Carnegie Mellon University
April 08, 2011

Security Advisory: Epsilon Breach Could Increase Spear Phishing Attacks

Epsilon, a service provider that manages email communications for many companies, reported last week that it suffered a security breach that exposed names and email addresses for some of its clients' customers.

Although Epsilon has indicated that no other personally-identifiable information  was put at risk, the compromised information could be used to send spam, phish, or malware-infected email. Most concerning is a type of phishing known as "spear phishing," whereby a phisher exploits a trust relationship to convince you to supply sensitive data like your login ID and password, credit card data, or banking information.  Your name, email, and the name of a company that you do business with provide all the ingredients for a successful spear-phishing attack.