How to Spot (and Dodge!) Today’s Sneakiest Digital Villains
Crossroads Security Checklist
- Slow down and evaluate messages that demand urgency or secrecy.
- Check the full email address, not just the display name.
- Hover over links or long‑press on mobile devices to preview where they lead.
- Never approve authentication prompts you did not initiate.
- Use a password manager and set unique passwords for every account.
- Enable Multi‑Factor Authentication whenever available.
- Keep devices, browsers, and applications fully updated.
- Report suspicious emails to the Information Services team at tticket@xrds.org or use the “Phish Alert Report” button in Outlook.
How to handle a Suspected Email Phish Attack (Mac) How to handle a Suspected Email Phish Attack (Windows/Outlook)
TABLE OF CONTENTS
- Email and Messaging Attacks
- Phone and Text Attacks
- Website and Browser Attacks
- Mobile and QR‑Based Attacks
- Account Takeover Techniques
- Malware and System‑Level Attacks
- Financial and Wire Transfer Scams
- Infrastructure and Advanced Attacks
- Crossroads Security Checklist
Email and Messaging Attacks
Phishing
Emails pretending to come from familiar organizations or services. The goal is usually to steal passwords, money, or sensitive information.
Spear Phishing
A more targeted version of phishing. Attackers use your correct name, role, or other personal details to appear legitimate.
Whaling
Aimed at high‑level staff. Messages are polished and professional, often involving financial requests.
Thread Hijacking
An attacker gains access to a mailbox and replies inside real email conversations with dangerous links or attachments.
Phone and Text Attacks
Smishing
Fraudulent text messages that impersonate delivery companies, banks, government agencies, or customer service teams.
Vishing
Scam phone calls claiming to be from HR, IT, your bank, or law enforcement. These calls often attempt to create pressure or urgency.
MFA Prompt Abuse
Endless login approval prompts designed to make you accidentally approve an unauthorized sign‑in.
Website and Browser Attacks
Spoofed or Clone Websites
Fake sites crafted to look identical to legitimate login pages. Entering your credentials sends them directly to attackers.
Typosquatting
Websites created under misspelled domain names intended to catch typing mistakes.
Malvertising
Malicious advertisements placed on otherwise safe websites that trigger harmful downloads.
Drive‑By Downloads
Malware that installs simply by visiting a compromised page, even without clicking anything.
Watering Hole Attacks
Attackers infect a reputable site known to be used frequently by a particular group, such as an organization or school community.
Mobile and QR‑Based Attacks
Quishing
QR codes placed on posters, tables, signs, or parking meters that lead to fake login pages or fraudulent payment forms.
Rogue Wi‑Fi or “Evil Twin” Networks
Look‑alike public Wi‑Fi hotspots created to capture passwords and activity.
SIM‑Swap Fraud
A phone number is transferred to an attacker’s SIM card so they can intercept text messages and reset accounts.
Sideloaded Apps
Applications installed outside official app stores that contain hidden malware or harmful permissions.
Account Takeover Techniques
Credential Stuffing
Attackers use large lists of previously leaked passwords to try logging in to accounts that may reuse the same credentials.
Password Spraying
Instead of guessing many passwords for a single user, attackers test one common password on many accounts.
Session Hijacking
Stealing browser session cookies to bypass the login process entirely.
OAuth Consent Phishing
Convincing users to grant access to a malicious third‑party app. This may give attackers ongoing access to email or files.
Malware and System‑Level Attacks
Ransomware
Malicious software that locks files or systems until a payment is made.
Trojans
Seemingly harmless programs containing hidden malicious code.
Worms and Viruses
Self‑replicating programs that spread across devices or networks.
Spyware and Keyloggers
Software designed to record keystrokes, screenshots, or browsing activity and send it to attackers.
Botnets
Large networks of infected devices controlled remotely for spam, credential attacks, or large‑scale disruptions.
Financial and Wire Transfer Scams
Business Email Compromise
Messages impersonating staff, vendors, or leadership requesting wire transfers, payment changes, or sensitive data.
CEO Fraud
Scammers pretend to be leadership requesting urgent and confidential actions such as gift card purchases or wire transfers.
Vendor Email Compromise
A vendor’s email is compromised, and attackers send new “updated” payment instructions.
Invoice Fraud
Real invoices with swapped banking information sent to trick organizations into paying the wrong account.
Charity and Disaster Scams
Fraudulent donation pages created during crises or emergencies.
Infrastructure and Advanced Attacks
Denial‑of‑Service Attacks
Overwhelm websites or online services with traffic to make them unavailable.
DNS Hijacking or Poisoning
Redirects traffic from legitimate websites to malicious ones.
Supply‑Chain Compromise
Attackers infiltrate software updates or trusted vendors to indirectly reach their targets.
Insider Threats
Data exposure caused intentionally or unintentionally by someone with authorized access.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article