
In recent months, the number of attacks targeting smartphones to gain access and compromise corporate networks.
An analysis by Lookout showed that there has been a 37% increase in mobile phishing attacks during the last three months of 2019 and the first months of 2020.
Phishing emails are a major problem for desktop and laptop users . But now, they should also be a concern for smartphone users. The increase in attacks coincides with the time when the whole world was quarantined and working remotely. As many people also used smartphones for their work, hackers began targeting both Android and iOS phones.
Phishing attacks on desktops can leave some telltale signs that something is amiss (you can preview links and attachments, or view email addresses and URLs). However, the verification process is not as easy on mobile email, social media, and messaging apps on smartphones.
“It’s difficult to detect signs that we would normally detect on a laptop or desktop computer because of the very small screen,” said Hank Schless, an executive at Lookout.
“Because we can’t preview links, see full URLs, and quickly open anything that comes up, malicious hackers invest their time and energy into making these campaigns undetectable to the untrained eye.”

In many cases, attackers design fake login pages that look authentic. If a user enters credentials on a phishing page via their smartphone, the data will be sent to hackers. The attackers then gain access to corporate accounts .
Mobile phishing attacks against personal accounts are also on the rise. Attackers are exploiting smartphones and mobile browsers to steal credentials , banking information, and other personal data.
Lookout discovered a campaign that sent mass phishing emails to customers of a major Canadian bank. The emails asked customers to log in to their accounts, directing them to pages that looked identical to the real ones.
According to Schless, phishing attacks on smartphones will become even more sophisticated and even more difficult to detect.
Hackers have realized that they can exploit devices (like smartphones) that are not protected by traditional corporate security policies, allowing them to gain access to an organization's infrastructure.
Defending against mobile phishing attacks can be difficult. However, educating employees can help. Organizations could also consider using a system security mobilethat does not overstep the boundaries of user privacy.
“Ideally, the solution should not screen content and should only notify the person when they encounter a malicious link. It should also automatically block anything malicious,” Schless said.
