Saturday, May 28, 2016

Beware "overlay" skimmers installed at Walmart check-outs

Look before you swipe, and don't ever swipe your debit card. Wherever possible, dip your chip-enabled credit card instead of swiping it.

We've said this all before. Today, security journalist Brian Krebs gives us reason for a reminder.

The card skimmers that thieves use to steal the data about you and your account—data that is stored in the magnetic stripe—are so well crafted these days that it is difficult to tell they're a ruse. Take a look at the photo here. Can you tell it's a fake?

ingenico_inserted

Probably not. Here is what it looks like before the thief snaps it onto the existing point-of-sale device:

A skimmer made to be fitted to an Ingenico credit card terminal of the kind used at Walmart stores across the country. Image: Hold Security.

This device records your account information when you swipe your card, including your PIN. The data is downloaded later when the fake front is retrieved by the thief.

These were found installed in Walmart stores in Virginia and Kentucky. But they can be installed anywhere that uses this particular Ingenico credit card terminal. Grocery store shoppers suffered card thefts when similar devices were installed at Safeway stores a few months ago.

For more information and a surveillance snapshot of criminals installing an overlay skimmer at a Walmart self check-out station, see Brian Krebs' blog posting Skimmers Found at Walmart: A Closer Look.

If your card is chip-enabled, dip it. And never swipe your debit card.

Saturday, May 7, 2016

Can your phone be hacked?

Yes, of course that computer in our pocket is easily hacked. When that happens, the hacker can see all of your phone data—email messages, account information, credit card numbers, text messages, bank information—and the bad guy can even listen to your calls. What is even creepier than that is the fact that the hacker can turn on your video camera and watch you without your knowledge.

How hard is it to hack a phone? It's not. Watch this 13-minute CBS News 60 Minutes episode "Hacking Your Phone," for a live demonstration of hackers listening in on a congressman's phone.

They say there are two types of people in this world: Those who know that their phones have been hacked, and those who don't know that their phones have been hacked.

Want more protection for your phone? Stay educated and alert, don't randomly connect to public Wi-Fi networks, don't click unexpected links (or attachments) delivered to you via texts or email messages, encrypt your data, keep your operating system and apps up to date, and consider installing a security app like Lookout. That happens to be the app that I use.

Other tips:
- FCC Smartphone Security Checker
- Smartphone Security (by Kaspersky)
8 common sense tips to keep your smartphone secure (by Verizon)

Monday, April 18, 2016

Now is the time to uninstall QuickTime from Windows

Apple QuickTime is a media player that can be downloaded and installed for free on your Windows computer, not unlike Windows Media Player.

Last week, Apple ended support for QuickTime on Windows due to critical security flaws. Apple will no longer support or provide security updates for this software and recommends that it be removed. I have uninstalled it from my computer, and you should too.

For more information, see US-CERT for more information at https://www.us-cert.gov/ncas/alerts/TA16-105A, or read the TrendMicro article at http://www.zdnet.com/article/apple-deprecates-quicktime-for-windows-with-two-security-holes-unpatched-trend-micro/.

Instructions for removing QuickTime for Windows can be found on the Apple Uninstall QuickTime page.

Do it today!

Sunday, April 17, 2016

Phishing alert: They use your home address in this one

Beware a new email phishing campaign that is targeting people by using your home address and claiming you are overdue payment on an invoice. 

The message in this one uses good grammar and is fairly well worded but is quite dangerous. If you fall victim by clicking the link, it executes a new variant of ransomware that doesn’t require a network connection to function. As we all know from previous posts on this blog, ransomware is designed to encrypt all of your files and hold the decryption key for ransom. Pay up, or lose all your files that have not been backed up to a separate system.

Folks, don't fall for this. The best way to avoid becoming a victim of a phishing attack is simple: Do not click links in email unless you've validated the sender, and don't open attachments to emails unless you are 100% certain they are safe. 


Have you backed up your files yet? Better safe than sorry!

