Section 5.43 Frauds and Scams Flashcards
Objectives 2.2 Explain common threat vectors and attack surfaces Objectives 5.6 Given a scenario, implement security awareness practices
Fraud
Wrongful or criminal deception that is intended to result in financial or personal gain for the attacker
Fraud: You are being tricked to hand over money/information
Common types of fraud
- Identity Fraud
- Identity Theft
Involves the use of another person’s personal information without their authorisation to commit a crime or to deceive or defraud that other person or some other third party
Identity Fraud
In identity fraud, the attacker takes the victim’s credit card number and charges items to the card
Identity Theft
In identity theft, the attacker tries to fully assume the identity of their victim
Scams
Fraudulent or deceptive act or operation
Most common scam is called the invoice scam
Invoice Scam
In which a person is tricked into paying for a fake invoice for a
product or service that they did not actually order
e.g Attacker send an invoice to billing depatment. Once the file is open the pdf uses embeded malicious code which allows attacker access using a remote access trojan.