Facebook for years may have topped cybersecurity firm Vade’s “Phishers’ Favorites,” a report of the most impersonated brands in phishing attacks, but the $2 trillion Credit Agricole bank recently edged out the social media giant with 17,755 unique phishing URLs.
Facebook’s topple from the No. 1 spot was a surprise, Adrien Gendre, chief product officer at the AI-based cybersecurity firm, tells Bank Automation News in this week’s episode of “The Buzz.”
“Facebook has been the top of that list for four years,” Gendre says. “Obviously, Credit Agricole is less famous worldwide than Facebook.”
Credit Agricole wasn’t the only financial institution to make the list. Seven others, including $3.7 trillion Chase, $1.9 trillion Wells Fargo and $2.98 trillion HSBC, ranked in the top-25 brands used in cyberattacks that leverage fake websites and emails to gain credentials from unsuspecting employees and customers.
In this podcast, Gendre and BAN explore how banks became a popular lure for phishing schemes, and what financial institutions can do to protect their brands.
Subscribe to The Buzz Podcast on iTunes, Spotify, Google podcast, or download the episode.
The following is a transcript generated by AI technology that has been lightly edited but still contains errors.
Good day and welcome to The Buzz, a Bank Automation News podcast. I’m Deputy Editor Loraine Lawson. In today’s episode, we’re joined by Adrian Gendre, chief product officer for Vade, an artificial intelligence-based cybersecurity firm. We discuss phishing attacks and why more hackers are using financial institutions to lure in employees and customers. Mr. Gendre also shares what banks can do to protect their brand.First of all, I wanted to know if you can explain what a phishing attack is because there are people who just aren’t familiar with the security terminology. So if you wouldn’t mind explaining what a phishing attack is.Adrian Gendre
Sure, a phishing attack first brand impersonation, the goal is to capture user’s credentials most of the time. If not, it’s just to proceed to any malicious act, such as planting a malware for instance, in the recipient’s computer. So a phishing attack is often an email spoofing the brand and a webpage, spoofing the brand, most of the time, but not only, but most of the time, the email is leading to the webpage to capture the user’s credentials. And that’s the phishing attack.Loraine Lawson
We just want to be very clear, it really doesn’t involve the base website or anything like that. They’ve just set up a fake website. In most cases.Adrian Gendre
It is just a fake website. It is a fake email. They look alike, but they’re not the same. Okay.
Loraine Lawson
All right. And also, can you just explain the process of how you created this list? What’s the methodology? What data are you drawing from to create your most fish list? Sure.
Adrian Gendre
So our job is to filter and protect emails. So we protect 1 billion boxes in the world. The way we identify the brands, it’s from the analysis of our traffic by our threat analyst or threat teams. Once we have identified the most famous brands in the traffic, we say, we train those brands in our computer vision engine, which is the ability to identify the brands from the visual rendering of the identity. Once the brands and the models are trained, the identification is done by the computer vision engine on the fly on every email, we’re scanning and released here to be very specific. The list in the fishes favorites is based on the amount of newly created web pages per inch wide brand. And fake web pages, of course.
Loraine Lawson
Do you I guess your product helps catch these attacks? Is that correct?
Adrian Gendre Yes.
Loraine Lawson Yeah. So that’s sort of why you’re monitoring that. Alright. And who tops the list?
Adrian Gendre
So, in this edition, the the top three brands are first, a French bank called credit agricole, in the French accent. Then we have Facebook, and then we have Microsoft. What’s interesting to look at here, it’s usually the brands that top the list of the most famous brands, because they are the most known to the users. So finishers use, how famous they are to for users. Because when we know a brand, we are less careful. When we receive an email, we click more easily on the emails.
Loraine Lawson
Really surprised to see that the bank had overtaken Facebook as the top one. Was that a surprise? I mean, do you think do you have any reason why that might have happened as Facebook obviously, usually recognized brand.
Adrian Gendre
Yes, and there was a surprise Facebook has been has been the top of that list for four years. Obviously, clear equal is less famous worldwide than Facebook. So to understand why we can just speculate and tries to guess why fishers have decided to retarget the attacks on the career record brand. It’s usually connected to the news. We also see fishers rotating through brands. But here is we speculate and again, it’s it’s just speculation here. But over the last two years, COVID changed the landscape in many respects. And what we have seen, we have seen a financial crisis in many countries. And we have seen financial aid provided by governments, through banks, with a lot of loans made very quickly for the people. So what we’re seeing in this edition of deficiency, which is quite special and unprecedented. We see the financial sector being much more represented in this edition than in the previous ones. And we believe COVID has a connection somewhere.
Loraine Lawson
Yeah, I counted six banks, would you mind just naming those for us? And that was the top 25
Adrian Gendre
I should say 25. And our candidates expense. Indeed. So in this top 25 we have banks are free financial institutions such as Korea recall labanc postar, another bank based in France, Chase in the US, Wells Fargo, HSBC, bank populair, also another one in France. So we’re seeing an amount of banks in the top 25, that is much higher than in the previous editions.
