An organization's security team detects an unauthorized login to a corporate account. Incident analysis reveals that the compromised employee received an SMS notification on their mobile device claiming to be from the IT helpdesk, warning that their account access would be revoked unless verified immediately via a provided URL. The link directed the user to a fraudulent authentication portal where their credentials were captured. Which social engineering attack vector initiated this security incident?
- SmishingAnswer
- BVishing
- CSpear phishing
- DPharming
Answer
Smishing is the social engineering attack vector delivered through SMS text messaging.
Smishing (SMS phishing) specifically leverages Short Message Service (SMS) text messages as the vector to deliver deceptive lures and malicious links to mobile devices. In this scenario, the attack was initiated through an urgent SMS notification containing a link to a credential harvesting site.
Step-by-Step Solution
Key Concept
Social Engineering Attack Vectors and Transport Media
Estimated Time:1m 0s