Reddit Phishing scam is the most recent data breach in recent weeks, where an employee was unfortunately deceived by a highly sophisticated and well-targeted spear phishing attack.
According to Reddit, the attacker behind the data breach set up a website that mimics the company's intranet gateway to send out highly-targeted phishing emails to unsuspecting Reddit employees. Once these credentials were obtained, two-factor authentication tokens were also stolen for further malicious intent.
Reddit notified its users to explain exactly what happened during the phishing scam but only revealed a few details. However, it did mention that the attacker managed to access "some internal docs, code and some internal business systems.
Since the update does imply that only one employee fell victim, there are some assumptions about the breach.
From the Reddit Phishing attack, there are key takeaways to ensure that your company does not fall to the same fate. Ensure that 2-factor authentication (2FA) is used on anything your company uses to give that extra level of security. It is better to have one than not have one at all.
It is also important to highlight that in the Rediit Phishing scam, the employees played a role in the breach, so staff must know what to do if a breach happens. Reddit explained how "soon after being phished, the affected employee self-reported, and the security team responded quickly, removing the infiltrator's access and commencing an internal investigation." Mistakes happen, but how they are resolved is the most crucial part.
Silver Lining can help you and your employees stay educated on keeping themselves secure with our cyber security management. We can offer a wide range of tools, from Simulated phishing campaigns to see where a breach would happen and Security Awareness Training. To find out more, please hit the link below to our Cyber Security Management page.
Equally, do not hesitate to get in touch with us by calling 0345 313 1111 or emailing us at info@silver-lining.com