Loraine Lawson
And you obviously are French. So you gave yourself away there, I hate to tell you, but anyway, do you have a lot of clients in France? Do you think that’s part of the reason so many French banks are on here?
Adrian Gendre
So we actually thought about it. And when we when we look at the numbers, we have much more data in the US than in France, for example, just by the size of the country and the number of customers we have over there. Same thing in Japan, for example, where we have much more data than than in France. So it doesn’t seem to be a correlation here. If we just speculate, again, what we are seeing in France during the COVID is that the government guaranteed fully loans to companies and people. So we have seen an amount of loans, and I forgot the numbers, but provided in like a few months that was completely unprecedented in the history of the country. So we believe this is why some issues might have mitigating their attack to some French banks.
Loraine Lawson
That makes sense. I assume if we had a list of the Top 100 phished companies, there would be other banks. Is it common? You said that you saw more banks on this list than you have in the past but is it common for bass to be used to phishing attacks?
Adrian Gendre
Yes, it’s common for banks to be using phishing attacks because they’re famous brands to people to consumers. We see most we see more sorry, consumer brands rather than b2b brands. We see some b2b brands, but consumer brands are really on the top. So it’s, it’s common to have banks being spoofed by features to fool people.
Loraine Lawson
And it makes sense that is where the money is, right? So if, yeah, if a bank does find its name has been used in a phishing scam, what can it do to reduce maybe the scope of the scams reach to like nip it in the bud, or we can do to protect its reputation.
Adrian Gendre
So there are some technical solutions to this. The first there are some protocols that are designed to protect the usage of your own domain name, like Wells Fargo, that calm phrase, for instance, and make sure this cannot be impersonated. But we’re seeing a phishing, most of the phishing links and emails are actually using other domain names that are created, some look alike, and some totally different. So it helps, but it doesn’t cover fully the solution here. From my opinion, the most effective way and long term way is to educate user. It’s to communicate with the users, it’s for the bank to be fully transparent in the way they communicate with their users. And explain how is the communication Polizzi with very simple things. For example, that bank will never request credentials by email to users, things like this. But some users don’t know how the bank will be communicating with them. And first by explaining how they will communicate with them, and what they will never do, actually, as a bank, it will help to educate users have users more aware. And so the attacks will be less effective because users will not fall into the traps anymore.
Loraine Lawson
You’ve been listening to the Buzz, a Bank Automation News podcast. Thank you for your time and be sure to visit us at BankAutomationNews.com for more automation news. You can also follow us on Twitter and LinkedIn. Please don’t hesitate to rate this podcast on your podcast platform of choice.
Facebook for years may have topped cybersecurity firm Vade’s “Phishers’ Favorites,” a report of the most impersonated brands in phishing attacks, but the $2 trillion Credit Agricole bank recently edged out the social media giant with 17,755 unique phishing URLs.
Facebook’s topple from the No. 1 spot was a surprise, Adrien Gendre, chief product officer at the AI-based cybersecurity firm, tells Bank Automation News in this week’s episode of “The Buzz.”
“Facebook has been the top of that list for four years,” Gendre says. “Obviously, Credit Agricole is less famous worldwide than Facebook.”
Credit Agricole wasn’t the only financial institution to make the list. Seven others, including $3.7 trillion Chase, $1.9 trillion Wells Fargo and $2.98 trillion HSBC, ranked in the top-25 brands used in cyberattacks that leverage fake websites and emails to gain credentials from unsuspecting employees and customers.
In this podcast, Gendre and BAN explore how banks became a popular lure for phishing schemes, and what financial institutions can do to protect their brands.
Subscribe to The Buzz Podcast on iTunes, Spotify, Google podcast, or download the episode.
The following is a transcript generated by AI technology that has been lightly edited but still contains errors.
Good day and welcome to The Buzz, a Bank Automation News podcast. I’m Deputy Editor Loraine Lawson. In today’s episode, we’re joined by Adrian Gendre, chief product officer for Vade, an artificial intelligence-based cybersecurity firm. We discuss phishing attacks and why more hackers are using financial institutions to lure in employees and customers. Mr. Gendre also shares what banks can do to protect their brand.First of all, I wanted to know if you can explain what a phishing attack is because there are people who just aren’t familiar with the security terminology. So if you wouldn’t mind explaining what a phishing attack is.Adrian Gendre
Sure, a phishing attack first brand impersonation, the goal is to capture user’s credentials most of the time. If not, it’s just to proceed to any malicious act, such as planting a malware for instance, in the recipient’s computer. So a phishing attack is often an email spoofing the brand and a webpage, spoofing the brand, most of the time, but not only, but most of the time, the email is leading to the webpage to capture the user’s credentials. And that’s the phishing attack.Loraine Lawson
We just want to be very clear, it really doesn’t involve the base website or anything like that. They’ve just set up a fake website. In most cases.Adrian Gendre
It is just a fake website. It is a fake email. They look alike, but they’re not the same. Okay.
Loraine Lawson
All right. And also, can you just explain the process of how you created this list? What’s the methodology? What data are you drawing from to create your most fish list? Sure.
