaction details, to trick the recipient into revealing sensitive credentials.

Step-by-Step Solution

1
Analyze the target specificity and delivery vector presented in the scenario.
The threat uses a spoofed email directed specifically at a high-ranking executive (CFO) rather than a broad, generic distribution list.
Identifying target specificity establishes whether an attack is generic phishing or targeted spear phishing.
2
Evaluate the contextual customization contained in the message.
The message incorporates confidential internal details (recent transaction data) to deceive a specific recipient.
Tailored contextual details distinguish spear phishing from standard bulk phishing campaigns.

Key Concept

Social engineering threat vectors and spear phishing characteristics
Rate this question