
The Dangers of Phishing and Spear Phishing
Online scams are the bread and butter of the modern day grifter. Technology has provided us with protection against some scams such as SPAM and malware, but the persistent thief has more than one trick up his sleeve. Scammers are nothing if not innovative, and unfortunately there is no single tool that provides a complete shield against all attacks. That said, in the war for online security, there is no substitute for the preventative power of education. Here is a brief guide to one of the online world’s more pernicious online scams: phishing.
Phishing attempts are among the most common of online scams, yet they also remain among the most effective. Often, phishing comes in the form of an email, text, or some other message from a seemingly legitimate source. For example, a text message may be sent out from a widely known company or government agency asking the target for personal information such as an ID number. Since the target often transacts business with that organization, the request seems reasonable at first glance. However, once that information has been handed over, the scammers can use even seemingly innocuous information to wreck untold havoc.
In fact, the IRS was recently a target in this exact scam. During late 2025, thousands of innocent taxpayers received messages from scammers claiming to be the IRS. Many complied with the requests for information, such as providing their social security numbers, and many had their identities stolen. It is impossible to know the exact cost of this for each victim, but on average, the time required to deal with nightmare scenarios such as this can be years. This one example also highlights the insidious nature of phishing attacks: they manipulate the natural human desire to comply with seemingly legitimate authority.
“Spear phishing” works by utilizing the same model as traditional phishing, but with a layer of sophistication added in. Traditional phishing relies upon numbers to produce results. Thousands of messages are sent out, but the scammers only need a handful of victims to actually reply. With spear phishing, however, the pool is far smaller, and the message is far more tailored to the individual targets. Chillingly, some hackers will spend months quietly observing their targets before crafting their message. These higher-profile targets are often the employees working in a single governmental agency or a single department of a company with access to highly sensitive information. A classic example of this is an email sent out to employees of a government agency asking them to “verify” their login credentials. The goal of these scammers is to acquire specialized information that can later be sold and exploited by unknown third parties. In the realm of military or government systems, leaks of this type can have serious career and national security implications.
There are several ways to protect yourself and your organization from the dangers of phishing and spear phishing. The most reliable method is to simply verify the request either in person or with a quick phone call. If you receive a suspicious message, err on the side of caution and verify it before replying. Do not be afraid of conflict in this scenario, especially given the enormous risks of a security breach. If the request is indeed illegitimate, the organization will need to do an investigation and strengthen their defenses anyway.
The scammers who create these traps rely on complacency from their victims, so routine training is the next most reliable method of defense. Regular security audits from IT professionals can provide employees with training on what signs to look out for and what to do in the event they receive any suspicious messages in the future. This can be augmented by penetration tests and employee training on the exact steps that need to be taken during a security breach.
If you are personally involved in a potential data breach, the first step is to alert the appropriate people in your organization. Cooperate fully with any investigation and DO NOT attempt to cover it up. While it can be embarrassing to be involved in a data breech, it is often forgivable. On the other hand, ignoring the problem or attempting to cover it up can, and often does, lead to severe consequences. In addition to violating the security policies of most organizations, such conduct often violates both State and Federal data privacy laws, leading to heavy fines or even criminal charges. When dealing with a data breach, trust the experts, cooperate fully, and remember that time is of the essence in mitigating the damage.
This article is intended to provide general legal knowledge, but it is no substitute for speaking with an actual lawyer. To speak with an attorney in the Fort Bliss Legal Assistance Office on this or any other topic, please schedule an appointment by emailing usarmy.bliss.hqda-otjag.mesg.bliss-legal-assistance-office@army.mil at any time or by calling (915) 568-7141 during business hours.
Capt. David Mathew, Fort Bliss Legal Assistance Office
