How to Improve Phishing Detection Using the SLAM Method

There is a reason why phishing is usually at the top of the list for security awareness training. It has been the primary delivery method for all types of attacks for the last decade or two. Ransomware, credential theft, database breaches, and more launch via a phishing email.

Why has phishing remained such a significant threat for so long? Imtex states it’s because it continues to work. Scammers evolve their methods as technology progresses. They use AI-based tactics to make targeted phishing more efficient, for example.

If phishing didn’t continue working, then scammers would move on to another type of attack. But that hasn’t been the case. People continue to get tricked. They open malicious file attachments, click on dangerous links, and reveal passwords.

In May of 2021, phishing attacks increased by 281%. Then in June, they spiked another 284% higher.

Studies show that phishing detection skills wane as soon as 6 months after training. Employees begin forgetting what they’ve learned, and cybersecurity suffers.

Want to give employees a “hook” they can use for memory retention? Introduce the SLAM method of phishing identification.

What is the SLAM Method for Phishing Identification?

One of the mnemonic devices known to help people remember information is an acronym. SLAM is an acronym for checking an email message’s four key areas before trusting it.

These are:

S = Sender
L = Links
A = Attachments
M = Message text

By giving people the term “SLAM” to use, it’s quicker for them to check suspicious emails. This device helps them avoid missing something important. All they need to do is use the cues in the acronym.

Check the Sender

It’s essential to check the sender of an email thoroughly. Often scammers will either spoof an email address or use a look-alike. People often mistake a spoofed address for the real thing.

The email address domain in this phishing email below is “@emcom.bankofamerica.com.” The scammer is impersonating Bank of America. This is one way that scammers try to trick you, by putting the actual company’s URL inside their fake one.

fake email

You can see that the email is compelling. It has likely fooled many people into divulging their details. People applying for a credit card provide a Social Security Number, income, and more.

A quick search of the email address reveals it to be a scam. And a trap used in both email and SMS phishing attacks.

fake email 2

It only takes a few seconds to type an email address into Google. This allows you to see if scam warnings indicate a phishing email.

Hover Over Links Without Clicking

Hyperlinks are popular to use in emails. They can often get past antivirus/anti-malware filters. Those filters are looking for file attachments that contain malware. But a link to a malicious site doesn’t have any destructive code. Instead, it links to a place that does.

Links can be in the form of hyperlinked words, images, and buttons in an email. When on a computer, it’s important to hover over links without clicking on them to reveal the true URL. This can often immediately call out a fake email scam.

fake email 3

When looking at email on a mobile device, seeing the URL without clicking on it can be trickier. There is no mouse like there is with a PC. In this case, it’s best not to click the URL. Instead, go to the purported site to check the message’s validity.

Never Open Unexpected or Strange File Attachments

File attachments are still widely used in phishing emails. Messages may have them attached, promising a large sale order. The recipient might see a familiar Word document and open it without thinking.

It’s getting harder to know what file formats to avoid opening. Cybercriminals have become savvier about infecting all types of documents with malware. There have even been PDFs with malware embedded.

Never open strange or unexpected file attachments. Use an antivirus/anti-malware application to scan all attachments before opening.

Read the Message Carefully

We’ve gotten great at scanning through text as technology has progressed. It helps us quickly process a lot of incoming information each day. But if you rush through a phishing email, you can miss some telltale signs that it’s a fake.

Look at the phishing example posted above in the “Links” section. There is a slight error in grammar in the second sentence. Did you spot it?

It says, “We confirmation that your item has shipped,” instead of “We confirm that your item has shipped.” These types of errors can be hard to spot but are a big red flag that the email is not legitimate

Get Help Combatting Phishing Attacks

Both awareness training and security software can improve your defences against phishing attacks. Contact us today to discuss your email security needs.

The article was used with permission from The Technology Press.

Like this article?

Share on Facebook
Share on Twitter
Share on Linkdin
Share on Pinterest

Related Posts

Free web design user interface website illustration

Is Your Business Website a Security Risk?

Summary: Most small-business websites run on WordPress, and the biggest risk is usually old plugins that nobody has updated. Attackers scan the web for these known weak spots and use the sites they find to spread malware, post spam, or steal what visitors type into forms. Keeping the site and its plugins updated, and knowing

Yet another performance boost for Windows 11

Yet another performance boost for Windows 11

It’s amazing how much time disappears into tiny little delays during the day.
Waiting for folders to open… switching between apps… clicking something twice because Windows didn’t respond the first time.
Microsoft seems to have finally realized those small frustrations are more important than flashy features…

Justifying security investment when nothing has happened

Justifying security investment when nothing has happened

One of the hardest parts of security planning is explaining the value before anything goes wrong.
Because if the environment is stable and incidents aren’t happening, it can look like everything is already covered.
So how do you make sure those conversations are successful…?

Free seo search engine optimization google illustration

Why You Should Scroll Past the First Result on Google

Summary: Scammers buy ads on Google and other search engines using the names of trusted brands and software, so their fake site shows up at the very top, above the real one. Click it and you can land on a fake page that steals your login or installs malware. You can avoid nearly all of

Should your business use an AI voice assistant?

Should your business use an AI voice assistant?

How much of your team’s day disappears into answering the same phone questions time and again?
There’s a new wave of technology starting to change that.
Some businesses are saving serious time with it already…