We have been made aware of an email display name spoofing campaign currently making the rounds. If you receive an email from us (or any organization) that you are not expecting and would like to confirm, please contact the organization directly.
What is Email Display Name Spoofing:
Email spoofing is a technique used in spam and phishing attacks to trick users into thinking a message came from a person or entity they either know or can trust. In spoofing attacks, the sender forges email headers so that client software displays the fraudulent sender address, which most users take at face value.
What are these emails used for:
The goal of these emails are common. They are to get the user to disclose information, download a malicious file/software or provide login information to the person/group that have issued the email.
How to protect yourself from this:
Even with Email Security in place, some malicious emails will still reach the inbox. Looking at certain items can help to avoid and protect becoming a victim of such attacks.
- Look for items such as disclaimers and email signatures. These are often not attached to the email when it is spoofed.
- Be suspicious about emails that you were not expecting or are grammatically different from what the person has sent prior.
- Avoid attachments in emails that are not normal or attachments that require you to input a password that is contained in the same email.
- Reminder. Never click on links for institutions that contain personal details. IE: Banks, SARS ETC
Is my system compromised:
If you are informed of an individual who has received an email from you that is a spoof, your systems are most likely not compromised. We will however always recommend that you contact your IT company and inform them of the event to ensure your systems security is maintained.
If you have received any spoofed email and opened it, we once again recommend that you contact your IT company and inform them of the event to ensure your systems security is maintained.