Phishing
Phishing is the most common entry point for financial fraud against wealthy families and their offices. An attacker crafts a message that looks legitimate — mimicking a bank, a law firm, or a known contact — and includes a link, an attachment, or a payment request. The goal is either to steal login credentials or to initiate an unauthorized transfer directly.
Spear phishing is a more targeted variant: the attacker researches the family or office first, then personalizes the message with real names, relationships, or transaction details. A hypothetical example: a family office accountant receives an email that appears to come from the family's estate attorney, referencing an actual trust amendment in progress and asking for a "revised" wire confirmation. That personalization dramatically increases the chance of compliance.
Whaling is spear phishing aimed specifically at senior figures — a principal, a CEO of a family operating company, or a chief investment officer. These attacks often involve spoofed email domains that differ from the real one by a single character. Families commonly implement email authentication protocols and train staff to inspect sender addresses carefully before acting on any financial instruction.
Phishing is inseparable from social engineering: the message creates the false context; the human response completes the fraud. Strong multi-factor authentication limits the damage when credentials are captured, and a documented incident response plan determines how fast the family can act once a breach is detected.
Términos relacionados
A login security method requiring a user to verify identity through two or more independent factors…
TérminoSocial EngineeringA manipulation technique where attackers exploit human trust or authority rather than technical…