Story image

Can you spot the phish? Google's quiz puts you to the test

24 Jan 2019

There’s an old adage that humans are the weakest link in cybersecurity – but they can also be one of the strongest links if they’re able to identify security risks.

Google’s parent firm Jigsaw has come up with one way of helping people hone their phishing skills. It devised an eight-question quiz in which people must differentiate genuine emails from fake ones.

It may not be as easy as many people think – after the participant selects an answer, the quiz then offers a ‘show me’ option that explains exactly why the example would be genuine or fake.

The examples include document shares appearing to be through Google Drive, links to downloads from fax machines, Dropbox notifications, Google logins, permissions requests, and more.

According to Jigsaw, “We created this quiz based on the security trainings we’ve held with nearly 10,000 journalists, activists, and political leaders around the world from Ukraine to Syria to Ecuador. We’ve studied the latest techniques attackers use, and designed the quiz to teach people how to spot them.”

There’s undoubtedly a need for more training simulations like this one – Symantec’s 2018 Internet Security Threat Report found that 71% of all targeted attacks started with spear phishing to infect victims’ systems. 

F5 Networks’ 2018 Phishing and Fraud Report presented similar findings – 71% of phishing attacks between September 1 2018 and October 31 2018 impersonated 10 high-profile organisations. The report also said that phishing was the root cause in almost half of the breach cases F5 investigated.

No matter which statistics you dig up, the message is almost the same: phishing emails are still sent by the masses, and they’re still tricking people.

“Some of the most famous examples of hacking and cyber-theft began with phishing. In 2016 hackers affiliated with the Russian intelligence services sent a carefully crafted spear-phishing email to John Podesta, Hillary Clinton’s campaign manager, and (because he didn’t have two-factor authentication enabled) they gained access to his email account,” says Jigsaw.

At the end of the quiz, Jigsaw helpfully redirects participants to a page that encourages people to turn on two-factor authentication (it’s a genuine request).

“When you have two-factor authentication enabled, even if an attacker successfully steals your password they won’t be able to access your account. We also offer a Chrome extension called Password Alert that protects you from entering your Google password in a fake login page,” says Jigsaw.

Try the quiz at https://phishingquiz.withgoogle.com/.

Earth Day 2019: How tech firms can support our planet's wellbeing
Six industry experts explain how they - and other tech organisations - can positively contribute to the wellbeing of our earth.
CyrusOne signs up three new senior execs for Europe
CyrusOne has appointed three new senior hires in its growing Europe-based team, including a new area vice president, engineering solutions director, and business development manager.
Dell EMC’s six server market trends
As the evolution of cloud-based computing continues, it is important to know what’s ahead to stay ahead of the market.
Park Place Technologies hires new EMEA managing director
Post-warranty data centre maintenance company Park Place Technologies has recruited Sean Sears as its new managing director for Europe, the Middle East and Africa.
Huawei FusionServer Pro built for 'intelligent transformation'
The next generation X86 servers draw on an intelligent acceleration engine, an intelligent management ending, and intelligent data center solutions for ‘diverse’ scenarios as transformation shifts from digital to intelligent.
HFW deploys digital edge strategy on Equinix
Equinix announced that global law firm HFW has collaborated with Equinix to build out its digital edge in key markets including Dubai, London, Hong Kong, Melbourne and Paris.
DE-CIX and Datacenter One sign service deal for Germany
Datacenter One’s LEV1 data centre in Leverkusen is the first to be connected to DE-CIX, with further DE-CIX sites to be created in the next few years as part of the agreement.
Teradata expands as-a-service offerings for Advantage platform
Data intelligence company Teradata has announced three new cloud and on-premise solutions that are now integrated into its Teradata Vantage platform.