You are on page 1of 19

EMAIL FRAUD

DEFENSE
UT Health
Andrew Wittner Account Manager
Josh Behnke Senior Sales Engineer
How Proofpoint Helps Address Impostor Email

Dynamic Email Granular Policy &


Classification & Authentication Filtering
Analysis Implementation
Impostor Phishing Techniques
REPLY-TO SPOOFING header From: CEO <CEO@acme.com>
60% header To: Other Exec <Exec@acme.com>
header Reply To: <hacker@badguy.com>

36% DISPLAY NAME SPOOFING header From: CEO hacker@badguy.com


header To: Other Exec <Exec@acme.com>

SPOOFED SENDER header From: CEO <CEO@acme.com>


2% header To: Other Exec <Exec@acme.com>

LOOKALIKE DOMAIN header From: CEO <CEO@acnne.com>


2% header To: Other Exec <Exec@acme.com>

PARTNER COMPROMISE header From: Account Receivable AR@acme.com


?? header To: AP@partner.com
Proofpoint Email Fraud Defense
Legitimate Company Email sender@trusted.com

Inbox

Legitimate Partner Email sender@partner.com

Email Fraud Defense


Rejected
Company Domain Spoofing badguy@trusted.com

Email Fraud Defense


Rejected
Partner Domain Spoofing badguy@partner.com
Service Implementation
Visibility Authenticate Block fraudulent
email

Understand who is Approve legitimate email Protect employees,


sending email using your senders partners and customers
domain
Email Fraud Defense
Your email Your service
BEC actors Cybercriminals
gateway providers
Who is sending
email as you

Assess email sent as you", both


Monitor Senders
good and bad
Email Fraud Defense
Enable recipients to authenticate
Create Policy
valid email from you

Who is receiving Your partners/


email from you Your customers
Your email gateway vendors email
email providers
gateways
Find and Block More
1 billion DMARC reports monitored and analyzed
Software to block email threats before they hit the inbox

25 times more forensic data than DMARC alone


70+ consumer ISP relationships
Data 29 million IPs scored each month
Millions of Consumer Inboxes

Dedicated Strategic Project Manager


A fully customized DMARC policy implementation plan
Service Knowledge of 3rd Party Senders Authentication Challenges
24/7 Support
Mail from Iran
Attachment Threat Summary
Downloaded: 2017-01-23
Date Range: 2016-11-25 to 2017-01-23

MD5 Hash Header From Domains Spoof Type Last Sent


32dfe2db740189febd79b607acad4591 uth.tmc.edu Domain 11/29/2016 10:53
852e92e734b1efe384f6aa1ae09e6601 uth.tmc.edu Domain 12/27/2016 7:12
1a3c8329e568d6e3da175ac40fb6a4ea uth.tmc.edu Domain 12/27/2016 7:12
fd4175b78eb5e2e90695e57409d7a438 uth.tmc.edu Domain 12/14/2016 21:01
2a01078e49d189a30467b53d3bebdd5c uth.tmc.edu Domain 11/29/2016 14:02
36c4f7bde333ef2c09f1fa57ea626f40 uth.tmc.edu Domain 11/29/2016 14:11
36da298c6dedd86406951d1a48cf5131 uth.tmc.edu Domain 12/23/2016 21:34
4a0821b87c76e4550130e6cef8d1aa05 uth.tmc.edu Domain 12/23/2016 21:48
4b3c88b447925124b918b67675af5840 uth.tmc.edu Domain 11/29/2016 14:02
4e6d5f6794f2f22a4479c17e188c94bb uth.tmc.edu Domain 12/23/2016 21:35
60c64cde2033a5bc431604e0ecb9266c uth.tmc.edu Domain 12/23/2016 20:45
7390029683a2905dc4b95fed0491bf93 uth.tmc.edu Domain 11/29/2016 14:12
79ac697ad3629f98bac19083ce67e1d9 uth.tmc.edu Domain 12/23/2016 21:48
7fe18d0d23158d00ee2eb1e19c6c0295 uth.tmc.edu Domain 12/23/2016 21:33
89bd87406aa85237b3d78afdfd6da9c5 uth.tmc.edu Domain 12/23/2016 21:33
8aa167f53c5024375ae52e1cad029cf4 uth.tmc.edu Domain 11/29/2016 14:14
986e4402ee1c906bb3e5c8d28c1ee088 uth.tmc.edu Domain 11/29/2016 14:11
9909da13aa52daaf8a7c92afd5664659 uth.tmc.edu Domain 11/29/2016 14:13
a9639784e9ec86abebdda9259db76e6f uth.tmc.edu Domain 12/23/2016 21:28
aae390f8eebbf7d81622a5ae98e7e89a uth.tmc.edu Domain 11/29/2016 14:12
b06df0656c049608cd09d1ccd68ede87 uth.tmc.edu Domain 12/23/2016 20:43
b301c131b314f98fceda01bb4080a1fc uth.tmc.edu Domain 11/29/2016 14:27
c06a2bb88391cb901d9ba58e16815faf uth.tmc.edu Domain 12/23/2016 21:48
c5ed6f9760413b4a41a426e60fab32b7 uth.tmc.edu Domain 11/29/2016 14:00
c6d18a3e35f46a62d564ea26851ddc6c uth.tmc.edu Domain 11/29/2016 13:58
c9965a32eb1fd98c70ce49ded93a9ca7 uth.tmc.edu Domain 12/23/2016 21:33
cf0534a49ab0b6d45a09453f220893ad uth.tmc.edu Domain 12/23/2016 21:48
def18306e554ac6af198023c6ac9d508 uth.tmc.edu Domain 11/29/2016 14:27
e3478787743801b7ba31dba8e27fd385 uth.tmc.edu Domain 11/29/2016 14:29
ee627ce63f2f3b152ce5ddf88889540e uth.tmc.edu Domain 12/23/2016 21:27
f155889e5313f79fc5efd7f6c8afd42a uth.tmc.edu Domain 11/29/2016 14:30
f747c3f8b83d9e0d2643dee1f1912a53 uth.tmc.edu Domain 11/29/2016 13:58
f96032ecb51a1a7ca79be4b4f6428cd8 uth.tmc.edu Domain 11/29/2016 14:01
ff223f2db8f200c4e92965af5d3c1196 uth.tmc.edu Domain 12/23/2016 21:48
1ecf7dff125376c05e562975cc516614 uth.tmc.edu Domain 12/23/2016 21:32
20750f996d7f9ef6a8b6606070a5c914 uth.tmc.edu Domain 12/23/2016 20:43
210726f64d292bf1f8290be1513301db uth.tmc.edu Domain 11/29/2016 14:26
0a8c81b43e69d216add63a25b6d7a821 uth.tmc.edu Domain 11/29/2016 14:17
10240e27fc805d0d73612fdc8a21b619 uth.tmc.edu Domain 1/7/2017 8:07
EFD Delivers Fully Customized Service
Dedicated Strategic Project Manager

Fully customized project


implementation plan

Comprehensive Risk Assessment


Service
Global team of email experts across
five continents

You might also like