/>
X

This password-stealing phishing attack comes disguised as a fake meeting request from the boss

Called to a meeting with the CEO? Don't be so sure.
danny-palmer
Written by Danny Palmer, Senior Writer on

A widespread phishing campaign is targeting executives across a number of industries with messages asking to reschedule a board meeting in an effort to steal logins and passwords.

Spotted by researchers at security firm GreatHorn, the phishing messages spoof the name and email address of the CEO of the company being targeted and uses a subject line including the company name and a note about the meeting to gain the attention of potential victims. Users are more likely to fall for attacks they believe to come from their boss.

The contents of the phishing email is simple: it says a board meeting has been rescheduled and asks users to take part in a poll to choose a new date.

If users click the link, they're taken to a webpage which appears to be a login page for Microsoft Outlook and Office 365, but this is in fact a phishing site — any information entered into it will go directly into the hands of the attackers.

The attack is slightly different if the email is viewed on a mobile device — the display name is changed to 'Note to Self' but the contents of the message stays the same.

SEE: Cybersecurity in an IoT and mobile world (ZDNet special report) | Download the report as a PDF (TechRepublic)

With the phishing email targeting high-level executives like CFOs, CTOs and SVPs, a successful attack could provide attackers with access to highly sensitive data across the corporate network — and the compromised accounts could also be used to help conduct further malicious campaigns.

The fake meeting phishing attack appears to be prolific — researchers at GreatHorn say it was found targeting one in seven of the firm's customers. In each case, the attackers were eliminated before damage could be done.

It's believed that the campaign is still active and that the phishing URL  claiming to be windows related — is still up.

Users are therefore warned to be aware of the campaign and to be suspicious of any emails containing a subject line following a pattern of: New message: [Company Name] February in-person Board Mtg scheduling (2/24/19 update)

READ MORE ON CYBER SECURITY

Related

Get an entire career's worth of Microsoft training for only $60
replace-this-image.jpg

Get an entire career's worth of Microsoft training for only $60

Deals
Office 2016 and 2019 users won't be cut off from Microsoft 365 back-end services next year
officebackendconnectivity

Office 2016 and 2019 users won't be cut off from Microsoft 365 back-end services next year

Productivity
Become more productive and less stressed with this $50 app
replace-this-image.jpg

Become more productive and less stressed with this $50 app

Deals