IBM researchers said a ChatGPT-generated phishing email was almost as effective in fooling people compared to a man-made version.

  • a1studmuffin@aussie.zone
    link
    fedilink
    English
    arrow-up
    28
    ·
    1 year ago

    A targeted phishing email is usually pretty sophisticated and requires days or weeks of research. For example, you might send an email pretending to be from someone’s IT department regarding a hardware audit, and ask a user to report back with the barcode sticker on their laptop, providing them with a photo of an example tag in similar format. You’ll pretend to be a specific individual at the company, or a contractor the company actually uses, and show knowledge of the internal software and hardware, and refer to other real employees by name/email to establish trust. Most of this data will be scraped from publicly available sources like LinkedIn profiles, job listings, and photos shared on social media by employees. This process is called OSINT (Open-Source Intelligence) and it’s a fascinating rabbithole to read about. Targeted phishing attempts are much, much more sophisticated than the ones you’ll see in spam email.

    • afraid_of_zombies@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      My old employer would get a call every few months from someone pretending to be our client and informing us we should change the banking information. No one could figure out how they figured out that there was a business relationship between the two companies let alone who was the financial person at my job.