Adrian Gendre
So our job is to filter and protect emails. So we protect 1 billion boxes in the world. The way we identify the brands, it’s from the analysis of our traffic by our threat analyst or threat teams. Once we have identified the most famous brands in the traffic, we say, we train those brands in our computer vision engine, which is the ability to identify the brands from the visual rendering of the identity. Once the brands and the models are trained, the identification is done by the computer vision engine on the fly on every email, we’re scanning and released here to be very specific. The list in the fishes favorites is based on the amount of newly created web pages per inch wide brand. And fake web pages, of course.
Loraine Lawson
Do you I guess your product helps catch these attacks? Is that correct?
Adrian Gendre Yes.
Loraine Lawson Yeah. So that’s sort of why you’re monitoring that. Alright. And who tops the list?
Adrian Gendre
So, in this edition, the the top three brands are first, a French bank called credit agricole, in the French accent. Then we have Facebook, and then we have Microsoft. What’s interesting to look at here, it’s usually the brands that top the list of the most famous brands, because they are the most known to the users. So finishers use, how famous they are to for users. Because when we know a brand, we are less careful. When we receive an email, we click more easily on the emails.
Loraine Lawson
Really surprised to see that the bank had overtaken Facebook as the top one. Was that a surprise? I mean, do you think do you have any reason why that might have happened as Facebook obviously, usually recognized brand.
Adrian Gendre
Yes, and there was a surprise Facebook has been has been the top of that list for four years. Obviously, clear equal is less famous worldwide than Facebook. So to understand why we can just speculate and tries to guess why fishers have decided to retarget the attacks on the career record brand. It’s usually connected to the news. We also see fishers rotating through brands. But here is we speculate and again, it’s it’s just speculation here. But over the last two years, COVID changed the landscape in many respects. And what we have seen, we have seen a financial crisis in many countries. And we have seen financial aid provided by governments, through banks, with a lot of loans made very quickly for the people. So what we’re seeing in this edition of deficiency, which is quite special and unprecedented. We see the financial sector being much more represented in this edition than in the previous ones. And we believe COVID has a connection somewhere.
Loraine Lawson
Yeah, I counted six banks, would you mind just naming those for us? And that was the top 25
Adrian Gendre
I should say 25. And our candidates expense. Indeed. So in this top 25 we have banks are free financial institutions such as Korea recall labanc postar, another bank based in France, Chase in the US, Wells Fargo, HSBC, bank populair, also another one in France. So we’re seeing an amount of banks in the top 25, that is much higher than in the previous editions.
Loraine Lawson
And you obviously are French. So you gave yourself away there, I hate to tell you, but anyway, do you have a lot of clients in France? Do you think that’s part of the reason so many French banks are on here?
Adrian Gendre
So we actually thought about it. And when we when we look at the numbers, we have much more data in the US than in France, for example, just by the size of the country and the number of customers we have over there. Same thing in Japan, for example, where we have much more data than than in France. So it doesn’t seem to be a correlation here. If we just speculate, again, what we are seeing in France during the COVID is that the government guaranteed fully loans to companies and people. So we have seen an amount of loans, and I forgot the numbers, but provided in like a few months that was completely unprecedented in the history of the country. So we believe this is why some issues might have mitigating their attack to some French banks.
Loraine Lawson
That makes sense. I assume if we had a list of the Top 100 phished companies, there would be other banks. Is it common? You said that you saw more banks on this list than you have in the past but is it common for bass to be used to phishing attacks?
Adrian Gendre
Yes, it’s common for banks to be using phishing attacks because they’re famous brands to people to consumers. We see most we see more sorry, consumer brands rather than b2b brands. We see some b2b brands, but consumer brands are really on the top. So it’s, it’s common to have banks being spoofed by features to fool people.
Loraine Lawson
And it makes sense that is where the money is, right? So if, yeah, if a bank does find its name has been used in a phishing scam, what can it do to reduce maybe the scope of the scams reach to like nip it in the bud, or we can do to protect its reputation.
Adrian Gendre
So there are some technical solutions to this. The first there are some protocols that are designed to protect the usage of your own domain name, like Wells Fargo, that calm phrase, for instance, and make sure this cannot be impersonated. But we’re seeing a phishing, most of the phishing links and emails are actually using other domain names that are created, some look alike, and some totally different. So it helps, but it doesn’t cover fully the solution here. From my opinion, the most effective way and long term way is to educate user. It’s to communicate with the users, it’s for the bank to be fully transparent in the way they communicate with their users. And explain how is the communication Polizzi with very simple things. For example, that bank will never request credentials by email to users, things like this. But some users don’t know how the bank will be communicating with them. And first by explaining how they will communicate with them, and what they will never do, actually, as a bank, it will help to educate users have users more aware. And so the attacks will be less effective because users will not fall into the traps anymore.
Loraine Lawson
You’ve been listening to the Buzz, a Bank Automation News podcast. Thank you for your time and be sure to visit us at BankAutomationNews.com for more automation news. You can also follow us on Twitter and LinkedIn. Please don’t hesitate to rate this podcast on your podcast platform of choice.






