Hackers continued betting on their best weapon – phishing to dupe businesses in 2024. Data collated by cybersecurity solutions company Kaspersky found over two lakh attempts to launch phishing attacks against businesses in India last year.
Kaspersky intercepted and thwarted over 1.99 lakh financial phishing attacks aimed at businesses across the country, spanning small enterprises to large corporations. These figures are instances where users clicked on phishing links distributed through a variety of platforms—emails, counterfeit websites, messaging apps, social networks, and more.
In phishing attacks, hackers create deceptive links that mimic legitimate services, and when people click on them, their systems can be compromised. Hackers loiter around discreetly and siphon off personal details, banking credentials and even encrypt the data and demand ransom to return it.
“Financial phishing targets banking, payment systems, and online retailers. This includes fake websites designed to mimic trusted payment platforms, aiming to deceive users into revealing financial information,” Jaydeep Singh, General Manager for India at Kaspersky, said.
“The significant number of financial phishing attempts we’ve identified on business devices in India is deeply concerning. It is evident that cybercriminals are taking advantage of the accelerated digital transformation in the country. Businesses must stay alert to safeguard their operations,” Singh said.
Kaspersky notes that the rise of AI has enabled cybercriminals to create highly convincing fake websites, making it easier for individuals and businesses to fall victim to phishing scams than to detect and avoid them.
How to stay safe
Kaspersky asks people and organisations to be cautious while dealing with emails and suspicious links. “You must open emails and click links if you are sure you can trust the sender. “
“When a sender is legitimate, but the content of the message seems strange, it is worth checking with the sender via an alternative means of communication,” he said.
“You must check the spelling of a website address (URL) before checking or accessing service on a website. The URL may contain mistakes that are hard to spot at first glance, such as a 1 instead of I or 0 instead of O,” he said.
He also wants businesses to run security awareness training for employees. This will equip them with the knowledge to resist social engineering techniques and spot cybercriminal tricks early.
