Learn more about our phishing simulations and awareness training.
Discover how your business can benefit

Nikolas Rösener
Security Expert
- cyber-security@ohb-ds.de
- 0421220950
It is hard to imagine communication in the digital business world without email. In a matter of moments, digital messages—complete with attachments—can be sent from one end of the world to the other, enabling the efficient and global exchange of information. However, these advantages can also be exploited for malicious purposes:
Since sending and receiving emails has become an integral part of many people’s daily work routines, employees—and especially those in leadership positions—are particularly attractive targets for phishing attacks. If an attacker succeeds in deceiving the victim, depending on the goal of the attack, they can gain access to internal company data or the victim’s login credentials, or even take control of the target’s system and thus penetrate the internal network.
Attackers are usually motivated by financial gain, though in some cases their primary goal is simply to cause harm to a company. By injecting so-called ransomware—which grants access to the target’s system following a successful attack—the attacker encrypts the file system and then demands a ransom for decrypting the data. In scenarios where the attacker has obtained the victim’s login credentials or internal company information, these are usually used for further attacks or sold to third parties.
A well-crafted phishing email can appear deceptively genuine at first glance and prompt the victim to click the link before they even have a chance to question the email’s authenticity. However, there are several ways to verify the authenticity of a received email without much effort.
One telltale sign is the sender’s address. In most cases, the sender’s address is either obviously unfamiliar or differs only very subtly from trustworthy websites in the domain part—for example, by using letters that look similar. However, sophisticated attackers also try to distract the victim from the sender address by using fake sender names, or they exploit DNS misconfigurations to forge the sender address without the email being filtered or flagged as spam.
Another key indicator is the format of the email’s content. For example, if the email contains unusual formatting, outdated logos, or is written in a different language for no apparent reason, this could indicate a potential phishing attempt.
The most telling sign, however, is the content of the email you receive. For example, if you are asked to click on a link below and log in to complete a task, or if you are told to download and run a file, this can often indicate a potential scam. In such cases, you should first hover your mouse over the link to check which site it actually leads to, or verify the legitimacy of any attached files.
A common attack scenario is what is known as “credential harvesting,” in which an attacker clones the login page of a well-known service or one used by the company and hosts it on the internet. The email then contains a link to the cloned page, along with a request to log in to the service again for some reason. The goal here is for the phishing victim to enter their login credentials on the cloned page, which are sent to the attacker upon login attempt instead of logging the user in. To conceal the deception, after submitting their login credentials, the victim is redirected to the genuine login page of the respective service so that the next login attempt succeeds and no suspicion is aroused.
Another very common attack scenario involves malicious email attachments. Attackers typically distribute Microsoft Office files that can automatically execute malicious code on the victim’s system via macros. The goal of this attack scenario is to gain access to the phishing victim’s system through the executed malicious code. In current versions of Office products, however, macros are disabled by default and require the user to explicitly enable them by clicking a button in the warning. To trick the victim into taking this step, attackers may, for example, feign compatibility issues or similar problems to make it seem as though enabling the macros is necessary to edit or view the file. Furthermore, antivirus programs make it difficult for the malicious code to execute successfully by blocking the macro before execution if malicious signatures are detected. However, the macro can also act as a so-called “stager,” which first downloads the malicious code from a target server and then executes it on the system, making it harder for antivirus programs to detect and block the executed malicious code.
As mentioned earlier, attackers can exploit DNS misconfigurations to ensure that emails with forged sender addresses are still delivered and are not filtered out or flagged by spam filters. The DNS records that protect a domain against such tricks are “Sender Policy Framework” (SPF), “DomainKeys Identified Mail” (DKIM), and “Domain-based Message Authentication Reporting and Conformance” (DMARC). All three DNS records are created as TXT records and, when used in combination, can ensure the authenticity and integrity of sent and received emails and enable automated filtering of emails that violate the rules defined in the records. Additionally, such incidents can also be reported simultaneously to a designated email address. Another technical measure for protection against phishing attacks is the use of antivirus programs and Endpoint Detection and Response (EDR) solutions, which can prevent or at least hinder the execution of malicious code on client systems. Furthermore, this allows for timely initiation of additional, targeted protective measures should alarm notifications be triggered.
However, the most important defense against phishing attacks lies with the end user. Especially in the day-to-day work environment, emails should always be handled with caution and a healthy dose of skepticism. It is also helpful to share suspicions about current phishing attacks with colleagues and raise awareness, for example, through a group email or word of mouth. To complement this, targeted awareness training and phishing simulations can significantly refresh and improve security across the entire company.
Leverage space technology for your business. OHB Digital Services GmbH has been a trusted partner for secure and innovative IT solutions for many years. We are part of one of Europe’s most successful space and technology companies. With our products and services, we can help you digitize your business processes across the value chain and address all security-related issues.Feel free to contact us.

You are currently viewing placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will result in data being shared with third-party providers.
More InformationYou are currently viewing placeholder content from YouTube. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will result in data being shared with third-party providers.
More InformationYou are currently viewing a placeholder content from reCAPTCHA. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from hCaptcha to submit the form. Please note that doing so will result in data being shared with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will result in data being shared with third-party providers.
More InformationYou are currently viewing placeholder content from Turnstile. To access the actual content, click the button below. Please note that doing so will result in data being shared with third-party providers.
More Information