Largo Books encountered a serious case of "spear phishing". Kaspersky Total Security defines spear phishing as, "an email or electronic communications scam targeted towards a specific individual, organization or business. Although often intended to steal data for malicious purposes, cybercriminals may also intend to install malware on a targeted user's computer." Largo Book customers were mislead into thinking that they had received an actual email from the company, presenting them with a deal most wouldn't pass up. A link was given in the email, proving its validity, and most likely asked for information like name, address, and credit information, typical questions a hacker would ask in order to receive the offered "deal". Sounding like this was a direct attack to Largo Books, hackers may have gotten into the network of the company in order to email its customers, compromising their Information System (IS).
In order for this hack to have been as successful as it was, this scam had to be convincing enough to have hundreds of Largo Book customers respond. Valacich describes various types of IS used in organizations, and when matching its purpose to its type, electronic commerce system, customer relationship management system, and enterprise resource planning systems may have been the companies most vulnerable areas of attack.
Today, hundreds of companies go through this exact issue. I personally have received emails from companies like Apple and even cell phone providers asking for more information, or providing me with a link to what seems to be a very identical website of that particular company. Now-a-days, a person wouldn't think twice to click the link and enter their information because most don't think they are at risk. Half don't even think about cyber risks they face daily. With software ensuring to help maintain a “virus free” computer, the user doesn't think about the dangers of giving sensitive information over the internet.
1. Revisit cyber security measures already in place. Look into new firewall hardware that can detect security violations and hackers before allowing them total access into the system.
2. Make sure all upgrades and updates are done on the system to guarantee a tighter watch of the IS. A simple update could determine the strength of protection on a system, and all companies should be on top of this.
3. Give customers peace of mind. Explain company policies, ensuring them personal information wouldn’t be requested through email, and be aware of where future emails are coming from. A lot of times a hacker’s email address doesn’t match the company, and that can easily be looked over by a customer.
“What is Spear Phising?” (2016). Retrieved from Kaspersky Lab USA website:
Joseph A. Valacich and Christoph Schneider (2014). Information Systems Today: Managing in the Digital World, 7th Edition. Pearson Prentice Hall.

