Showing posts with label account takeover. Show all posts
Showing posts with label account takeover. Show all posts

Thursday, February 28, 2019

Beware of Compromised Personal E-mail

Over the last few years personal e-mail providers like Yahoo and AOL have had massive data breaches, in which user's e-mail addresses and passwords were compromised.  Recently there have been a number of phishing campaigns whereby these compromised e-mail accounts are being used. 

How this works
So a Yahoo or AOL e-mail account owner who has never changed their password, and a hacker gains access to it (Most likely from a password list bought on the Dark Web).  The hacker then send a personalized e-mail to everyone in the compromised account owner's Address Book with a link to either collect credentials or launch malware.  The sad thing is some people have been getting these phishing e-mails from people close to them who have passed away.  Other's are getting e-mails from friends and relatives that seem legitimate and so the recipient innocently clicks on the link seeing that the e-mail is from someone they know.

Security Tip
Ask yourself these questions when you receive an e-mail:
  1. Do I know the sender?  (hover your cursor on the display name or click the display name to see the real e-mail address)
  2. Am I expecting this e-mail or any web links/attachments from this sender?
If you answer "No" to either question, it is probably a phishing e-mail.

If you know the sender, pick up the phone and verify that they sent you the e-mail and any attachments or web links.  Don't reply to the sender's e-mail as the hacker has control over the e-mail account.

In 2018, the number of malicious web links (URLs) sent by cyber criminals was more than twice as many as malicious attachments sent.

Think before you click!


In addition, if you have a Yahoo or AOL e-mail address and haven't changed your password in the last year,,,,CHANGE YOUR PASSWORD NOW!


Be Secure!

@TJMProfessional

Thursday, October 4, 2018

How to Overcome Your E-mail Insecurity - Part 3 of 3

Phishing
Less complex than BEC, but even more widespread, phishing e-mails will usually come from free e-mail providers, ex. gmail, yahoo, outlook/hotmail, but will have a display name that is different than the actual e-mail in trying to gain your trust.  The e-mail is supposedly from DHL, UPS, DropBox, Microsoft, or some large company that you trust, but then you find out that the underlying e-mail address is not from that companies e-mail domain, but is a gmail account or a similar domain like DHL_Accountservices.com, etc.  

Some recent attacks actually impersonated domains to try and fool employees at the actual business.  An example is if your business e-mail domain is "marysdonuts,com", the impersonated e-mail domain might be rnarysdonuts.com, whereby the "m" is replaced with an "r" and an "n" to fool your eye into thinking it's a lower case "m".  Cyrillic alphabet characters have also been used to play tricks on your eyes.

Security Tip:  Like the BEC e-mails, there is a call to action, usually an attachment (virus infected) or a button/link to click. 

Ask yourself these questions when you receive an e-mail:
  1. Do I know the sender?  (hover your cursor on the display name or click the display name to see the real e-mail address)
  2. Am I expecting this e-mail or any attachments from this sender?
If you answer "No" to either question, it is probably a phishing e-mail. Again, if you do know the sender, pick up the phone and verify that they sent you the e-mail and any attachments. 

So the lesson at the end of the day, is if you want to be safe, and not be a victim of e-mail fraud, BEC, or phishing you should use the low tech communication device that was invented by Alexander Graham Bell and verify before taking action based on e-mailed instructions.  After all, as discussed in my Part 1 blog post, e-mail is not secure by design.

Be Secure!

@tjmprofessional


Thursday, September 6, 2018

How to Overcome Your E-mail Insecurity - Part 1 of 3

As a small business owner you probably have a lot of things keeping you up at night.  Your use of E-mail in doing business probably wasn't one of them, until you read this post.

E-mail was not designed to be secure.  It was created to be a simple electronic messaging platform for trusted networked computers back in the late 1960's, and grew in use during the 1990's.  It eventually replaced both the telephone and the fax machine as the primary communication medium for business in the 2000's.  Its security flaw of being "trusted" remains from its original 1960's design, and is what has also made it the preferred attack vector for cyber criminals to defraud both individuals and businesses.  Rather than dwell on what we can't change, let's focus on what we can.

The E-mail Interloper
Over the last year a very popular type of e-mail hacking has been targeting attorneys, loan officers, and realtors. (Although there have been similar scams with vendor payments and payroll provider settlements)  A hacker compromises one of these party's e-mail accounts.  Rather than make their presence known, they will just sit back and read through the person's e-mails and wait for the right situation to arise, usually a real estate transaction.  Once the hacker knows the particulars of the deal, they wait until the time of closing and then send an e-mail from the compromised party's e-mail account stating to the buyer or the buyer's agent that the wiring instructions for the settlement has changed and to use the new bank routing and account number to transfer the proceeds of the transaction.  The buyer then sends the wire to the hacker's bank, and by the time all the parties figure out what has occurred, the hacker has since moved the money to several other banks and eventually wires the funds to an overseas bank and "poof" hundreds of thousands, potentially millions are gone.  If that wasn't bad enough, now everyone gets lawyer-ed up to try and figure out who is at fault, and the real mess begins.  Regardless of whether you are the buyer, seller, a real estate agent, or attorney, this can be a business nightmare as both the money and the deal are gone.

Security Tip: If you are in the real estate business, or another business where you frequently send wires to different parties, always pick up the phone and call a number (that you already have on file) and verify with the receiving party the wiring instructions before sending the funds.  A simple five minute phone call will defeat an e-mail take over scam, and will also demonstrate to your customers and business partners that you take security and doing business with them seriously.  If your clients are the ones sending funds, remind them to do this one simple thing to protect themselves, and your commission.


Be Secure!


@tjmprofessional

Friday, January 12, 2018

Vishing, It's not Just for Kids Anymore.

