An organization's finance department receives an email requesting an immediate change to a trusted vendor's direct deposit bank account details before a scheduled wire transfer. The email features legitimate company logos, uses appropriate financial terminology, and references recent specific purchase order numbers, but originates from a slightly altered external domain. Which of the following social engineering attacks is depicted in this scenario?
- Spear phishingAnswer
- BWatering hole attack
- CSmishing
- DPharming
Answer
Spear phishing is the correct answer because the attack specifically targets finance department personnel with tailored, context-specific information like genuine purchase order details to perform financial theft.
Spear phishing describes a social engineering attack that targets specific organizations or individuals using custom-tailored details—such as accurate contract references and specific financial context—to increase credibility and the likelihood of success.
Step-by-Step Solution
Key Concept
Spear phishing involves crafted, highly targeted messages leveraging stolen or researched context to deceive specific targets.