Saturday, February 4, 2017

CEO fraud and W-2 scams running at full-tilt during tax season

In Wyoming, two health organizations fell victim to a W-2 phishing scam last month. At Campbell County Health, an employee clicked a link in an email that appeared to be sent by a hospital executive. End result: SSNs and W-2 information of 1,400 employees were disclosed. A similar breach occurred at eHealthInsurance when one of their employees sent W-2 information in response to a phishing email that he/she believed was sent from a company executive. 
In Kansas, Sedgwick County lost $566,000 when a Georgia (U.S.) hacker sent an email to a county employee that appeared to be from the CEO of another company. The email included a form requesting payments be made electronically to a new account at a Wells Fargo Bank in Georgia. The payment was made. 
In this particular case, the hacker was caught, and George S. James is now charged with one count of wire fraud. See https://www.justice.gov/usao-ks/pr/georgia-man-charged-cyber-crime-cost-sedgwick-county-566000
The moral of the story: Things are not always as they seem
It's called "CEO fraud" because typically the email address of the CEO is spoofed in the "From" line on an email that is delivered to an employee or other C-level executive of the company. Just because an email appears to come from someone you know doesn't mean it actually is.
The lesson here is that you should never send sensitive information like W-2s (or money!) based on an email you received. Always verify an email's origin before taking action. When it comes to sharing private or otherwise sensitive information, trust but verify.

Saturday, January 7, 2017

Hey Mom, is that really you on the phone?

There is no end to phishing innovations. The new Adobe VoCo software can take an extremely short audio recording of someone’s voice—say, from a YouTube video, and allow a user to create new audio in that person’s voice… all on the fly. This is pretty amazing technology, but the potential for voice phishing is scary. Think of the ways this could be exploited at work and at home. For example:

“Mom, I am in jail and my lawyer needs $3000 to bond me out.”
“Sis, what is your SSN again? I need to make you a beneficiary on my new benefits program.”

The possibilities are endless. Will all humans need to invoke phone passcodes going forward? Or should we invoke call-backs whenever dealing with sensitive information by phone? ("I will call you back with that information."

You decide.


Wednesday, December 28, 2016

Update your Netgear wireless router or be hacked

A couple of weeks ago, Netgear announced that there is a major security vulnerability in several router models that allows anyone within range of your wireless network to log in as administrator without credentials. So many things can go wrong if this happens to you. Even the US-CERT recommends that you don't use the router until you've updated it.

Check your home wireless router. Popular brands include Linksys, Asus, D-Link and Netgear, among others. If your manufacturer is Netgear, check which version you have and update your router with newer firmware asap.

The page listing the models and the steps to update the firmware is here: http://kb.netgear.com/000036386/CVE-2016-582384.

Even if you don't have a Netgear router, it is always a good idea to log in to your router occasionally to see if it needs a firmware update. Or set a Google alert that queries the manufacturer's name and model. Add the word "firmware" to your query and configure it to deliver a notification to you whenever there is new information available on the Internet.

For more information, see the Forbes article here: http://www.forbes.com/sites/leemathews/2016/12/12/these-netgear-routers-are-scarily-easy-to-hijack/#1f89ad0d9537.

Saturday, December 17, 2016

Advice if you use Yahoo: Don't.

By now the world knows about the one billion Yahoo accounts breached over the past three years. The best advice I've seen from the experts this week is "get rid of your Yahoo account." Likewise, if you have an account with Yahoo partner AT&T, consider cancelling that as well.

Tips for moving away from Yahoo:

  1. Back up your Yahoo data like old emails, contacts, calendar entries and photos. This includes Flickr photos. See instructions at: https://help.yahoo.com/kb/download-save-info-lose-good-sln15129.html
  2. Delete your Yahoo folders.
  3. Navigate to the Delete Your Account page at https://login.yahoo.com/?.done=https%3a%2f%2fedit.yahoo.com%2fconfig%2fdelete_user%3f.scrumb%3d0, and terminate your Yahoo account (see screen shot below). This can take up to 90 days to process. 

