Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Friday, February 8, 2019

What is Phishing and How To Spot It


The blog Phishing.org defines phishing as



a cybercrime in which a target or targets are contacted by email, telephone or text message by someone posing as a legitimate institution to lure individuals into providing sensitive data such as personally identifiable information, banking and credit card details, and passwords.






We've all been exposed to phishing emails. It's easy to be taken in by them, although it is also possible to avoid them with a little knowledge and effort. The phishing scammers are getting more sophisticated but fortunately the basic rules for spotting these scams still work in most instances. This graphic has a lot of good advice.


https://www.knowbe4.com/what-is-social-engineering/

Notice that the graphic contains advice for business email users, not just personal ones. If you use email at work, please pay attention! This advice is related to another common fraud called spear phishing. That's an attempt to get insider information from a business--information like email addresses of top executives or access to customer data. Sometimes the data will be used directly, as in an order from the CEO to transfer money to a fraudulent account. At other times it will be used to breach the system and install malware, permitting long-term damage. In any event, this post focuses on the personal email user.

The basic advice for spotting phishing emails is:
  1. If it sounds too good to be true, it undoubtedly is.
  2. It is urgent; the recipient will miss out unless she responds immediately.
  3. It asks for personal information. Never reply to this type of email, even if (especially if) it purports to be from an institution like the IRS or your bank. Never. Period. Don't even confirm personal information sent to you in an email.
  4. The sender is unknown or looks fishy (pun intended :).
  5. There are hyperlinks that look strange--don't match the sender, for example. It's best not to even click on these links to check them out.
  6. It's poorly written with spelling and grammatical errors or awkward sentence structure.
  7. It has an attachment. Don't even bother to examine the attachment closely--if the email is in any way suspicious don't open the attachment. Malware lives there.
  8. WHEN IN DOUBT, JUST DELETE IT. 
The chances you are going to ignore a legitimate email that has any of these characteristics is pretty low. However, it you're a worrier, pick up the phone and call the supposed sender. That's safe!

All legitimate internet businesses are concerned about phishing; it makes the internet less trustworthy for all of us. Google has performed an excellent service with this exercise in spotting phishing emails. Use the link provided and give it a try!

https://phishingquiz.withgoogle.com/

Don't worry about being embarrassed by naivete. I missed a rather humiliating number of the 10-item quiz and Google was very nice about it!

Take the quiz and stay safe!

Saturday, January 5, 2019

Five Top Data Threats Consumers Should Watch Out For In 2019

It's not clear that security threats are coming from genuinely new directions in 2019, but it is clear that some of the existing threats are becoming more damaging. Here's a look at 5 powerful and persistent threats, not in order of presumed priority.

Cybersecurity resource site     https://www.stopthinkconnect.org/

- The IoT provides easy access to many smart homes. When did you last buy an appliance, or perhaps even something as simple as a door lock, that wasn't connected to the internet? Most are, and manufacturer security is notoriously weak. Begin by changing the manufacturer-supplied password and continue by reading the instructions to ensure that protection like automatic software updates is in place. It's likely that threats will become ever more sophisticated.

- Mobile threats multiply with emphasis on fake apps. Traditional threats like advertising that delivers malware and phishing attacks--born on the desktop and migrating to mobile--continue to affect millions of consumers. Even more worrisome, because they are so hard to detect, are fake apps. They can be found anywhere, even on the app stores. The malicious apps are removed when identified, but new ones take their places. One security firm suggests three ways to identify fake apps:
  1. Look for the developer name. If it is not the same as the brand, there's something wrong.
  2. Read the reviews and see if they appear legit.
  3. Be suspicious of unreasonable promises--or unreasonable requests like writing a review before you download the app.
It would be good to read the entire post.

- Phishing is now spear phishing. Here's one example, mortgage wire fraud:

home buyers are tricked into wiring closing fees to a rogue party by an email arriving from a trusted mortgage agent. “The hacker breaks into the mortgage lender’s (or title agent’s) computer and takes note of all the upcoming pending deals and their closing dates,” he says. “Then the day before the mortgage agent would normally send out an email telling the client where to send the closing money, the phisher uses the mortgage agent’s computer to beat them to the punch. The unsuspecting client wires the money, which is rarely recovered, and ends up losing the house (unless they can come up with another substantial closing payment, which most can’t do).” 

