12. A customer of a financial institution complained that they had received multiple emails appearing to originate from the FI urging them to click on a link or open a remittance attachment for confirmation. After opening the attachment, the customer later realized that funds had been systematically transferred out of their bank account without their knowledge. Which type of cybercrime is described in this scenario?

Answer: B

Explanation:

Spear phishing

In this scenario, the type of cybercrime described is spear phishing, as the emails were specifically crafted to target the customer and deceive them into taking action that resulted in unauthorized fund transfers.

A) Vishing

Vishing, or voice phishing, involves fraudulent practices conducted via phone calls to deceive individuals into revealing personal information. This option is incorrect because the scenario describes a cybercrime executed through emails rather than phone communications.

B) Spear phishing

Spear phishing is a targeted attempt to steal sensitive information such as account credentials or financial information from a specific individual, often for malicious reasons. The scenario indicates that the emails were designed to deceive the customer into clicking links or opening attachments, which aligns perfectly with spear phishing tactics.

C) Pharming

Pharming involves redirecting users from legitimate websites to fraudulent ones without their consent, typically through malware. This option is incorrect as the scenario specifically mentions emails urging the customer to click on links, rather than redirecting them away from a legitimate website.

D) SMSishing

SMSishing, a form of phishing conducted through text messages, is not applicable in this scenario, as the communication took place through emails. Thus, this option is not relevant to the situation described.

Conclusion

Spear phishing is definitively the correct answer because it involves a targeted approach aimed at deceiving a specific individual, which matches the context given in the scenario. All other options fail to describe the method of cybercrime accurately, as they either pertain to different communication channels or broader phishing tactics that do not involve direct targeting.