Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ......

21
Who is Using Your Domain for Phishing & Spam? Daniel Ingevaldson CTO

Transcript of Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ......

Page 1: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

Who is Using Your Domain for Phishing & Spam?

Daniel Ingevaldson CTO

Page 2: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

73% of data breaches begin with fraudulent email. The below scenarios are common methods to breach consumers’ devices or employees’ “bring your own devices.”

2

BrandErosion

UntrustedEmails

FraudExpenses

UserCreden)alCompromise

•  URLtowebsitetocapturelogincreden)als

•  Compromisedusername&passwordo9enreusedacrosswebsites

•  Emailo9enspoofsYourCompany.com,YourCompamy.com,orothertrusteddomain

MalwareInstalla)on

Most Breaches Begin with an Email

Page 3: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

Below is a free service to create a phishing email with a fraudulent FROM address.

3

h7ps://emkei.cz/

Anyone Can Spoof

Page 4: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

4

.…Fraudemailissenttocustomers&businesspartners..1

ItisdifficulttoidenDfyfraudulentemail.2

-  100billionspammessagesgloballyperday-  2.1millionphishingmessagesperday-  73%ofdatabreachesbeginwithafraudulentemail

-  Phishingemailscanhavea70%openrate-  50%ofuserswhoopenaphishingemailwillopentheURLora7achment

The Two Email Problems

Page 5: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

Increase proacPve idenPficaPon and removal of threats to decrease fraud loss.

5

toDecreaseFraudLosesIncreaseProacDveAcDvity

ReduceAFackerIncen)ves•  Takedownplanneda7acksbeforetheyoccur•  Betheindustry’smostdifficulttarget

IncreaseProac)vity•  IdenDfya7acker’sinfrastructure•  Understanda7acker’sintent•  Takedowna7acker’scapability

EasySoluDons’strategymaximizesproacDvethreatremovaltosavecustomersmillionsinfraudloss.

How Loss Occurs

Page 6: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

Email has also become an untrusted channel. Thanks to spam and phishing scams, users are taught to be wary of incoming messages.

[PERCENTAGE]

2015 Proportion of Spam in Email²

Spam

97% of people globally are unable to correctly idenPfy phishing emails³

Page 7: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

What Does DMARC Do?

Allows email receivers to determine if an email is authentic and what to do if it isn’t

Page 8: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

Collect reporPng from email receivers Measure global email authenPcaPon rates QuanPfy email channel health

Page 9: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

Getting started with DMARC is easy. Any email sender and receiver can use the DMARC rails provided by the global community.

Page 10: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

Can be deployed in Monitor, Quarantine or Reject mode.

DMARC

Page 11: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

DMARC supports three “modes” – Monitor only, QuaranPne and Reject

11

DMARCPolicy p=None p=Quaran)ne p=Reject

SpoofingResults •  Doesn’tstopthea7ack •  Decreaseina7acksuccess •  Stopsa7acks

DomainEmailFraudwithDMARC

SpoofedEmailsSuccessfulEmails

#Em

ails

Time

Fraud Lifecycle with DMARC

Page 12: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

It is impossible for spoofed email to be delivered to DMARC-protected email servers

Page 13: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

“DMARC protects more than 85% of the people who receive and send email from Facebook.”

Michael Adkins, Facebook

“Implementing DMARC stopped nearly 25 million attempted attacks on our customers during the 2013 holiday season alone.”

Trent Adams, PayPay / Ebay, Chair of DMARC.org

Does it work?

Page 14: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

OrganizaPons Using DMARC

…Andthousandsmore

Page 15: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

The DMARC Standard

Page 16: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

DMARC Compass® is a key component of a comprehensive online Brand Protection

strategy.

Page 17: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

What is Needed for Complete Visibility?

Pu_ng DMARC into Context

% of Incidents from DMARC?

<20% Hacked

Sites

Social Media

Fraudulent Domains

DMARC

Malware/Mobile Apps

Non-spoofed Phish

Active Monitoring

DMARC on its own is not a complete fraud strategy – but anything that provides some visibility is a win. Make sure you have other layers in place to protect against these other threats.

Page 18: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

18

DMARC Compass™

Detect Monitoring Service™

Threat Reduction

Attack Deactivation

DMARC Within a Brand ProtecPon Framework

Page 19: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

19

*2014,Top40USBank

Why Easy SoluPons?

Page 20: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

Learn more: DMARC Compass Contact us: [email protected]

Questions?

Page 21: Who is Using Your Domain for Phishing & Spam - TAG … is Using Your Domain for Phishing & Spam? ... Untrusted Emails Fraud Expenses ... Any email sender

Sources: 1.  http://www.radicati.com/wp/wp-content/uploads/2015/02/Email-Statistics-Report-2015-2019-

Executive-Summary.pdf 2. 

https://securelist.com/analysis/quarterly-spam-reports/69932/spam-and-phishing-in-the-first-quarter-of-2015/

3.  http://www.information-age.com/technology/security/123459514/think-you-can-spot-scam-97-people-wouldnt-know-phishing-email-if-it-hooked-them

4.  http://www.cmo.com/articles/2015/1/6/15_stats_marketing_ROI.html