Crossroads Cybersecurity Guide

Created by Art Bryman, Modified on Mon, 2 Mar at 10:11 AM by Art Bryman

How to Spot (and Dodge!) Today’s Sneakiest Digital Villains

Cybersecurity does not have to be confusing. This guide breaks down the most common types of email, text, web, and mobile attacks you might see. Each section includes simple explanations to help you recognize and avoid threats quickly.


Crossroads Security Checklist

  • Slow down and evaluate messages that demand urgency or secrecy.
  • Check the full email address, not just the display name.
  • Hover over links or long‑press on mobile devices to preview where they lead.
  • Never approve authentication prompts you did not initiate.
  • Use a password manager and set unique passwords for every account.
  • Enable Multi‑Factor Authentication whenever available.
  • Keep devices, browsers, and applications fully updated.
  • Report suspicious emails to the Information Services team at tticket@xrds.org or use the “Phish Alert Report” button in Outlook.


How to handle a Suspected Email Phish Attack (Mac)
How to handle a Suspected Email Phish Attack (Windows/Outlook)

TABLE OF CONTENTS


Email and Messaging Attacks

Phishing

Emails pretending to come from familiar organizations or services. The goal is usually to steal passwords, money, or sensitive information.

Spear Phishing

A more targeted version of phishing. Attackers use your correct name, role, or other personal details to appear legitimate.

Whaling

Aimed at high‑level staff. Messages are polished and professional, often involving financial requests.

Thread Hijacking

An attacker gains access to a mailbox and replies inside real email conversations with dangerous links or attachments.


Phone and Text Attacks

Smishing

Fraudulent text messages that impersonate delivery companies, banks, government agencies, or customer service teams.

Vishing

Scam phone calls claiming to be from HR, IT, your bank, or law enforcement. These calls often attempt to create pressure or urgency.

MFA Prompt Abuse

Endless login approval prompts designed to make you accidentally approve an unauthorized sign‑in.


Website and Browser Attacks

Spoofed or Clone Websites

Fake sites crafted to look identical to legitimate login pages. Entering your credentials sends them directly to attackers.

Typosquatting

Websites created under misspelled domain names intended to catch typing mistakes.

Malvertising

Malicious advertisements placed on otherwise safe websites that trigger harmful downloads.

Drive‑By Downloads

Malware that installs simply by visiting a compromised page, even without clicking anything.

Watering Hole Attacks

Attackers infect a reputable site known to be used frequently by a particular group, such as an organization or school community.


Mobile and QR‑Based Attacks

Quishing

QR codes placed on posters, tables, signs, or parking meters that lead to fake login pages or fraudulent payment forms.

Rogue Wi‑Fi or “Evil Twin” Networks

Look‑alike public Wi‑Fi hotspots created to capture passwords and activity.

SIM‑Swap Fraud

A phone number is transferred to an attacker’s SIM card so they can intercept text messages and reset accounts.

Sideloaded Apps

Applications installed outside official app stores that contain hidden malware or harmful permissions.


Account Takeover Techniques

Credential Stuffing

Attackers use large lists of previously leaked passwords to try logging in to accounts that may reuse the same credentials.

Password Spraying

Instead of guessing many passwords for a single user, attackers test one common password on many accounts.

Session Hijacking

Stealing browser session cookies to bypass the login process entirely.

Convincing users to grant access to a malicious third‑party app. This may give attackers ongoing access to email or files.


Malware and System‑Level Attacks

Ransomware

Malicious software that locks files or systems until a payment is made.

Trojans

Seemingly harmless programs containing hidden malicious code.

Worms and Viruses

Self‑replicating programs that spread across devices or networks.

Spyware and Keyloggers

Software designed to record keystrokes, screenshots, or browsing activity and send it to attackers.

Botnets

Large networks of infected devices controlled remotely for spam, credential attacks, or large‑scale disruptions.


Financial and Wire Transfer Scams

Business Email Compromise

Messages impersonating staff, vendors, or leadership requesting wire transfers, payment changes, or sensitive data.

CEO Fraud

Scammers pretend to be leadership requesting urgent and confidential actions such as gift card purchases or wire transfers.

Vendor Email Compromise

A vendor’s email is compromised, and attackers send new “updated” payment instructions.

Invoice Fraud

Real invoices with swapped banking information sent to trick organizations into paying the wrong account.

Charity and Disaster Scams

Fraudulent donation pages created during crises or emergencies.


Infrastructure and Advanced Attacks

Denial‑of‑Service Attacks

Overwhelm websites or online services with traffic to make them unavailable.

DNS Hijacking or Poisoning

Redirects traffic from legitimate websites to malicious ones.

Supply‑Chain Compromise

Attackers infiltrate software updates or trusted vendors to indirectly reach their targets.

Insider Threats

Data exposure caused intentionally or unintentionally by someone with authorized access.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons

Feedback sent

We appreciate your effort and will try to fix the article