When I was a kid, it was common practice to phone scam your grumpy neighbors.  Calling and asking; "Is your refrigerator running?", and getting the response "Uh yes it is.", and then saying "Then you better go catch it!", was something that gave us hours of childish joy at the expense of our severely annoyed neighbors.

I had thought those days were behind me, but I guess not.  So in addition to phishing, another attack vector that scam artists and hackers are starting to employ with greater frequency is Vishing or Voice Phishing.

The common approach is that they get a list of names and phone numbers and will call folks and pose as their electric utility, their cell phone provider, or the water company.  They will be calling because they either didn't get your last payment and now have to shut off your service, or have some other urgent matter to speak with you about.   I have also seen where this is automated using a phone dialer and a recorded message instructing you to call another phone number immediately to resolve the issue.  They will then try to get you to provide them with your personal information in order to "verify" who they are speaking with.  They will structure the call in a way so they get your information in pieces so it doesn't raise any suspicions.  They may try to get your banking or credit card information in order to "pay your overdue balance".  Remember, if one of your service providers is calling you, they should already have your information as they are calling your phone number of record.

Red Flags to look for:

  1. Your utility companies will give you multiple late notices and you will need to be 2+ months late on paying your bill before they shut off your service.
  2. If you get one of these calls and are not sure if it is a scam, hang up and call the phone number on your last bill.  This way you will know if it's legit.


Another popular vishing scheme is to call posing as the IRS.  This scam has been targeting businesses and individuals alike.  The "agent" will claim that you have an outstanding tax debt and it has to be paid immediately or you will be taken to court, lose your house, business, car, and bank account.  As with "turning your service off" above, this scam preys upon most people's fear, and who isn't fearful of getting into trouble with the IRS?  In some cases the scam is more about getting your social security number and date of birth rather than payment.  Either way, don't give any information over the phone.

Red Flags to look for:

  1. The IRS will never call or e-mail you about a tax debt, they will send you notice via certified mail.
  2. The IRS will never ask you to pay your tax debt using Western Union, Money Gram, or by getting a prepaid debit card at your corner drug store.
While the above two schemes have been known to target both individuals and businesses, the last one I'll be discussing is just focused on individuals.  

In this scenario, the caller will tell you they are calling from the local courthouse, and you had been sent a notice for jury duty months ago, but you did not show up to court today, so you are now in contempt.  If you want to get out of going to jail, you need to immediately send money to pay the fine using Western Union (or one of their competitors).  Again the fear factor is used to create panic and a sense of urgency.

So the lesson here is you need to authenticate the person on the other end of the phone.  When in doubt, hang up and call back using a phone number you know is legitimate.

If only my grumpy old neighbor could see me now.

Be Secure!



Monday, December 18, 2017

The Center of Your Online Life is Not Social Media

While I might have an entire generation of Millennials that disagrees with this statement.  E-mail is the hub in which all other online activities revolve around.  To prove this point, take a look at the last 30 e-mails you have in your Inbox (disregarding any spam).  You probably have an e-mail or two from your financial institutions (banks, loan company, insurance, and brokerage), e-mails from online eCommerce sites that you frequent, e-mails from all of your social media sites, your mobile phone provider, and possibly your utilities as well.  Also, if you think about it, every website that you are registered on does password resets via e-mail.   While some may also have SMS text as an option, or as an additional factor, the majority still just use your e-mail to reset your password.  And that is what makes e-mail a huge cyber risk area.  Should your e-mail be compromised by a hacker, while yes,  they can read your e-mail or send e-mail on your behalf, the worst part is that they can quickly inventory every website and bank that you do business with.  This combined with the ability to reset your online passwords through your e-mail makes for a dangerous combination.  And once they have access to your e-mail, they can intercept and delete any alert e-mails you get from your banking and eCommerce websites of transactions, address changes (for shipping credit/debit cards or merchandise paid for with your account), or other suspicious activity.  

Also, the common mistake people make is that they use the same password for their e-mail that they use for their other online accounts.  So before a hacker even tries a password reset, which may be noticeable by you, and may send an SMS text alert to your phone, they will first try your e-mail password on your other websites as a one-time attempt.  This way they will not trip the “3 strikes and you’re out” password lockout rules, and will most likely get some hits, preferably on a banking site or eCommerce site that you’ve stored other information on such as your date of birth, social security number, or your masked credit/debit card that shows the last 4 digits.  Although it is PCI compliant to mask all but the last 4 digits of your credit/debit card, it is also another data point that many organizations use to identify you if you call in to their contact center.

To sum it up, your e-mail is used on all your other web/mobile sites.  It is used for identification, for password resets, for communication with you, and contains a history of messages from all websites you have interactions on.  You need to protect your e-mail account.

So how do you do this?  Follow my tips below:
  • Don’t use the same password for your e-mail that you use on other websites.  (If your account is compromised on another website, and your e-mail uses the same password, then the Hacker has control of your e-mail)
  • Don’t recycle old passwords.
  • Change your passwords every 30 – 45 days. (See my blog post on changing passwords frequently)
  • Make your password a complex password that can’t be guessed.  Use lower and upper case, numbers, and special characters.  The longer the better (10-14 characters).  Never use dictionary words of names of people.
  • Be alert of suspicious activity in your Inbox, such as e-mails that are in a “read” status that you did not read yet, or e-mails that have been moved to Deleted Items, that you did not delete.  Also check your Sent items to see if there is anything in there that you did not draft.
  • Be cautious when using public computers (libraries, hotel business center, etc.).  Make sure you totally log out of your e-mail, and it is a good idea to change your password when you get back to home/work and can access a computer that you trust.    
Be secure!