HomeNewsArticle Display

AFCYBER evaluates Airmen with spear-phishing emails

JOINT BASE SAN ANTONIO-Lackland, Texas (AFNS) -- Air Forces Cyber conducted a mock spear-phishing test on European bases in November to assess Air Force Network users’ cyber awareness.

The test, coordinated with U.S. Air Forces in Europe leaders, incorporated techniques known to be employed by adversary actors against U.S. and partner nations, for the purpose of gaining a foothold inside our networks.

“Spear-phishing attacks are a persistent threat to the integrity of our networks,” said Col. Anthony Thomas, AFCYBER Operations director. “Even one user falling for a spear-phishing attempt creates an opening for our adversaries. Part of mission resiliency is ensuring our Airmen have the proficiency to recognize and thwart adversary actions.”

Spear-phishing attacks differ from normal phishing attempts because they target a specific recipient and appear to be from a trusted source.

For the test, AFCYBER’s threat emulation team sent several emails from non-Department of Defense email addresses to network users. These emails included legitimate-looking content, mirroring tactics used by cyber adversaries. The emails provided a variety of scenarios, urging Airmen to follow certain steps.

One email appeared to come from an Airman & Family Readiness Center, asking users to update a hyperlinked spreadsheet for an upcoming sale. Another email claimed to be from a legal office, and requested users to provide data in a hyperlinked document for a court-martial jury panel.

If users followed the hyperlink, then downloaded and enabled macros in the documents, embedded code would be activated. This allowed the threat emulation team access to their computer.

According to Maj. Ken Malloy, AFCYBER’s primary planning coordinator for the assessment, attacks by state-sponsored groups are sophisticated and can catch users unaware if they’re not paying attention.

“We chose to conduct this threat emulation (test) to gain a deeper understanding of our collective cyber discipline and readiness,” said Malloy. “Lessons from our efforts in USAFE will inform data-driven decisions for improving policy, streamlining processes and enhancing threat-based user training to achieve mission assurance and promote the delivery of decisive air power.”

Results from the test showed most recipients did not fall for the emails. According to the team, the test did not collect individual user information, as it was designed to improve the network’s overall defensive posture.

To protect the network from cyber threats, users should verify every email’s source by verifying that emails from official sources have valid digital signatures. Any embedded links should produce a secure connection, represented by a padlock icon in the browser’s search bar. Users should not enable macros in Microsoft Office documents downloaded from non-DOD sources.

While this initial assessment was conducted specifically in the European theater, Malloy said spear-phishing attempts remain a constant threat to all AFNet users. Users should always be cautious and vigilant. If a malicious email is suspected, users should contact their local communications focal point for guidance.

Engage

Facebook Twitter
.@Offutt_AFB #Airmen worked around the clock to fortify facilities w/ 235,000+ sandbags and 460 flood barriers, min… https://t.co/Hw45u8RNhT
This new laser cleans up corrosion & helps @AndersenAFBGuam #Airmen get the mission done faster, cheaper, & more sa… https://t.co/cmMz6wQvaF
.@HQUSAFEPA works to thwart Norway's tolls, upgrades fleet to #electricvehicles saving approximately $4000 per year… https://t.co/m3GU8q34aZ
#Airmen & #Soldiers deployed to two different installations in #Qatar combine optometry capabilities to ensure serv… https://t.co/SgRGYCiInG
Welcome to the fleet, Ghostrider! The 4th Special Operations Squadron is now home to @AFSpecOpsCmd’s newest aircraf… https://t.co/teNYuXnFh0
.@TeamMinot celebrates equality this #WomensHistoryMonth by hosting an all-women’s missile alert.… https://t.co/2379t1LIZm
.@US_EUCOM received a Bomber Task Force of #B52s, #Airmen and equipment in preparation for joint and allied theater… https://t.co/itIF3lxCcA
Hear #Airmen of the 774th Expeditionary Airlift Squadron share what the #C130J mission means to them. https://t.co/MifPeiclpP
.@ScottAFB #Airmen use their love of the game to even the battlefield both on and off the court. https://t.co/ul1Z33LV2t
Are you getting enough Zzs 😴 at night? If not, try these simple changes throughout the day to sleep more restfully… https://t.co/ppAAtT6bgK
.@KunsanAirBase dental #Airmen are supporting a high readiness status using a #CEREC, a machine that produces custo… https://t.co/ULji8m6wMs
.@RAFMildenhall's #innovative improvement to their dorm key system saves money and time, and improves security. https://t.co/hmB0BEmx9F
#USAF and @USNavy partner to complete missions around the world. Watch how #Airmen and #Sailors use #airpower to de… https://t.co/GULcztQL0C
RT @PACAF: #COMPACAF and multinational #5thgen experts had the opportunity to experience an #F35 simulator in #Hawaii. #interoperability #R
These @341MissileWing #Airmen braved sub-zero temperatures and frigid, heavy snow to save a citizen stranded in a s… https://t.co/qeMSUoVbNy
.@grandslamwing has some real SLICC #Airmen, who provide communications in the sky. Watch how: @USAFCENT @CENTCOM https://t.co/oEkz70r0n1
.@Travis60AMW and @USAScienceFest hosted 600+ middle school students for this #XSTEM event, where #airpower was use… https://t.co/XGbEsE3Gs6
On today's #ThrowbackThursday, we remember all the #LadiesofLiberty #Airmen who help make our mission possible.… https://t.co/DRv3XKHd6a