Spear phishing can be very close to home and very personal. At least 3 employees at Wichita State University responded to a phishing email by supplying their university ID number and lost their entire paychecks, which were diverted and never reached their banks. Individuals should never respond to this kind of request for information and employers have a huge responsibility to educate and remind their employees of the danger.

- Artificial Intelligence leading to smarter attacks on a larger scale. What AI can accomplish remains a mystery to many web users because it's highly technical in nature. Look at it this way. AI can help cybercriminals deceive users directly or to trick the technology itself.  I wrote about fake news during CyberMonth and the warnings there are relevant (1, 2 and more).

https://www.bbc.com/news/av/technology-40598465/fake-obama-created-using-ai-tool-to-make-phoney-speeches

Here an example of a totally fake Obama message that could have been aimed at web users. It was produced by researchers and they explain the basics of how they did it. It's easy enough to understand, but harder to actually do. However, the technology is readily available to web users who care enough to find it and learn to use it.

Harder to understand are techniques used to hijack web sites. Here's a brief article about the use of fake fonts to disguise landing pages created for phishing schemes. It's not necessary to understand how it is done to understand there are ways of deceiving users that are hard to identify. The article doesn't say so, but the fake pages should have URLs that are not exactly the same as that of the actual brand. Users need to beware, but they also need to be able to trust brands, and that's getting increasingly hard to do. When in doubt, especially about a followed link, close it and go directly to the brand website. And make a practice of notifying brands when you see something that appears suspicious. How the brand responds is one way of knowing whether to trust it or not.

- Following the implementation of the EU's GDPR in 2018 laws protecting privacy will continue to emerge.  The General Data Protection Regulation is a sweeping reform of European privacy laws, which were already stronger than those in the US. I explained how and why the law applies to US web users in a 2017 post. Users currently see the effects in things like cookie warnings and explicit requests to contact users when they visit a site. See if your state has recently passed a law regarding data privacy on this consumer-oriented site. There are also legal sites that cover the issue.

The focus in the US is on the states because the federal government has moved in the other direction. The repeal of the Net Neutrality law made it possible for ISPs to collect and sell data about the activities of their users. Who knows more about us? Watch for a followup post on this issue soon.

These are five broad categories that cover many types of threats. Customers need to have high expectations of the brands they use in terms of how well the brand protects their data. It really helps for brands to know that their customers are paying attention and even taking actions on the basis of how much they trust the brand.

'Paying attention' is the relevant phrase. Every individual user needs to be alert to attempts to breach their privacy and steal their identity. My new year's resolution is to do all I can to be helpful!

Stay Safe in 2019!

Sunday, October 21, 2018

Sunday Advice: What's a Suspicious Email?


A suspicious email is any message designed to get the recipient to provide personal data. Phishing is the most common method. Here is a definition of phishing from StaySafeOnline:

A phishing attack is a form of social engineering by which cyber criminals attempt to trick individuals by creating and sending fake emails that appear to be from an authentic source, such as a business or colleague.

Their advice on how to spot phishing emails is:
  1. The email asks you to confirm personal information
  2. The web and email addresses do not look genuine
  3. It’s poorly written
  4. There’s a suspicious attachment
  5. The message is designed to make you panic.
It often takes a technical specialist to conclusively determine whether an email is a phishing attack or just something stupid. The layperson should not worry about being sure it is phishing. Just being suspicious is enough to take the appropriate action

When in doubt, throw it out! 

Don't want to run the risk of alienating a friend or colleague? Compose a new message using your own contact information. Briefly explain that the email looked funny and you discarded it to be on the safe side. If it was important, they can reply to your email. 

Watch for suspicious emails
and
Stay Safe!

Thursday, October 18, 2018

Free Cybersecurity Tools


I found this set of mobile security guidelines on twitter. They are excellent for businesses as well as for individuals.

It led me to the site of KnowBe4, a cybersecurity firm. There I found a set of free tools that can be used to assess specific cyber risks.


https://www.knowbe4.com/

Some risks can be mitigated by cybersecurity training--phishing  (and smishing and vishing!) is high up on that list--awareness of the danger is key. Some may require paid services. The point is to determine where your business is vulnerable before making investments in cybersecurity.

A hint to the wise: if I found these free tools on one try; there are undoubtedly more out there. Don't hesitate to broaden the search and become well-versed in the nature of cyber risks and how your firm can deal with them.

Stay Safe!

Why I'm Writing A Blog About Personal Data Protection

The subhead states the mission of the blog. I want to make key methods for protecting user data privacy and identify comprehensible to the m...