CAMS · Question #947
A customer of a financial Institution (Fl) complained that they had received multiple emails appearing to originate from the Fl urging them to click on a link or open a remittance attachment for…
The correct answer is D. Spear phishing. This scenario describes a targeted email-based attack where a customer was deceived into opening a malicious attachment, resulting in unauthorized fund transfers from their bank account.
Question
A customer of a financial Institution (Fl) complained that they had received multiple emails appearing to originate from the Fl urging them to click on a link or open a remittance attachment for confirmation. After opening the attachment, the customer later realized that funds had been systematically transferred out of their bank account without their knowledge Which type of cybercrime is described in this scenario?
Options
- AVishing
- BPharming
- CSMSishing
- DSpear phishing
How the community answered
(41 responses)- A12% (5)
- B7% (3)
- C2% (1)
- D78% (32)
Why each option
This scenario describes a targeted email-based attack where a customer was deceived into opening a malicious attachment, resulting in unauthorized fund transfers from their bank account.
Vishing refers to voice phishing conducted via telephone calls, not email-based deception involving malicious attachments.
Pharming involves redirecting users from legitimate websites to fraudulent ones by corrupting DNS settings or hosts files, not through deceptive emails with attachments.
SMSishing is phishing conducted via SMS text messages, not via email.
Spear phishing is a targeted form of phishing that uses personalized emails appearing to originate from a trusted source - such as the victim's own financial institution - to trick the recipient into opening malicious attachments or links. Unlike generic phishing, spear phishing is directed at a specific individual or organization, and the goal of stealing banking credentials or initiating unauthorized transfers is a defining characteristic of this attack type.
Concept tested: Identifying spear phishing as a targeted cybercrime method
Source: https://csrc.nist.gov/glossary/term/spear_phishing
Topics
Community Discussion
No community discussion yet for this question.