Linchakin

Phishing Reported in IKEA’s Internal Email System

 November 29, 2021     No comments   

IKEA Phishing EmailIKEA has been working to contain a continuing phishing campaign that’s afflicting the furniture and houseware chain’s internal email system. BleepingComputer describes it as a “reply-chain email attack.” This form of attack is unusual but not unknown. The attackers obtain a legitimate corporate email and reply to it. “As the reply-chain emails are legitimate emails from a company,” BleepingComputer explains, “and are commonly sent from compromised email accounts and internal servers, recipients will trust the email and be more likely to open the malicious documents.”

"There is an ongoing cyber-attack that is targeting Inter IKEA mailboxes. Other IKEA organisations, suppliers, and business partners are compromised by the same attack and are further spreading malicious emails to persons in Inter IKEA," explained an internal email sent to IKEA employees and seen by BleepingComputer.

"This means that the attack can come via email from someone that you work with, from any external organisation, and as a reply to an already ongoing conversations. It is therefore difficult to detect, for which we ask you to be extra cautious."

The malicious emails have tended to trip filters designed to quarantine threats. But they’re convincing enough to induce employees to release them, quite innocently, from quarantine. IKEA is taking steps to preclude that possibility. IKEA has explained this to the retailer’s employees:

"Our email filters can identify some of the malicious emails and quarantine them. Due to that the email could be a reply to an ongoing conversation, it's easy to think that the email filter made a mistake and release the email from quarantine. We are therefore until further notice disabling the possibility for everyone to release emails from quarantine.”

As is usually the case, a trained and well-informed employee seems to be the final line of defense. The malicious reply-chain emails do carry certain marks that might alert employees to the possibility they’re being subjected to phishing, and IKEA is working to raise awareness of those marks. For one thing, the links the phishing emails contain end with seven digits.

How the attackers have succeeded in compromising the email accounts isn’t clear. In other cases attackers have exploited ProxyShell and ProxyLogin vulnerabilities to compromise Microsoft Exchange Servers. IKEA has been tight-lipped about the incident, and it’s unknown whether the company’s internal servers were compromised.

New-school security awareness training can help your employees become alert to the threat posed by reply-chain attacks. BleepingComputer has the story.

Adblock test (Why?)


You may be interested in:
>> Is a Chromebook worth replacing a Windows laptop?
>> Find out in detail the outstanding features of Google Pixel 4a
>> Top 7 best earbuds you should not miss

Related Posts:
>> Recognizing 12 Basic Body Shapes To Choose Better Clothes
>>Ranking the 10 most used smart technology devices
>> Top 5+ Best E-readers: Compact & Convenient Pen
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Email ThisBlogThis!Share to XShare to Facebook

Related Posts:

  • Best Raspberry Pi Black Friday Deals for 2021ByAvram Piltch 01 November 2021You can find savings not Raspberry Pi products and accessories in time for... With more than 40 million units sold and a powerful community of makers and fans behind it, Raspberry Pi is more than a single-board computer; it's a… Read More
  • Intel Posts XMP 3.0 DDR5 QVL for Alder Lake CPUsByZhiye Liu 01 November 2021New Intel document details DDR5 memory kits that have been validated for t... Intel has shared a new document that lists the DDR5 memory kits validated on the chipmaker's Alder Lake platform that will soon vie for a spot on our… Read More
  • 1st Nov - Typography in Bootstrap 4In this article, we will understand about the typography in Bootstrap 4. What do you mean by Typography in Bootstrap 4. In Bootstrap 4, Typography is … Read More
  • 1st Nov - How to secure your home wireless network routerIn your house, you most likely have a wifi router that allows everyone in the family to connect to the internet. People often ask for the password whe… Read More
  • Best Black Friday Dell and Alienware Deals: Cheap Aurora Gaming PCs and XPS LaptopsByJason England 01 November 2021Dell has been dropping impressive P...Dell has been dropping impressive PC and laptop deals all year long, but Black Friday is here. It's time for the company to pull out the big guns. Fro… Read More
Newer Post Older Post Home

0 Comments:

Post a Comment


Copyright © 2025 Linchakin | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates