Showing posts with label online safety. Show all posts
Showing posts with label online safety. Show all posts

Wednesday, March 31, 2021

Cybersecurity: Is there something phishy going on in your inbox?

 

SOURCE: Jeffrey L. Price, 2020
Have you ever noticed how many fishing lures are shiny and brightly colored?

It’s because fish can’t resist them, and it seems we humans also have this same flaw. Send someone a flashy message promising them some reward or a vaguely worded threat and we just can’t resist clicking on the link or attachment in that message to see what it is. 

Cybercriminals know this and depend on your trust and curiosity to make their scams work. And just like that poor trout who goes to investigate that shiny thing floating around in the water, it doesn’t end well. 

So how do you avoid becoming some cyber-fisherman’s catch of the day? 

The answer is deceptively easy. When it comes to e-mails -- and even text messages – trust nobody. Assume every message you get is fake until you can confirm it’s not. 

And how do you go about confirming a message isn’t fake? 

By following some simple precautions I outline below. While this list isn’t exhaustive and doesn’t guarantee you will never be fooled, you will be surprised how often it can save you from being hooked.

Skepticism is your best defense

First and foremost, be skeptical of any message you get. Are you expecting a message from this person and what are they asking you to do? If they are asking you to download an attachment or requesting you to sign into some site – even one that seems legitimate – ask yourself if this person really needs to know that information.

If a stranger came up to you on the street and introduced themselves as a friend of a friend then asked you for your social security number, would you give it to them? Probably not. So you shouldn't do it with an e-mail from some stranger either.

If the message appears to be from a bank or other institution you do business with and they are requesting you verify information they should already have, then don’t give it to them.  Again, you wouldn’t give the keys to your safe deposit box to some Joe on the street who introduces himself as the VP at your bank, would you?

Remember hackers are extremely good at what they do. They are experts at creating seemingly valid email addresses, language, and mimicking brand logos. So be skeptical when it comes to your email inbox – if an email looks even remotely suspicious, do not open it. Instead, delete it. It is always better to be safe than sorry.

Look closely at the display name and email address

Faking or forging the display name on an email (or even a text message) is a classic phishing ploy. Many times hackers will intentionally misspell a name betting you won’t notice the difference between something like CityBank and Citibank to get you to think their message is real.

Another trick they use is to slightly change the name of a person or colleague they might think you regularly communicate with. So instead of getting a message from a Michael Smith, hackers might try to disguise themselves as Micheal Smith, Mike Smith or even Mika Smith, again betting your familiarity with their name will make you overlook the misspellings. Also be on the lookout for names in the wrong order. At my company display names from internal employees are always listed as LastName, FirstName. So when I see a message from our CFO with a display name of FirstName Lastname, I know it is fake. 

Next take a look at the email address following that display name. Does it match and appear to come from the right organization? A message from Citibank for example, should come from someone@citbank.com and not Citibank@abc.com.

The tip here is to always look at the part of the email address that follows the @ sign.  Remember that no legitimate organization will send an email using a public domain like email address like ones ending with @gmail.com, @comcast.net, @yahoo.com, @aol.com, etc. Every organization will have its own email domain (the part of the address that follows the @ sign) and only send from official company accounts. The best way to find out what an organization’s real domain name is is to type that company’s name into a search engine.
Also be on the lookout for domain names that mimic real ones. Hackers are betting that you will overlook misspellings like @citbank.com (missing the second “i”), @citybank.com (using a “y” instead of an “i) or even wrong endings like citibank.net instead of citibank.com.

Finally, watch out for is mismatched display names and e-mail addresses. If the display name says  Michael Smith, then the e-mail address should not give another name like marcia.brown@gmail.com. If the first part of the address is a random string of numbers or letters – such as 1234VZE@verizon.net – then it’s a good bet the message is from someone trying to hide their true identity from you and you should automatically treat that message as fake. 

Review the salutation 

Who is the email addressed to? Is it to a vague “Valued Customer?” Legitimate businesses will often use a personal salutation with your first and last name, so beware if it doesn’t. Likewise if you get a message that has your name misspelled or appears to be from someone you know and they use your formal name rather than the nickname they’ve always used with you, then again, you can bet the message is a fake. 

Be warry of urgent or threatening language 

Cyberscammers often try to put you off guard by using fear or the threat of legal or financial action against you or play on your emotions by creating a false sense of urgency in their messages. Commonly, they will have subject lines such as “urgent payment request” or make claims that your “account has been suspended.” Others will say you have won an expensive prize in a contest you don’t remember entering telling you you must claim the prize now or it will go to someone else. 

These messages will often direct you to click on some link or download an attachment that could infect your device with malware or trick you into revealing usernames and passwords to important accounts.

Guard your confidential information as if your life depended on it

Legitimate businesses will never ask for personal credentials through an email.

Ever.

These types of phishing scams often proport to be from a bank or other financial institution, the IRS or even online shopping sites like Amazon. 

Again, ask yourself if you would give up that information to some guy on the street who just came up to you saying they were from your bank or the IRS and didn’t show you any hard proof of who they were. 

So ignore any requests you get to “reset,” “sign in,” or input username or password through email – it’s almost always a scam.  

The one exception to this rule is if you get a password reset message immediately after clicking the “I forgot my password” link on a site you usually do business with.

Also remember that legitimate businesses will never ask you for your account numbers, social security numbers, dates of birth or other information that could be used to personally identify you via an email. They should already have this information on file. If they ask you for it in an e-mail or text message, it’s either a phish or it’s a company you should stop doing business with immediately!

Think before you click

Note the link in the body says one thing, but when you hover 
over it, the real link shows a different address!                    
Hackers love to embed malicious links in what look to be legitimate messages. To expose this fraud,
hover your mouse over the link. If the link address looks weird, DON’T click on it. If you’re skeptical about the link, call an IT pro to have them check it out. If you don’t have a favorite IT person you can bug, then look up the business’ contact information via a google search or go old-school and use a phone book, and call the company and ask them about the message.

Don’t click attachments either

Just like malicious links, hackers like to embed malicious attachments that contain viruses and malware in their phishing emails. Malware can steal your passwords, damage files on your computer, or spy on you without you ever knowing. Curiosity killed the cat, so don’t open any email attachments you weren’t expecting.

Texts messages aren’t any safer

Almost all of these rules can apply to text messages too. So don’t think that just because you don’t use e-mail that much, you’re safe. 

You’re not.

Cyber criminals know more and more people are ditching e-mail for texting and are quickly adapting their tactics to target all you thumb-typers out there, so you need to heed these guidelines too.
  
Now, after reading all this, if you’re beginning to feel paranoid, and think every e-mail or text message you get could be bomb ready to go off in your face,  good. I did my job! You should feel paranoid these days! Because that old saying is true. Just because you’re paranoid, it doesn’t mean the world isn’t out to get you. 


Sunday, February 28, 2021

Cybersecurity speak: Is it all geek to you?


When IT folks like me start talking about cybersecurity we often throw around a lot of terms we just assume everyone is already familiar with. I mean in this day and age, who could possibly NOT know what phishing, ransomware, smishing, vishing, spear-phishing or even malware is?

Yet according to a 2020 report from the e-mail security firm, Proofpoint, quite a few non-IT people don’t.

So before I start telling you how you can better defend yourself against online threats, I’d like to spend some time defining the terms we IT folks often use to make sure everyone understands what I’m talking about from here on out. 

MALWARE

Let’s start with the most generic term, malware.

As the name implies, malware is any program or application that does bad things to your device (Mal = malicious or bad / Ware = an abbreviated form of software). It’s also not just something that can get installed on your computer or laptop. Malware can infect your cell phone, tablet, smart TV or any other internet-connected device. And contrary to what you might have heard, users of Apple devices are just as vulnerable to malware as those running Microsoft or Android-based software.

The writers of this bad software go where the users are and will target their programs to take advantage of the most popular platforms. So if iPhones are the most popular type of cell phones, you can bet that cyber crooks are working on ways to exploit these devices.

To get users to download these bad programs, criminals will often disguise this software as something desirable, often a “free” or heavily discounted version of a legitimate program like Microsoft Office, Adobe Photoshop;  a game or pirated copy of a popular TV show, movie or music.

RANSOMWARE 

Ransomware is a particularly nasty subset of malware which seeks out a user’s data, encrypts it so it cannot be opened by any program until the user pays a cyber criminal a fee to unlock it. What makes this type of malware so insidious is that the malware not only effects the device that it’s downloaded on, but can also spread to other devices the infected machine is connected to.

Ransoms can be as “small” as $100 or range into the millions. It’s often demanded in bitcoin, a type of virtual or electronic currency that is hard to trace, and there is no guarantee that even if you pay the ransom, the hostage taker will give you the key to unlock your data.

Most people have probably heard about the recent ransomware attacks on big hospitals and municipal governments, but do not let that fool you into thinking that cybercriminals only target big institutions with deep pockets.

They don’t.

You are just as vulnerable to this type of attack as they are, as this type of infection is often spread through bogus e-mails where the sender tries to get you to open an infected attached file or click on a link to website that will download the malware to your device.  

PHISHING

SOURCE: Jeffrey L. Price, 2020
Unlike, malware, the goal of phishing (pronounced “fishing”) isn’t to put any malicious software on
your computer or lockup your data. It’s to trick you into willingly reveal your sensitive information or data to an attacker. Attackers will do this by trying to impersonate someone you know or an institution you trust to not only get you to reveal your usernames, passwords and/or financial information, but also trick you into sending money to some fake account they have control of. Phishers also use these types of attacks to gather other background information on you such as your birthdate, social security number, previous employers, salary, etc. so they can use that information to open fake credit accounts in your name. 

These types of attacks come in the form of e-mails, but have been branching out to other types of electronic communications as well

SPEAR-PISHING

Spear-phishing is a phishing attack where the cyber crook is directly targeting someone or some company, using information specific to the targeted victim, rather than sending out a more generic-sounding message aimed at everyone on the Internet.  It is designed to make the victim think they are communicating with a known or trusted colleague.  An example of this type of attack is a fake e-mail purporting to be from a company’s chief financial officer, directing some low-level staff accountant to transfer money to some new or unknown account.

SMISHING

While phishing attacks generally take place over e-mail, smishing happens through text messages. So instead of getting an e-mail from someone masquerading as a trusted friend, colleague or institution, the fake message comes in the form of text. This type of text often asks you to click on a link which takes you to fake website which will then ask you for things like a username or passwords.

VISHING

While the term vishing maybe new, this type of attack has been around for a long time. It’s just a fake phone call from someone saying they are from a company you might do business with or government agency demanding money or other information. Examples of this might be a recorded call from the IRS saying you are behind on your taxes and will be audited unless you call a certain number.

SOCIAL ENGINEERING

The one thing almost all these different types of “ishing”-attacks have in common is that the attackers are trying to fool you into thinking they are someone you already know or someone you can/should trust. In the pre-internet days, we would have called this people Con Men or Con Artists, because their game is exactly the same as their online counterparts. Only instead of trying to talk you out of your money face-to-face by putting on some great performance and pretending to be someone they aren’t, they substitute in-person contact with e-mail (phishing), texts (smishing) and phone calls (vishing). But that’s not the only way social engineers ply their trade. Many hang out on social media sights trying to lure you into revealing information that could be used to impersonate you by creating quizzes to see which celebrity you are most like or buddying up to you by claiming to be some half-remembered high school acquaintance or friend of old friend you haven’t talked to for a while. 

AGE DOESN’T MATTER

SOURCE: Proofpoint 2020 State of the Phish report
While it’s easy to believe that social engineers and other online fraudsters only target less tech-savvy
and older folks, you’d be dead wrong. “Digital natives” – the generation who has never known a world without all this technology – aren’t immune from falling victim to cybercrime. 
In fact, it’s they appear even more clueless about the dangers lurking out there in cyberspace than their older counterparts. 

Maybe it’s because they just take this always-connected world for granted. Or maybe it’s a case of familiarity breeding contempt.  Maybe it’s even a failure by us older folks to teach them the little we know about keeping safe online. 

Whatever the cause, Proofpoint’s “2020 State of the Phish” report showed “Baby boomers outperformed everyone in their recognition of phishing and ransomware terminology. Millennials had the best recognition of only one term: smishing.”

The report showed that only 47 percent of adults between the ages of 18 and 22 correctly identified what phishing was compared to 65 percent of adults aged 39-54 and 66 percent age 55 and over. Older adults also scored 20 percent better than younger ones in knowing what Ransomware was too. 
Some of this isn’t really that surprising as other studies have shown folks that between 18-22 prefer texting to e-mailing. However, it’s still no excusing for not knowing that the same types of scams you might see in a text can and do effect other online communications as well. 

So next time you see a member of the Instagram-generation dissing an older colleague for not understanding the latest tech with one of their “OK Boomer” memes, remind them of this: Old-timers may not be as adept at using the latest tech as they are, but we older folk are better at something even more important – identifying cyberscams. (Then tell them to get off your virtual lawn before you ask them for the millionth time what a ‘hashtag’ is!)

2FA/MFA

We’ve talked a lot about jargon we tech-types use to describe the types of attacks you might see out there in cyberspace, but what about other jargon we use to describe defensive measures? Aren’t there things called firewalls? DMZs? E-mail protection gateways? VPNs? IP addresses? 
Yes, and while they are important, I’d argue they aren’t as important to the average person as 2FA or MFA is.

These acronyms stand for Two (2) Factor Authentication or Multi Factor Authentication, and what it does is require you to prove who you are by providing two (or more) forms of identification before you can login to a website or application.

Think of this as having to provide both your ticket and driver’s license before boarding a bus or airplane. Or having to provide your birth certificate, passport, and a current utility bill in order to renew your driver’s license.

In the online world, 2FA/MFA works by sending you a text message, e-mail or phone call with a temporary code to a secondary device or account you own. Without entering this one-time-use code on the website on in the program, you won’t be able to log in, even though you’ve entered the correct password. 

The idea is that while a cyber crook might have figured out your username and password, they won’t have access that second piece of information or device (often your cell phone), thus be unable to impersonate you.  

Like everything else in life, this is not foolproof, but the more hurdles you make cybercriminals jump over, the more likely they are to abandon the attack on you in favor of easier targets. So if you are not using 2FA/MFA now, you should start.

Immediately.

Look these days we all carry a cell phone, and while having to grab it, look for that code and enter it every time you need to login someplace may seem like a giant inconvenience, the extra 30 seconds it takes will seem like nothing when trying to get your Facebook account back after some hacker has stolen it from you.

Ultimately this is what cybersecurity is all about: taking time now to prevent a lot of headaches later. And that now that you understand some of the jargon we IT folk use, I hope you’ll come back next month when we start discussing how to actually spot and defend yourself against these types of attacks.

Until then, stay safe out there! 

Wednesday, November 25, 2020

Follow these online shopping tips to stay safe this holiday season


 Cyber Monday is right around the corner and cybercriminals are gearing up to take advantage of unsuspecting people during the biggest online shopping day in the United States.  It’s especially important this year, as many people will be foregoing their annual shopping trips to potentially crowded malls and stores to avoid the risks of contracting Covid 19.

As usual, cybercrooks will try to lure you into giving up your personal information like your credit card numbers, usernames and passwords, social security number and even date of birth by doing the following:

  • Creating fraudulent (but real-looking) web sites and email messages
  • Intercepting insecure transactions
  • Targeting computers that are not running the latest security patches, have minimal or no antivirus software on them or are already infected with malware.

Fortunately, with a little foreknowledge and some precaution, you can avoid many of these cyber-threats.  Think of these eight steps recommended by IT security professionals, as the same type of common-sense things you’d do when shopping in person: like locking the car and putting away your cash or credit card when you’re done with your purchase.

Shop reliable websites and get there safely

If an offer sounds too good to be true, it probably is. Don't be fooled by the lure of great discounts from unfamiliar websites or companies you may not have heard of.  Most likely they are fake! Use the sites of retailers that you know and trust, and get to their sites by directly typing a known, trusted URL into the address bar instead of clicking on a link. Also look closely at the names of the company and make sure they are who you think they are. Many scammers may try to fool you by misspelling or using a look-alike name of a better known company (for example Wallmart.com or Wal-Mart.com instead of Walmart.com or Amazzon.com instead of Amazon.com)

Beware of seasonal scams

Fake package tracking emails, fake e-cards, fake charity donation scams, and emails requesting that you confirm purchase information are another common tactic cyber criminals use this time of year.  Treat every message you get like this as suspicious and use known, trusted web address instead of clicking on the links in these messages. If you don’t know the URL of a charity or company look it up and confirm it across several websites. Which leads us to our next tip:

Graphic courtesy of Kaspersky Labs https://www.kaspersky.com/

Conduct research 

When considering a new website or online company for your holiday purchases, read online reviews of it on other websites to see whether others have had issue with them. Never trust the reviews on the company’s web site itself. You can use sites like Yelp.com, Better Business Bureau and Consumer Reports to help you rate shopping sites, while the Federal Trade Commission recommends using BBB Wise Giving AllianceCharity NavigatorCharityWatch, and GuideStar to check out charitable organizations .

And remember, if a site looks suspicious, avoid it!

Think twice before clicking on links or opening attachments

Even if links appear to be from people you know, legitimate organizations, your favorite retailers, or even your bank, messages can easily be faked. Use known, trusted URLs instead of clicking on links. And only open known, expected attachments. If in doubt, use a phone number you know to call your bank, a store or your contact and find out if they really sent you that attachment. I you can’t do that and still are in doubt, throw it out!

Make sure your device is patched and up-to-date

Before shopping online at anytime of the year, you should always make sure your device, apps, browser, and anti-virus/anti-malware software are patched and up to date. Make sure automatic updates are turned on and periodically restart your devices to ensure that updates are fully installed.

Protect your passwords

Never reveal your passwords to anyone. Make them long, strong, unique, and use multi-factor authentication (MFA) wherever possible. MFA requires you to have a second device – most often a cell phone -- that a message can be sent to, to ensure it’s really you trying to log into some website and not someone who may have stolen your username or password.

Use different passwords for different accounts and don’t use the same passwords you use at home for work accounts and vise-versa. We IT pros know that doing that is cumbersome and it’s hard to remember all those passwords, but that is what cybercrooks count on! They know that if they crack one of your passwords they will often be able to gain access to all your other accounts as well!

To help you remember all those different passwords consider using a password manager such as LastPass or RoboForm to store all them. That way you only have to remember one master password. Better yet buy a small notebook like an old-fashion address book and write down all your usernames and password in that and always keep it in your desk at home.

And finally, don’t let your apps and websites remember your passwords. If your device is ever stolen or lost, whoever finds it will then have a record of all your usernames and passwords.

Check your credit card and bank statements regularly

These are often the first indicators that your account information or identity has been stolen. If there is a discrepancy, report it immediately.

If you have the option, turn on text alerts. Most banking apps and sites provide them and allow you to create alerts for things like transactions over a specified dollar amount or a daily text summary of your current balance. Getting these types of alerts can help you to spot signs of unusual activity before thousands of dollars are either charged or withdrawn from your accounts.

Lastly, check your credit report at least annually. The Federal Trade Commission provides information about getting free credit reports and what to do if you find discrepancies.

Secure your home WiFi

To prevent eavesdroppers and data thieves, ensure that you have a strong passphrase (12 characters or more with your wireless network set to WPA-2). Change your network’s name (SSID) from the default to something that does not obviously belong to you. Limit who has administrative access to your home network. Finally, log into your wireless router periodically to check for software updates (many home routers don’t auto-update).

Get savvy about WiFi hotspots and public computers. Treat all WiFi hotspots and public computers as compromised, even if they appear to be safe. Limit the type of business you conduct on them, including logging in to key accounts, such as email and banking, and shopping. And set your devices to “ask” before joining new wireless networks so you don’t unknowingly connect to an insecure or fraudulent hot spot.

Following all these tips may sound like a lot to remember, but they’re really no different than the precautions you’d usually take when planning a shopping trip to the mall during the busy holiday season. And they are certainly easier than trying to find that coveted parking spot close to the entrance in a crowded lot!