HomeNewsArticle Display

AFCYBER evaluates Airmen with spear-phishing emails

JOINT BASE SAN ANTONIO-Lackland, Texas (AFNS) -- Air Forces Cyber conducted a mock spear-phishing test on European bases in November to assess Air Force Network users’ cyber awareness.

The test, coordinated with U.S. Air Forces in Europe leaders, incorporated techniques known to be employed by adversary actors against U.S. and partner nations, for the purpose of gaining a foothold inside our networks.

“Spear-phishing attacks are a persistent threat to the integrity of our networks,” said Col. Anthony Thomas, AFCYBER Operations director. “Even one user falling for a spear-phishing attempt creates an opening for our adversaries. Part of mission resiliency is ensuring our Airmen have the proficiency to recognize and thwart adversary actions.”

Spear-phishing attacks differ from normal phishing attempts because they target a specific recipient and appear to be from a trusted source.

For the test, AFCYBER’s threat emulation team sent several emails from non-Department of Defense email addresses to network users. These emails included legitimate-looking content, mirroring tactics used by cyber adversaries. The emails provided a variety of scenarios, urging Airmen to follow certain steps.

One email appeared to come from an Airman & Family Readiness Center, asking users to update a hyperlinked spreadsheet for an upcoming sale. Another email claimed to be from a legal office, and requested users to provide data in a hyperlinked document for a court-martial jury panel.

If users followed the hyperlink, then downloaded and enabled macros in the documents, embedded code would be activated. This allowed the threat emulation team access to their computer.

According to Maj. Ken Malloy, AFCYBER’s primary planning coordinator for the assessment, attacks by state-sponsored groups are sophisticated and can catch users unaware if they’re not paying attention.

“We chose to conduct this threat emulation (test) to gain a deeper understanding of our collective cyber discipline and readiness,” said Malloy. “Lessons from our efforts in USAFE will inform data-driven decisions for improving policy, streamlining processes and enhancing threat-based user training to achieve mission assurance and promote the delivery of decisive air power.”

Results from the test showed most recipients did not fall for the emails. According to the team, the test did not collect individual user information, as it was designed to improve the network’s overall defensive posture.

To protect the network from cyber threats, users should verify every email’s source by verifying that emails from official sources have valid digital signatures. Any embedded links should produce a secure connection, represented by a padlock icon in the browser’s search bar. Users should not enable macros in Microsoft Office documents downloaded from non-DOD sources.

While this initial assessment was conducted specifically in the European theater, Malloy said spear-phishing attempts remain a constant threat to all AFNet users. Users should always be cautious and vigilant. If a malicious email is suspected, users should contact their local communications focal point for guidance.

Engage

Twitter
RT @AETCommand: Learning Professionals across the @usairforce can now register for the #AirForce Learning Professionals Consortium. The eve…
Twitter
Esther McGowin Blake 🛩️ Blake was the first woman in the U.S. Air Force, enlisting on the first minute of the fir… https://t.co/kUI5jYlWzq
Twitter
RT @cmsaf_official: It’s true though. Have a fantastic Monday, folks! https://t.co/q2cgZvmaTX
Twitter
#ICYMI Department of the Air Force PT tests were pushed to July. Updates to scoring and physical components are ahe… https://t.co/Gn7fIr0JF6
Twitter
RT @GenCQBrownJr: Thank you to @MEaglen for the recent discussion on how the @USAirForce is #acceleratingchange. https://t.co/Ycx8dLWUwS
Twitter
Hang in there. Spring is around the corner. Icing in any of its forms can add weight to the aircraft, decrease th… https://t.co/U3NA0pqFiM
Twitter
RT @USAFCENT: It’s important for U.S. AFCENT to work with effective, capable partners to advance the security and stability in the region.…
Twitter
.@179AW members recently deployed in support of Operation Spartan Shield. OSS is a @USAFCENT joint forces operation… https://t.co/qeJnOgPT1l
Twitter
#Airmen and #Guardians! Don't forget to register for the Department of the Air Force's virtual Women’s Air and Spac… https://t.co/fHrRzsi4rC
Twitter
Medical professionals administer the Moderna #COVID19Vaccine at Kadena Air Base, Japan. Kadena AB continues to admi… https://t.co/SWw70MsNwf
Twitter
#AccelerateChange or Lose Action Order B: Bureaucracy. Learn more about the Action Orders here:… https://t.co/On0LRHOOf5
Twitter
RT @AFSpecOpsCmd: Special Tactics operators from the 24th SOW participated in a personnel recovery training mission during #EmeraldWarrior
Twitter
RT @cmsaf_official: It is my honor to be a part of this incredible event at the @AFmuseum. To see an exhibit celebrating the accomplishment…
Twitter
Check out the latest Air Force Week in Photos! Which is your favorite? See more the 🔗: https://t.co/EJKDIKhaE7 https://t.co/iQXfYWBA0w
Twitter
.@KadenaAirBase Airmen train with a #CV22Osprey during exercise Gryphon Jet 21 @374AirliftWing. Gryphon Jet exercis… https://t.co/vhR2nGmjMM
Twitter
#DYK On Sept. 26, 2005, the first all-female C-130 Hercules crew flew in combat. They were assigned to the 737th Ex… https://t.co/0F9vT7bgDz
Twitter
As part of @AETCommand's efforts to #AccelerateChange, Airmen and Guardians can access the “myLearning” digital pla… https://t.co/mAaG4pK8vi
Facebook
The newest Air Force Podcast recently dropped. Listen to a small snippet of CMSAF Kaleth O. Wright talk with Staff Sgt. New about resiliency. Listen to the entire podcast on Youtube: https://go.usa.gov/xpnAD or Subscribe to The Air Force Podcast on iTunes: https://podcasts.apple.com/podcast/the-air-force-podcast/id1264107694?mt=2
Facebook
Our mantra, "Always ready!" It's the spirit we fly by! #B2Tuesday
Facebook
Need some motivation to get your week started off right? Listen as CMSAF Kaleth O. Wright weighs in...
Facebook
The U.S. Air Force Academy gives its cadets some unique opportunities. Ride along one of this opportunities.
Facebook
A United States Air Force KC-135 Stratotanker refuels an F-22 Raptor over northern Iraq, Nov. 6, 2019. U.S. Central Command operations deter adversaries and demonstrate support for allies and partners in the region. (Video by Staff Sgt. Daniel Snider)
Facebook
Although the Silver Star is the third-highest military medal, it's not given often. Today, TSgt Cody Smith was the 49th Special Tactics Airman to receive this medal since Sept. 11th, 2001. Read more of TSgt Smith's amazing story: https://www.airforcespecialtactics.af.mil/News/Article-Display/Article/2024815/special-tactics-airman-battled-through-injuries-awarded-silver-star/fbclid/IwAR2LZWwx1VHdTnQe39rIEBOuJS_0JvMQBBGt7I-E6zsxxn-Lx9387yu43Bc/ Cannon Air Force Base Air Force Special Operations Command United States Special Operations Command (USSOCOM) U.S. Department of Defense (DoD)
Facebook
Tune in as our Air Force musicians along with other military musicians are awarded the National Medal of Arts.
Facebook
Like Us
Twitter
1,332,302
Follow Us