Don’t Be Fooled by Workspace Tools

Webex Banner

Many organizations use platforms such as Microsoft Teams, Google Drive, or Zoom to stay connected. Unfortunately, these trusted communication tools can lead to a false sense of security. Just like with traditional email, bad guys can use these platforms to launch a cyber attack.

Below are three examples of how cybercriminals use these platforms for phishing—and what you can do to keep your organization safe!

Lurking

Recently, a cybercriminal gained access to an organization’s Microsoft Teams channel, which is similar to a group message or a chat room. The scammer lurked in the channel for nearly a year, reading messages, collecting data, and waiting for the perfect time to strike. Finally, someone asked that a file be shared to the channel and the bad guy used this opportunity to send a malicious ZIP file. When opened, the file installed malware that gave the scammer full access to the victim’s computer.

Remember: If someone sends you a link or an attachment, verify that you know and trust the sender before you click.

Playing Tag

On Google Drive, anyone can be tagged in a file, so long as their Gmail address is valid. This means that if a bad guy tags you in a Google document, you will receive a legitimate notification from Google that includes a link to the bad guy’s file. If you view the bad guy’s file, you’ll likely find that it tells you to click another link. This second link is actually a malicious attempt to steal your sensitive information.

Remember: If you receive a suspicious notification, contact your IT department or follow the specific security procedure for your organization.

Phony Notifications

Attending meetings on Zoom is as simple as clicking a button within an email. Unfortunately, getting phished is just as easy. Cybercriminals send out fake Zoom notifications that claim you missed an important meeting. They use a sense of urgency to get you to click on a link to view the meeting schedule. But don’t be fooled! The link actually sends you to a phony login page designed to steal your username and password.

Remember: If an email asks you to log in to an account or online service, log in to your account through your browser—not by clicking the link in the email.



Knowbe4 Logo

Stop, Look, and Think. Don’t be fooled.

Like This Post?

Facebook
X
LinkedIn
Email

More Posts

Speed Test Blog Image
Technology

Know Your Numbers: A Simple Guide to Internet Speed Tests

Nothing is more frustrating than being in the middle of a video call and experiencing choppy, pixelated picture or audio. Or, if you’re trying to update your computer or gaming system, and that download loading bar is barely headed toward

Guest Wi-Fi Blog Image
Technology

Why Every Home Needs a Guest WiFi Network

Most people think of WiFi as a single network. A friend visits, asks for the password, and you share it without much thought. What many people don’t realize is that sharing your WiFi password may also give guests access to

Virtual Game Night Image
Technology

Host a Virtual Game Night Without Lag

Hosting a virtual game night is a great way to stay connected with your friends and family, especially when everyone is joining in from different places. Whether you’re catching up with friends or planning something fun for everyone to do

Tech Energy Costs Image
Technology

Reduce the Energy Costs of Your Tech

Most of us think about saving energy by turning off lights or adjusting the thermostat. But today’s homes run on something just as important: connectivity. From streaming and remote work to smart thermostats and connected devices, technology plays a bigger