Terminating your Yahoo! account


After successfully terminating your Yahoo account:

  1. If you have ever used your Yahoo password for other sites–which is always a bad idea–change the password and security questions for those accounts. For sites holding really sensitive data (banking, insurance, taxes, medical, etc.), consider modifying your user name as well by appending or prepending it with a few characters, numbers or symbols (where allowed). 
  2. If you have mobile phone number associated with your Yahoo account, and you still subscribe to that number, then you may be more prone to SMS phishing (a.k.a. smishing). Be on the alert for smishes and don't click links in text messages.
  3. Open a Gmail account.

Sunday, December 11, 2016

Don't get hacked this holiday season!

The holiday season is here. This is the time of year when scam artists are operating at full-tilt. Half of shoppers are buying gifts online this year. I've blogged about this in the past. This post is simply a reminder to be on your toes and to not share information about yourself with anyone who calls or emails you.

For tips in preventing identity theft and online scams, see the StaySafeOnline.org article Hackers Love the Holidays Too: How to Protect Yourself from Information and Identity Theft, summarized here.

  • Avoid making purchases when using public Wi-fi.
  • Never clicks links in unexpected, unusual or out-of-character emails - navigate to the web site directly from your browser. Just because an email looks like it is from someone you know doesn't mean it is legitimate.
  • Never download or open attachments sent to you in email.
  • Use anti-virus software and activate the firewall on your operating system.
  • Delete unused accounts on web e-commerce and other sites where possible.

Remember: Stop. Think. Do not click.

Wednesday, November 23, 2016

Watch out: ɢoogle.com isn’t the same as Google.com

It isn't unusual for bad guys to buy fake domain names that resemble real ones. Often they use simple character substitution.

For example, in h0medep0t.com, you'll notice there is a zero (0) where there should be a letter O. Although this example looks pretty obvious, often we don't take time to scrutinize what's in the address bar of the web browser.

Or, we jump to the link without looking closer, such as in an email or a text message where the real URL doesn't match up with the link displayed. In most email programs, like Microsoft Outlook, you can hover over the displayed link with your mouse cursor to see the actual web location that the link redirects you to—the URL—but this feature isn't available in all operating systems or in all email clients. You won't necessarily have this ability on your smart phone or web email client, for example.

This is why I don't click links sent to me—even from people I know—without scrutinizing them first. Here is a PCWorld article with more information about validating links: http://www.pcworld.com/article/248963/how_to_tell_if_a_link_is_safe_without_clicking_on_it.html.

Here is more about the Google scam. Scammers use a domain name that looks like Google.com but isn't: ɢoogle.com. Look at the "G." It isn't a standard letter that you'd type on a keyboard. It is actually a symbol, which uses a different character set. International (or extended) characters like this one are rendered on your computer screen by typing a specific combination of keys and numbers on a standard keyboard.

For more info, do a web search on the phrase "character set."

Here is the full article about the bad ɢoogle.com:
http://www.analyticsedge.com/2016/11/heres-a-secret-%C9%A2oogle-com-is-not-google-com/.

Saturday, November 19, 2016

Beware fake phone calls from "customer service"

It cannot be said enough: hang up on callers whom you do not know, especially if they are trying to elicit any information from you. Better yet, if you don't recognize the phone number of the caller, don't pick up. Scam artists are less likely to try again if you're not answering.

Protect yourself and your employer by taking advantage of Caller ID service on your phone. Personally, if a call comes in to my cell phone from an unknown number, I let it go to voice mail.

It seems there is a new phone scam every day. Reported by Trustwave this week is a ruse that targets hotel and restaurant chains. This scam is perpetrated by a known cyber criminal gang that employs very convincing social engineering techniques like name-dropping and familiarity with other "insider" knowledge about your org chart.

When the caller reaches the hotel or restaurant's customer service line by phone, he/she claims to be a client who cannot log in to the reservations system. The caller may claim to know your boss or C-level executive.

Remember that this type of information about your company is available on the web to anyone. It takes little effort to mine LinkedIn profiles and gather intelligence about your organization's personnel structure.

An email is sent to the customer service rep with a malicious Microsoft Word document attached. When clicked, malware is executed behind the scenes that provides access to the company's credit card database and other sensitive information.

Click here for the story: This malware attack starts with a fake customer service call. When in doubt, just hang up!