Yes, it can, and very likely will, happen. A staff member on a campaign or in an organization clicks on something and immediately feels a sense of dread that maybe it was a mistake, a big mistake. What should they do?
First, don’t panic.
According to Microsoft’s recent Phishing Trends and Statistics Report 94% of all phishing attacks that included a malicious attachment were attempts to harvest credentials (logins, passwords, and gain account access) NOT deliver malware. These are the steps you can take.
Step #1: If your campaign or organization has policies and procedures around reporting cyber incidents or potential incidents, do as the policy indicates. Report quickly as time is the enemy in a cyberattack. The longer a potential compromise is unaddressed the worse it can become.
Step #2: Implement DDC’s number one cybersecurity recommendation–turn on the strongest multifactor authentication available.
Both Google and Microsoft offer passkeys -an encrypted digital credential. Passkeys are free and the best account protection available. They can’t be copied or stolen and are virtually phishing resistant. So, follow these steps:
Use this link to add a passkey on personal and work Gmail accounts: https://www.google.com/account/about/passkeys/
Follow these steps to add a passkey to your Microsoft accounts: https://support.microsoft.com/en-us/accounts-billing/security/create-save-passkey
You can also up your account security with additional protections for high risk users.
Google users: Turn on Google’s Advanced Protection Program with a passkey on Workspace and personal Gmail Accounts.
Microsoft users: Organizations can up their security by applying for AccountGuard, their enhanced protection for high risk organizations.
Step #3: Protect Critical Accounts: Once you have strengthened your email, implement strong multifactor authentication on other critical accounts, such as social media, banking, and with other critical vendors you use. If passkeys or other forms of MFA are not available, change passwords. Use a password manager to create and store strong passwords.
Step #4: Scan your device (if needed) If you are concerned that you potentially downloaded or opened a suspicious file and you are concerned about potential malware you can either:
Disconnect your device from Wi-Fi or the internet immediately to prevent the spread of malware to other devices and networks..
OR
Run a malware/ virus scan
On a windows machine go to settings>Privacy and Security>Virus and threat protection> and click on the quick scan button under current threats.
Mac’s do have built in virus and malware protection called XProtect. However, while it does scan for malware you can not conduct a manual scan. You can use a third party tool including Microsoft Defender for MAC, which you can find in the Mac App store (https://apps.apple.com/us/mac/discover) or scanners from other companies. All will require a download.
Step #5: On both Google and Microsoft you can check for any devices that have or are attempting to access your accounts.
In Google: click on your account (your photo or initial upper right)>click on manage your account>on the left hand side click on security and signin>scroll down and look at the devices attached to your account and the apps linked to your account to see if there is anything unusual and sign-out of unauthorized devices.
In Microsoft: Go to the My Account Page and sign in with your organizational credentials > Choose Devices from the left-hand menu to see connected hardware >Choose My Sign-ins or Recent Activity from the menu to review active login sessions, operating systems, and IP locations > Click Disable on any unfamiliar or old device to revoke its access
Step #6: If you are DDC eligible (US House and Senate races and in GA, OH, MI, VA) we can help in other ways including providing security keys that provide strong account protections and are usable at numerous sites on the internet, hold a session for your team to help the implement passkeys and other security features. We can also help in some instances regain access to your account if you get locked out.
Common phishing attacks you should know about this election cycle:
Phishing in the world of AI has become more sophisticated and effective. Microsoft’s recent Digital Defense Report reveals that AI-driven automation has pushed phishing click-through rates to a staggering 54%—roughly 4.5 times more effective than the 12% rate seen in conventional phishing campaigns. They achieve through hyper-personalization of communications and creating a sense of connection with a recipient leading to people lowering their guard (Read our blog on how AI makes phishing more effective here).
Here are some other common phishing schemes by no means an all inclusive list. Remember that creating a sense or urgency and immediate action remains the heart of any phishing effort.
Calendar Phishing Attacks: If you received a phishing calendar appointment, a very common attack scenario these days where attackers send a direct calendar invitation that automatically appears on your calendar, do not click on the link to the meeting and do not accept (obviously) , decline, or respond maybe. This action will confirm your email address belongs to a real person. Instead, delete the email invite and the calendar appointment. FYI, these calendar phishing attempts often include calls to urgency such as a critical meeting with leadership, or a need to meet immediately because of a crisis.
RFP Scam: This scam attempts to access your login credentials by tricking you into thinking a colleague or client is requesting a proposal. In order to “access” the document it requires your login credentials. The individual is then locked out of their account.
Pay this invoice now: What’s known as the business executive compromise (BEC) has been and remains a common attack technique. Bad actors pose as someone you know like a manager or CEO (sometimes by hacking their account or even impersonating via voicemail or both) and say it’s critical you pay an invoice ASAP and include the information you need including routing number. Of course, it goes to the bank account of a cyber criminal. Never pay under these circumstances without a verbal confirmation from the sender.
Keep an eye out for these types and similar scams. DDC is happy to help. Feel free to book a consultation with our onboarding team to discuss your concerns and needs and learn more about implementing protections like passkeys. Reach out anytime https://defendcampaigns.org/contact-us
