22. A customer of a financial institution (FI) complained that they had received multiple emails appearing to originate from the FI urging them to click on a link or open a remittance attachment for confirmation. After opening the attachment, the customer later realized that funds had been systematically transferred out of their bank account without their knowledge. Which type of cybercrime is described in this scenario?

Answer: B

Explanation:

Spear phishing

Spear phishing is the type of cybercrime described in this scenario, as it involves targeted emails that appear to come from a legitimate source, urging the recipient to take action that compromises their security. The emails in this case specifically prompted the customer to open an attachment, leading to unauthorized transfers from their bank account.

A) SMSishing

SMSishing refers to phishing attacks conducted through SMS text messages. While similar in intent to phishing, it does not pertain to emails or attachments as described in this scenario. Therefore, this option is incorrect.

B) Spear phishing

Spear phishing is a targeted form of phishing where attackers send fraudulent emails to specific individuals, often mimicking trusted entities to deceive them. This option accurately reflects the scenario, as the emails appeared to come from the financial institution and prompted the victim to interact with a malicious attachment, resulting in unauthorized fund transfers.

C) Pharming

Pharming involves redirecting users from legitimate websites to fraudulent ones, often without their knowledge. This scenario describes an email and attachment interaction, not a redirection to a fake website, making this option incorrect.

D) Vishing

Vishing, or voice phishing, involves the use of phone calls to trick individuals into revealing personal information. The scenario clearly involves emails and attachments, not phone communication, thus rendering this option incorrect.

Conclusion

Spear phishing is the correct answer as it captures the essence of the targeted email attack that led to unauthorized access to the customer’s bank account. Other options fail to fit the specifics of the scenario, as they either pertain to different mediums or methods of cybercrime that do not involve emails or attachments as described.