On July 15, 2020, the Twitter accounts of Barack Obama, Elon Musk, Joe Biden, and Apple all promised to double any Bitcoin sent their way. The mastermind was a 17-year-old who broke no encryption. He and his accomplices phoned Twitter employees working from home, posed as the IT help desk, and sent them to a fake VPN site, netting about $117,000. This episode uses that breach to explain phishing as a hack of human psychology, delivered by email, phone calls, text messages, and now QR codes.
The history runs from America Online in 1995, where users posed as staff to collect passwords, through the Russian Business Network and the 2013 Target breach, to the state-backed group Fancy Bear. Then comes the present arms race. Language models write flawless lures for about three cents each, subscription kits let anyone launch a campaign, and adversary-in-the-middle attacks relay login codes in real time to steal session cookies. The strongest answer so far is the passkey.
- In a study of 1,876 participants, statistically none could identify a malicious QR code, and scammers in the UK have stuck fake codes over real ones on car park payment machines.
- US computer users lost around $929 million to phishing in a single year in the mid-2000s, and in 2006 the Russian Business Network was tied to almost half of all phishing thefts.
- Attackers reached Target’s 110 million customer and card records by spear phishing an HVAC subcontractor with network access.
- A 2024 study found the mandatory training shown after a failed phishing test does not improve behavior, though periodic reminders that tests exist do help.
- Passkeys tie the cryptographic signature to the real domain, so a spoofed site gets nothing an attacker can intercept or relay.
Leave a Reply