If you get an email from a stranger wanting to join your LinkedIn network, you should think twice before clicking on it.
The same goes for emails with LinkedIn subject lines like “See Your Profile Views,” “Join my network,” or “Account Deactivation Request.”
Emails with LinkedIn subject lines are the number one phishing scam, according to a leading cybersecurity source.
“Last quarter, more than half of all social media-related phishing emails imitated LinkedIn messages,” says the anti-phishing site KnowBe4. “This trend has been increasing quarter over quarter, likely because there is a perception that they would be legitimate coming from a professional network.”
Each quarter, KnowBe4 compiles the 10 Most Clicked-On Email Phishing Subject Lines, based on data from millions of user accounts.
LinkedIn Is Number One Phishing Bait
Social media sites, with LinkedIn leading the way, are becoming the most popular phish bait for cybercriminals. According to this site, social media phishing attacks are up more than 70 percent.
“It feels good to ‘join my network’ or connect with someone in some way – that’s why social media phishing attacks are so successful,” says Stu Sjouwerman, CEO of KnowBe4. “Alerts containing security-related warnings come unexpectedly and can cause feelings of alarm. Messages such as ‘a new message’ or ‘a friend tagged a photo of you’ can make you feel special and entice you to click.”
It’s a big problem, says Sjouwerman, because many LinkedIn users have their accounts tied to their corporate email addresses.
“Such a high percentage increases corporate risk of a phishing attack, ransomware breach or other social engineering-related threat,” he writes.
After social media-related messages, subject lines related to password management were highest on the phishing list.
Top-Clicked Social Media Related Subjects in Q1 2019
- LinkedIn: Profile Views
- LinkedIn: Join my network
- LinkedIn: Add me to your network
- LinkedIn: Deactivation Request
- Login alert for Chrome on Motorola Moto X
- 55th Anniversary and Free Pizza
- Your Friend Tagged a Photo of You
- Facebook Password Reset Verification
- Your password was successfully reset
- New voice message at 1:23AM
Top 10 Most-Clicked General Email Subjects in Q1 2019
- Password Check Required Immediately
- De-activation of [[email]] in Process
- Urgent press release to all employees
- You Have A New Voicemail
- Back Up Your Emails
- Revised Vacation & Sick Time Policy
- UPS Label Delivery, 1ZBE312TNY00015011
- Please Read Important from Human Resources
- [[manager_name]] sent you a file on Box
- Important Message from [[company_name]] Admin
Most Common “In the Wild” Attacks
- eBay: [Important] Your account
- Google: Your photo has been successfully published
- Outlook/Microsoft: You're invited to share this calendar
- Secure Your Btc Wallet Now
- Amazon: Account Refund Verification Status
- Unusual sign-in activity
- Check Sent
- LinkedIn: LinkedIn Password Reset
- Warning: Unauthorized Software Detection
- Microsoft: You’ve been assigned a task!