Previous posts are:


Saturday, March 26, 2016

How easy it is to install a credit card skimmer

Ever wonder how easy it is to install one of those skimmers that steals your credit card information straight from the magnetic stripe on the back of the card? Check out this YouTube video to see how a pair of convenience store shoppers install a credit card skimmer on the point-of-sale (POS) device in two and a half seconds. It's pretty amazing.

And here is a 5-minute ABC News Nightline story on YouTube showing thieves installing a skimmer on a gas pump. As I was watching this, I wondered how the bad guys are able to open up the pump's front panel. Turns out, every gas pump uses a universal key, easily purchased online for a few bucks.

Want to know more about these skimmers? See Brian Krebs' blog All About Skimmers.

The FBI warns: Taking a Trip to the ATM? Beware of Skimmers. Recently, here in Georgia, an investigation was launched covering six states, as described in this news story: Secret service launches 6 state investigation into ATM skimmers.

If you think you've been a victim of credit card skimming, contact your local U.S. Secret Service field office. If you're not sure whether to report, see When and how to report fraud to the U.S. Secret Service.

Be smart when swiping your card.

  • Never let a cashier or server swipe it for you or take it out of view.
  • Keep an eye on your credit card account, checking every statement line-by-line
  • Report any suspected fraud immediately to your bank, certainly within 60 days
  • Don't swipe your card at gas pumps that are "in the shadows," or pay inside
  • Look before you swipe


Wednesday, March 16, 2016

Beware big uptick in ransomware this week!

Last July, we posted What is ransomware? If your computer is infected with ransomware, the hacker encrypts all of your data and then offers to decrypt it in exchange for payment. If you do get hit with ransomware, you have two choices: (1) pay, or (2) wipe your hard drive and restore it from backup.

Did you know that your computer can get infected with ransomware when you visit safe, familiar web sites like MSN.com or AOL.com, national weather web sites, everyday news sites like the New York Times, and other "safe" places? It's true. That's because these sites host advertisements, which are run by third parties that they do business with. All those little ads that you see popping up on every news site you visit—that is called adware.

If you get a pop-up like this, you are a victim of ransomware:



It isn't that the big name web site owners like New York Times aren't being careful, it's that the adware companies suffer some sort of breach or domain name takeover before anyone else realizes it, and they start serving up malicious ad links on the "safe" sites that we are familiar with and use every day.

And if you're smart, you do not click those links. They can be downright convincing, but if your personal rule is "don't click," no matter how enticing an ad may be, then you are practicing safe browsing. Make this your mantra when surfing the web: Do. Not. Click. Ads.

For details read Big-name sites hit by rash of malicious ads spreading crypto ransomware [Updated].


Saturday, March 5, 2016

If Microsoft "tech support" calls, hang up!

I actually saw a very bright young college grad fall for this scam a few years ago.

It goes like this: You get a phone call from someone who says is name is so-and-so (Mack, Jack, Mike, Matt, Joe or what-have-you), and that he's with Microsoft Support or Windows Tech Support—something along those lines. He may speak with a thick accent.

He'll tell you that your computer is showing up on his monitor as being infected with a virus and that in order to prevent something really awful from happening to your data, he's going to help you fix it. Typically, he'll direct you to a web site and may even offer to help you change settings in your browser configuration (e.g., a proxy server IP address) if the site appears to be blocked.

If the conversation gets this far, it is way past time to hang up. Never, ever make changes to your security settings or navigate to a web site URL given to you by an unknown caller. Oh, and they may continue to try to call you at least once more before giving up.

Microsoft does not make unsolicited calls to help you fix your computer.

In fact, if anyone calls you claiming to represent some established corporation, retailer, charity, or government agency and then asks you to either (1) navigate to a web site, or (2) provide a credit card number or other personally identifying information, just hang up. Never give your information to an unsolicited caller, even if he says you already have an account with his organization. That's called social engineering; don't fall for it.

For more information about the tech support scam, see this page at the Microsoft Safety & Security Center: Avoid scams that use the Microsoft name fraudulently.