Share this article
If there’s one thing we must concede when talking about hackers, cybercriminals and fraudsters out in the world today, it’s that they are talented opportunists. I was reminded of this fact only recently myself when I was targeted by a phishing scam that very nearly lured me in.
Even as an experienced professional with many years’ experience in running a cybersecurity business, it can be difficult to spot the genuine emails from the fictitious ones. Often, it’s only those deeply ingrained defence mechanisms and distrust of anything not from a well-known source that protects one from falling victim to a scam.
My own recent experience took place in early February – in the days after Newcastle United had beaten Southampton to reach the EFL Cup Final against Manchester United. Coming from a family of Newcastle fans I was delighted to see my team compete for silverware for the first time in many years. And I wasn’t at all surprised to see that many ticketing platforms and corporate hospitality companies were beginning to advertise packages for the upcoming match.
So, when my own inbox pinged with a message from a seemingly reputable hospitality company called Corinthian Group, my interest was piqued. The email offered what seemed like a reasonable package for a box at the cup final – with enough tickets to share between a number of family members, friends and colleagues.
I should also point out that the name of the business wasn’t entirely unfamiliar. As a sports fan I’d often had dealings with Corinthian when they’d had tickets for big events such as Wimbledon or an England test cricket match.
However, my natural instincts and years of training led me (as always) to do some due diligence before pursuing further and supplying any bank details. I searched for Corinthian Group online and all seemed fine. What I found was a slick, professional looking site with an array of services on offer and offices listed in London, Birmingham and Abu Dhabi.
Just before clicking away from the website I did note that the footer featured the line “Corinthian Group is a trading name of Darcella Ltd”. This isn’t entirely unusual, of course. Plenty of organisations have a complex corporate hierarchy with various registered company names. But when I Googled the name Darcella Ltd, I quickly found a link to the website of Corinthian Sports, which featured a “Fraud Warning Update”.
At this point, the penny dropped for me.
The company I had dealt with in the past was, in fact, Corinthian Sports and the business known as Corinthian Group was not an organisation that I’d ever had direct dealings with – and it should not have had access to my email address for marketing purposes.
I immediately made contact with Corinthian Sports and was reassured to hear that they – a reputable hospitality experience company – were very helpful and were aware that a company was promoting sporting events to which they did not have access to tickets. The Corinthian Sports team also taking steps to address their activities.
In sharing with them my intention to document my experience their Director, Mark Hoskins, offered this advice to anyone looking to distinguish between reputable vendors and unscrupulous ones:
“At Corinthian Sports we understand the importance of offering a transparent and trustworthy experience for customers. Before parting with any cash in exchange for tickets or hospitality packages we would always recommend taking the time to ensure that the venues advertised have provided their logos to be used on the vendor’s website.
We also feature Google reviews prominently on our website and encourage customers to share their experiences to help others know that we deliver on the service we advertise.”
The truth is that this kind of scam takes place every day in some shape or form. In this instance, my guess would be that Newcastle reaching the cup final acted as a trigger for fraudsters to begin messaging directors and senior managers within North East businesses, knowing that they were likely to attract interest from local fans. After all, what better way to lure people in than to offer something that they know would be in high demand.
Although the outcome of my experience was a positive one – if you ignore the fact that Newcastle United lost their cup final! – I know only too well that thousands of people fall foul of such tactics every week. What I would say is that taking precautions and being prepared to question the validity of any correspondence is always important within an organisation.
If you aren’t confident that your employees are sufficiently prepared to deal with daily phishing attacks or social engineering efforts, my advice would be to invest in training and work with experts in this field – like those in my team here at SRM.
Want to find out more? Contact us.